vici: Make childless initiation of IKE_SAs configurable

This commit is contained in:
Tobias Brunner
2019-04-25 15:23:19 +02:00
parent 6b00d34b42
commit 2889b77da2
2 changed files with 41 additions and 1 deletions
+16 -1
View File
@@ -154,7 +154,7 @@ connections.<conn>.dpd_timeout = 0s
specified; this option has no effect on connections using IKE2.
connections.<conn>.fragmentation = yes
Use IKE UDP datagram fragmentation. (_yes_, _accept_, _no_ or _force_).
Use IKE UDP datagram fragmentation (_yes_, _accept_, _no_ or _force_).
Use IKE fragmentation (proprietary IKEv1 extension or RFC 7383 IKEv2
fragmentation). Acceptable values are _yes_ (the default), _accept_,
@@ -168,6 +168,21 @@ connections.<conn>.fragmentation = yes
Note that fragmented IKE messages sent by a peer are always accepted
irrespective of the value of this option (even when set to _no_).
connections.<conn>.childless = allow
Use childless IKE_SA initiation (_allow_, _force_ or _never_).
Use childless IKE_SA initiation (RFC 6023) for IKEv2. Acceptable values
are _allow_ (the default), _force_ and _never_. If set to _allow_,
responders will accept childless IKE_SAs (as indicated via notify in the
IKE_SA_INIT response) while initiators continue to create regular IKE_SAs
with the first CHILD_SA created during IKE_AUTH, unless the IKE_SA is
initiated explicitly without any children (which will fail if the responder
does not support or has disabled this extension). If set to _force_, only
childless initiation is accepted and the first CHILD_SA is created with a
separate CREATE_CHILD_SA exchange (e.g. to use an independent DH exchange
for all CHILD_SAs). Finally, setting the option to _never_ disables support
for childless IKE_SAs as responder.
connections.<conn>.send_certreq = yes
Send certificate requests payloads (_yes_ or _no_).