vici: Make security labels and mode configurable
This commit is contained in:
@@ -1011,6 +1011,34 @@ connections.<conn>.children.<child>.if_id_out = 0
|
||||
|
||||
The daemon will not install routes for CHILD_SAs that have this option set.
|
||||
|
||||
connections.<conn>.children.<child>.label
|
||||
Optional security label (e.g. SELinux context), IKEv2 only. Refer to
|
||||
**label_mode** for details on how labels are processed.
|
||||
|
||||
connections.<conn>.children.<child>.label_mode = system
|
||||
Security label mode (_system_, _simple_ or _selinux_), IKEv2 only.
|
||||
|
||||
Defines the mode in which the configured security label is used. The default
|
||||
value of _system_ selects _selinux_ if strongSwan was built with SELinux
|
||||
support and SELinux is enabled by the kernel, otherwise, _simple_ will be
|
||||
selected.
|
||||
|
||||
If set to _simple_, the label will be used as is as an additional
|
||||
identifier/selector on the IKEv2 level when negotiating CHILD_SAs and
|
||||
selecting configs, labels are not installed in the kernel and received
|
||||
labels have to match exactly.
|
||||
|
||||
If set to _selinux_, which is only allowed if SELinux is usable on the
|
||||
system, the configured label is expected to be a generic context (e.g.
|
||||
_system_u:object_r:ipsec_spd_t:s0_) for which flows, whose context match it
|
||||
via association:polmatch, will trigger an acquire if no SA exists yet for
|
||||
the flow's specific context. The configured label is installed on (trap)
|
||||
policies, so this should generally be combined with _trap_ in
|
||||
**start_action**. However, if the connection is initiated directly,
|
||||
without acquire, a childless IKE_SA is established and appropriate trap
|
||||
policies are installed on both ends. Labels received from peers are accepted
|
||||
if they match the configured label via association:polmatch.
|
||||
|
||||
connections.<conn>.children.<child>.tfc_padding = 0
|
||||
Traffic Flow Confidentiality padding.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user