diff options
author | Mike Belopuhov <mikeb@cvs.openbsd.org> | 2017-03-27 17:17:50 +0000 |
---|---|---|
committer | Mike Belopuhov <mikeb@cvs.openbsd.org> | 2017-03-27 17:17:50 +0000 |
commit | be937ec9c344c2a67820d47fa5105e5b70583317 (patch) | |
tree | ecd54664e518242b527c5ad2d35cf2beebdbf8a0 /include | |
parent | c95c19c5a7ad77c6074e52ed3341e7cc9cba6537 (diff) |
Don't cache the DH group in the policy
When tearing IKE SA down, the DH group referred by it is destroyed,
however it remains cached in the policy. With the introduction of
IKE SA rekeying we have extended the life of this dangling pointer
by reusing it on new SAs. So instead of caching the pointer in the
policy we can store the DH group ID and create a DH group on demand
using this parameter if it's specified.
With and OK reyk
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions