Hello community, here is the log from the commit of package strongswan checked in at Tue Feb 19 14:17:01 CET 2008. -------- --- strongswan/strongswan.changes 2007-12-08 13:03:50.000000000 +0100 +++ /mounts/work_src_done/STABLE/strongswan/strongswan.changes 2008-02-19 12:04:52.412133000 +0100 @@ -1,0 +2,19 @@ +Tue Feb 19 11:44:03 CET 2008 - mt@suse.de + +- Updated to 4.1.11 maintenance release, providing following fixes: + * IKE rekeying in NAT situations did not inherit the NAT conditions + to the rekeyed IKE_SA so that the UDP encapsulation was lost with + the next CHILD_SA rekeying. + * Wrong type definition of the next_payload variable in id_payload.c + caused an INVALID_SYNTAX error on PowerPC platforms. + * Implemented IKEv2 EAP-SIM server and client test modules that use + triplets stored in a file. For details on the configuration see + the scenario 'ikev2/rw-eap-sim-rsa'. +- The 4.1.10 final version, declared upstream as "Fully tested support + of IPv6 IPsec tunnel connections", fixes ordering error in oscp cache, + IPv6 defaults of the nexthop parameter, adds support for new EAP + modules [disabled in this build] and obsoletes our strongswan_path + and strongswan_ipsec_script_msg patches. +- Removed a sed call from init script. + +------------------------------------------------------------------- Old: ---- strongswan-4.1.9.tar.bz2 strongswan-4.1.9.tar.bz2.sig strongswan_ipsec_script_msg.dif strongswan_path.dif New: ---- strongswan-4.1.11.tar.bz2 strongswan-4.1.11.tar.bz2.sig ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ strongswan.spec ++++++ --- /var/tmp/diff_new_pack.i27770/_old 2008-02-19 14:16:45.000000000 +0100 +++ /var/tmp/diff_new_pack.i27770/_new 2008-02-19 14:16:45.000000000 +0100 @@ -1,7 +1,7 @@ # -# spec file for package strongswan (Version 4.1.9) +# spec file for package strongswan (Version 4.1.11) # -# Copyright (c) 2007 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2008 SUSE LINUX Products GmbH, Nuernberg, Germany. # This file and all modifications and additions to the pristine # package are under the same license as the package itself. # @@ -10,11 +10,12 @@ # norootforbuild + Name: strongswan -%define upstream_version 4.1.9 +%define upstream_version 4.1.11 %define strongswan_docdir %{_docdir}/%{name} -Version: 4.1.9 -Release: 6 +Version: 4.1.11 +Release: 1 License: GPL v2 or later Group: Productivity/Networking/Security Summary: StrongSwan -- OpenSource IPsec-based VPN Solution @@ -28,9 +29,7 @@ Source0: http://download.strongswan.org/strongswan-%{upstream_version}.tar.bz2 Source1: http://download.strongswan.org/strongswan-%{upstream_version}.tar.bz2.sig Source2: %{name}.init.in -Patch1: %{name}_path.dif -Patch2: %{name}_ipsec_script_msg.dif -Patch3: %{name}_modprobe_syslog.dif +Patch1: %{name}_modprobe_syslog.dif BuildRoot: %{_tmppath}/%{name}-%{version}-build BuildRequires: bison flex gmp-devel gperf pkg-config %if 0%{?suse_version} >= 1030 @@ -49,9 +48,11 @@ * runs both on Linux 2.4 (KLIPS IPsec) and Linux 2.6 (NETKEY IPsec) kernels -* supports both the IKEv1 and IKEv2 (RFC 4306) key exchange +* implements both the IKEv1 and IKEv2 (RFC 4306) key exchange protocols +* NEW: Fully tested support of IPv6 IPsec tunnel connections + * Dynamical IP address and interface update with IKEv2 MOBIKE (RFC 4555) @@ -123,8 +124,6 @@ %prep %setup -q -n %{name}-%{upstream_version} %patch1 -p0 -%patch2 -p0 -%patch3 -p0 sed -e 's|@libexecdir@|%_libexecdir|g' \ < $RPM_SOURCE_DIR/strongswan.init.in \ > strongswan.init @@ -251,8 +250,25 @@ %{_mandir}/man8/pluto.8* %{_mandir}/man8/scepclient.8* %{_mandir}/man8/starter.8* + %changelog -* Sat Dec 08 2007 - mt@suse.de +* Tue Feb 19 2008 mt@suse.de +- Updated to 4.1.11 maintenance release, providing following fixes: + * IKE rekeying in NAT situations did not inherit the NAT conditions + to the rekeyed IKE_SA so that the UDP encapsulation was lost with + the next CHILD_SA rekeying. + * Wrong type definition of the next_payload variable in id_payload.c + caused an INVALID_SYNTAX error on PowerPC platforms. + * Implemented IKEv2 EAP-SIM server and client test modules that use + triplets stored in a file. For details on the configuration see + the scenario 'ikev2/rw-eap-sim-rsa'. +- The 4.1.10 final version, declared upstream as "Fully tested support + of IPv6 IPsec tunnel connections", fixes ordering error in oscp cache, + IPv6 defaults of the nexthop parameter, adds support for new EAP + modules [disabled in this build] and obsoletes our strongswan_path + and strongswan_ipsec_script_msg patches. +- Removed a sed call from init script. +* Sat Dec 08 2007 mt@suse.de - Updated to 4.1.9 final, including all our patches. - Changed init script to use ipsec cmd using LSB codes now. - Added strongswan_path.dif setting a PATH in scripts (updown). @@ -260,9 +276,9 @@ ipsec script messages. - Added strongswan_modprobe_syslog.dif redirecting modprobe output to syslog. -* Mon Nov 26 2007 - mt@suse.de +* Mon Nov 26 2007 mt@suse.de - Renamed charon plugins to avoid rpm conflicts with existing libraries (libstroke). Patch: strongswan-libconflicts.dif - Added init script. Template file: strongswan.init.in -* Thu Nov 22 2007 - mt@suse.de +* Thu Nov 22 2007 mt@suse.de - Initial, unfinished package ++++++ strongswan-4.1.9.tar.bz2 -> strongswan-4.1.11.tar.bz2 ++++++ ++++ 11932 lines of diff (skipped) ++++++ strongswan.init.in ++++++ --- strongswan/strongswan.init.in 2007-12-07 08:58:23.000000000 +0100 +++ /mounts/work_src_done/STABLE/strongswan/strongswan.init.in 2008-02-19 11:48:13.000000000 +0100 @@ -208,7 +208,7 @@ case "$1" in start) - $IPSEC_CMD start 2>&1 | sed -e "s/ -- .*//g" + $IPSEC_CMD start 2>&1 rc_status -v1 ;; stop) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Remember to have fun... --------------------------------------------------------------------- To unsubscribe, e-mail: opensuse-commit+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-commit+help@opensuse.org
participants (1)
-
root@Hilbert.suse.de