On Mon, 20 Aug 2012 11:32:12 +0300, Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> wrote: > On Wed, Aug 08, 2012 at 08:22:15PM -0500, Kim Phillips wrote: >> On Wed, 8 Aug 2012 18:46:45 +0300 >> Horia Geanta <horia.geanta@xxxxxxxxxxxxx> wrote: >> >>> Support for ESNs (extended sequence numbers). >>> Tested with strongswan on a P2020RDB back-to-back setup. >>> Extracted from /etc/ipsec.conf: >>> esp=aes-sha1-esn-modp4096! >>> >>> Signed-off-by: Horia Geanta <horia.geanta@xxxxxxxxxxxxx> >>> --- >> >> series: >> >> Reviewed-by: Kim Phillips <kim.phillips@xxxxxxxxxxxxx> > > Patch applied. Thanks! What about patches [1-4]/5 ? http://www.mail-archive.com/linux-crypto@xxxxxxxxxxxxxxx/msg07507.html Patch 5/5 won't work without these. 4/5 adds "support for handling non-contiguous assoc data and iv", which is exactly how native IPsec submits SPI + ESN to talitos. Horia -- To unsubscribe from this list: send the line "unsubscribe linux-crypto" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html