[Announce] ANNOUNCE: strongswan-4.2.3 released
Andreas Steffen
andreas.steffen at strongswan.org
Tue May 27 09:08:42 CEST 2008
Hi,
we are proud to announce our latest strongSwan 4.2.3 release which
can be downloaded from
http://www.strongswan.org/
You might wonder about version 4.2.2 which was never announced
publicly. Due to a GNU autotools configuration problem, the path
to the strongswan.conf file was not resolved correctly, so that
we decided to immediately fix this with the 4.2.3 release.
What's new in 4.2.3?
- Selective loading of plugins
----------------------------
Plugins for libstrongswan and charon can optionally be loaded
according to a configuration list defined in strongswan.conf.
Most components provide a 'load = ' option followed by a
space-separated list of plugins to load. This allows e.g. the
fallback from a hardware crypto accelerator to software-based
crypto plugins for the case when no HW acceleration is available.
By default all plugins enabled with configure options during
compile time are also loaded during run time. An example of a
load list can be found here:
http://www.strongswan.org/uml/testresults42/ikev2/rw-eap-aka-rsa/moon.strongswan.conf
- Non-volatile virtual IP address pool
------------------------------------
Charons' SQL plugin has been extended by a virtual IP address pool.
Configurations with a rightsourceip=%poolname setting query an
SQLite or MySQL database for leases. The "ipsec pool" command helps
in administrating the pool database. See ipsec pool --help for the
available options.
ipsec.conf / ipsec.secrets based configuration:
http://www.strongswan.org/uml/testresults42/ikev2/ip-pool-db/
or SQLite database based configuration:
http://www.strongswan.org/uml/testresults42/sql/ip-pool-db/
There is also a volatile RAM based "pool-lite" version available:
http://www.strongswan.org/uml/testresults42/ikev2/ip-pool/
- Support of authenticated ESP encryption algorithms
--------------------------------------------------
The Authenticated Encryption Algorithms AES-CCM-8/12/16 and
AES-GCM-8/12/16 for ESP are now supported starting with the
Linux 2.6.25 kernel. The syntax is e.g. esp=aes128ccm12 or
esp=aes256gcm16.
http://www.strongswan.org/uml/testresults42/ikev2/esp-alg-aes-ccm/
http://www.strongswan.org/uml/testresults42/ikev2/esp-alg-aes-gcm/
- 4th IKEv2 Interoperability Workshop in San Antonio, Texas
---------------------------------------------------------
We fixed a couple of minor issues that came up while testing
with IBM, Microsoft, Nokia, SafeNet, SonicWALL and the TAHI project.
LinuxTag 2008 in Berlin
-----------------------
The strongSwan team consisting of Tobias Brunner, Martin Willi and
Andreas Steffen will be present at the forthcoming LinuxTag 2008
in Berlin which opens tomorrow and lasts until Saturday May 31.
Please visit our booth 107 in hall 7.2a. If you want a free ticket
please send me an email.
Best regards
Andreas
======================================================================
Andreas Steffen andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution! www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==
More information about the Announce
mailing list