Emeric POUPON emeric.poupon at stormshield.eu
Thu Oct 23 17:49:05 CEST 2014


Today, we are able to log the IKE SA connection names, thanks to the ike_sa argument in the log/vlog functions (see src/libcharon/bus/listeners/logger.h)

Sometimes this is no that useful (lot of possible subnets, lot of roadwarriors, etc.)
I wonder if adding a child_sa parameter to these log functions would make sense?
This would allow us to log extra information, such as the selected traffic selectors or spi, in order to better identify the child SA that is responsible for the log.

What do you think?


