Uploaded image for project: 'Fast Datapath Product'
  1. Fast Datapath Product
  2. FDP-645

OVS IPsec is incompatible with Libreswan 5

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • openvswitch3.3
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • Important

      Major distributions are not shipping Libreswan v5 yet, but they will start soon, including Fedora and later, likely, RHEL 10.

      Libreswan 5 deprecated ipsec auto command that ovs-monitor-ipsec is heavily relying on.  In practice, however, ipsec auto is just broken for our use case in v5, see https://github.com/libreswan/libreswan/issues/1726 .

      Need to migrate out of ipsec auto. Ideally, replacing with commands that work in both v4 and v5 to avoid version checking within ovs-monitor-ipsec.

              rh-ee-mpattric Mike Pattrick
              imaximet@redhat.com Ilya Maximets
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: