home.social

#geekadventures — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #geekadventures, aggregated by home.social.

  1. Wow! After delving into IPSec strongSwan rekeying, I now know that the initial 'data key' (Child SA) is like a quick handshake with no fancy secret exchange (PFS) (RTFM! [1]). However, for rekeys, it's full secret agent handshake mode! Writing the GitHub bug report, which turned out not to be a bug, helped me to understand my situation better. [2] Finally migrated to the new IPSEC connection setup in OPNsense and updated my blog post. [3]

    (Now I expect to get answers, aka 'Use WireGuard!')

    [1]: docs.strongswan.org/docs/lates
    [2]: github.com/opnsense/core/issue
    [3]: du.nkel.dev/blog/2021-11-19_pf

    #IPsec #PFS #strongSwan #GeekAdventures #OPNsense

  2. Wow! After delving into IPSec strongSwan rekeying, I now know that the initial 'data key' (Child SA) is like a quick handshake with no fancy secret exchange (PFS) (RTFM! [1]). However, for rekeys, it's full secret agent handshake mode! Writing the GitHub bug report, which turned out not to be a bug, helped me to understand my situation better. [2] Finally migrated to the new IPSEC connection setup in OPNsense and updated my blog post. [3]

    (Now I expect to get answers, aka 'Use WireGuard!')

    [1]: docs.strongswan.org/docs/lates
    [2]: github.com/opnsense/core/issue
    [3]: du.nkel.dev/blog/2021-11-19_pf

    #IPsec #PFS #strongSwan #GeekAdventures #OPNsense