From owner-freebsd-security Mon May 27 5:46: 6 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.dev.itouchnet.net (devco.net [196.15.188.2]) by hub.freebsd.org (Postfix) with ESMTP id 9F9B737B405 for ; Mon, 27 May 2002 05:45:59 -0700 (PDT) Received: from nobody by mx1.dev.itouchnet.net with scanned_ok (Exim 3.35 #1) id 17CJt1-000D51-00 for FreeBSD-Security@freebsd.org; Mon, 27 May 2002 14:46:07 +0200 Received: from shell.devco.net ([196.15.188.7]) by mx1.dev.itouchnet.net with esmtp (Exim 3.35 #1) id 17CJt0-000D4g-00; Mon, 27 May 2002 14:46:06 +0200 Received: from bvi by shell.devco.net with local (Exim 3.33 #4) id 17CJt1-000K48-00; Mon, 27 May 2002 14:46:07 +0200 Date: Mon, 27 May 2002 14:46:07 +0200 From: Barry Irwin To: Jerry Murdock Cc: Shoichi Sakane , FreeBSD-Security@FreeBSD.ORG Subject: Re: Racoon SA Hard/Soft Lifetimes Message-ID: <20020527144607.R38967@itouchlabs.com> References: <20020525122004P.sakane@kame.net> <20020525133315.86705.qmail@web14603.mail.yahoo.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <20020525133315.86705.qmail@web14603.mail.yahoo.com>; from jerry_murdock@yahoo.com on Sat, May 25, 2002 at 06:33:15AM -0700 X-Checked: Scanned for any viruses and unauthorized attachments at mx1.dev.itouchnet.net X-iScan-ID: 50279-1022503567-23729@mx1.dev.itouchnet.net version $Name: REL_2_0_2 $ Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hi All I have tracked this down as being available in 4.5< However I can find mo mention of any of the net.key.* sysctls in the man pages, anyone aware of a description, or is it a case of read the source ? Barry On Sat 2002-05-25 (06:33), Jerry Murdock wrote: > > > > try like the following, > > # sysctl -w net.key.preferred_oldsa=0 > > Sounds like exactly what I was looking for, unfortunately it doesn't seem to > have any effect. > > I still see the counters for the old SA incrementing, and nothing going out the > new SA until the old one expires completely. > > For now, I've modified racoon to set the soft lifetime to "hard lifetime - 10 > seconds." The value seems to work quite well for the connection in question > with no apparent key-renegotiation packet loss. > -- Barry Irwin bvi@itouchlabs.com +27214875177 Systems Administrator: Networks And Security Itouch Labs http://www.itouchlabs.com South Africa To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message