Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 9 May 2017 17:21:42 +0000 (UTC)
From:      Glen Barber <gjb@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-11@freebsd.org
Subject:   svn commit: r318052 - stable/11/release/doc/en_US.ISO8859-1/relnotes
Message-ID:  <201705091721.v49HLgK1057251@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: gjb
Date: Tue May  9 17:21:41 2017
New Revision: 318052
URL: https://svnweb.freebsd.org/changeset/base/318052

Log:
  Document r315514:
  - IPSEC_FILTERTUNNEL deprecation
  - ipsec.ko and tcpmd5.ko additions
  - IPSEC_NAT_T removal
  - setkey(8) updates
  
  Sponsored by:	The FreeBSD Foundation

Modified:
  stable/11/release/doc/en_US.ISO8859-1/relnotes/article.xml

Modified: stable/11/release/doc/en_US.ISO8859-1/relnotes/article.xml
==============================================================================
--- stable/11/release/doc/en_US.ISO8859-1/relnotes/article.xml	Tue May  9 17:21:41 2017	(r318051)
+++ stable/11/release/doc/en_US.ISO8859-1/relnotes/article.xml	Tue May  9 17:21:41 2017	(r318052)
@@ -174,6 +174,14 @@
     <sect2 xml:id="userland-programs">
       <title>Userland Application Changes</title>
 
+      <para revision="315514" contrib="sponsor" sponsor="&yandex;">The
+	&man.setkey.8; utility has been modified to show the runtime
+	<acronym>NAT-T</acronym> configuration.  The
+	<literal>-g</literal> and <literal>-t</literal> flags have
+	been added, which list only global and virtual policies,
+	respectively when used with the <literal>-D</literal> and
+	<literal>-P</literal> flags.</para>
+
       <para revision="316098" contrib="sponsor"
 	sponsor="&dellemc;">The &man.getaddrinfo.1; utility has been
 	added, ported from NetBSD.</para>
@@ -276,12 +284,24 @@
     <sect2 xml:id="kernel-config">
       <title>Kernel Configuration</title>
 
-      <para>&nbsp;</para>
+      <para revision="315514" contrib="sponsor" sponsor="&yandex;">The
+	<literal>IPSEC_NAT_T</literal> kernel configuration option has
+	been removed.  Support for <acronym>NAT-T</acronym> is now
+	enabled by default.</para>
+
+      <para revision="315514" contrib="sponsor" sponsor="&yandex;">The
+	<literal>IPSEC_FILTERTUNNEL</literal> kernel option has been
+	removed, which was deprecated by the
+	<literal>net.inet.ipsec.filtertunnel</literal> sysctl.</para>
     </sect2>
 
     <sect2 xml:id="kernel-modules">
       <title>Kernel Modules</title>
 
+      <para revision="315514" contrib="sponsor" sponsor="&yandex;">The
+	<literal>ipsec</literal> and <literal>tcpmd5</literal> kernel
+	modules have been added.</para>
+
       <para revision="316274" contrib="sponsor" sponsor="&yandex;">The
 	&man.ipfw.4; packet filter has been updated to add support for
 	named dynamic states.</para>
@@ -449,7 +469,10 @@
     <sect2 xml:id="network-protocols">
       <title>Network Protocols</title>
 
-      <para>&nbsp;</para>
+      <para revision="315514" contrib="sponsor"
+	sponsor="&yandex;">Support for the
+	<literal>UDP_ENCAP_ESPINUDP_NON_IKE</literal> encapsulation
+	type has been removed.</para>
     </sect2>
   </sect1>
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201705091721.v49HLgK1057251>