From owner-freebsd-current@FreeBSD.ORG Mon Apr 3 16:27:17 2006 Return-Path: X-Original-To: current@freebsd.org Delivered-To: freebsd-current@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3B0A116A423 for ; Mon, 3 Apr 2006 16:27:17 +0000 (UTC) (envelope-from nikruzhan@gmail.com) Received: from zproxy.gmail.com (zproxy.gmail.com [64.233.162.194]) by mx1.FreeBSD.org (Postfix) with ESMTP id 20A7743D4C for ; Mon, 3 Apr 2006 16:27:14 +0000 (GMT) (envelope-from nikruzhan@gmail.com) Received: by zproxy.gmail.com with SMTP id l8so1653424nzf for ; Mon, 03 Apr 2006 09:27:13 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; b=LaJtBQGtX+9M0nAaxmPDbhvg5ircPc+0wYaRJp4/ybS6ozXuFGh7oTx+ALSVZ9re9daGY1NopXZq3TyCkXsu2Lg+G6KimMKV/QEtr9yQZ1Q9ZXrLe7i02sRBWW+EHFHCurzCk0KHnMufm5hFYhNlhFTjF4nMzVs1kedkQYvW+mw= Received: by 10.35.91.10 with SMTP id t10mr1468399pyl; Mon, 03 Apr 2006 09:27:13 -0700 (PDT) Received: by 10.35.92.9 with HTTP; Mon, 3 Apr 2006 09:27:13 -0700 (PDT) Message-ID: <60ffc71f0604030927g3a75f914hf32457fe8934c091@mail.gmail.com> Date: Mon, 3 Apr 2006 16:27:13 +0000 From: Nik To: "Chuck Swiger" In-Reply-To: <44312E56.3040606@mac.com> MIME-Version: 1.0 References: <60ffc71f0604030126w60070561i9781729205d3790d@mail.gmail.com> <1144055468.15377.12.camel@bert.mlan.solnet.ch> <60ffc71f0604030255h3b418706vfaf51bb5f088dff3@mail.gmail.com> <44312E56.3040606@mac.com> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: current@freebsd.org Subject: Re: BGP: can't set sockopt TCP_MD5SIG 0 to socket 16 X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Apr 2006 16:27:17 -0000 If that is the case then I only need to recompile my kernel as what Thomas said. Thanks a lot Thomas & Chuck. # quagga needs this for MD5 passwords on BGP sessions options TCP_SIGNATURE options FAST_IPSEC device crypto device cryptodev On 4/3/06, Chuck Swiger wrote: > > Nik wrote: > > I'm curious why I need to enable MD5 because in my system I don't use > any > > authentication method. [ ... ] > > Using the MD5 signature TCP option for BGP has become a common requiremen= t > since > the RST-window vulnerability was published... > > -- > -Chuck > >