From e7ad5ffcc804b558f7cb889e6e6427c748cdcfd3 Mon Sep 17 00:00:00 2001 From: AlmaLinux RelEng Bot Date: Mon, 27 Jul 2026 03:59:36 -0400 Subject: [PATCH] import CS git libreswan-5.3.2-1.el10_2 --- .gitignore | 9 +- .libreswan.metadata | 4 - LIBRESWAN-OpenPGP-KEY.txt | 51 + ...eswan-3.32-1861360-nodefault-rsa-pss.patch | 31 - ...eswan-4.1-maintain-obsolete-keywords.patch | 136 --- SOURCES/libreswan-4.12-CVE-2026-12413.patch | 25 - SOURCES/libreswan-4.12-CVE-2026-14957.patch | 76 -- SOURCES/libreswan-4.12-CVE-2026-50721.patch | 83 -- SOURCES/libreswan-4.12-CVE-2026-50722.patch | 96 -- ...an-4.12-ikev1-compute-keymat-default.patch | 92 -- ...breswan-4.12-ikev2-auth-delete-state.patch | 54 - SOURCES/libreswan-4.3-1934186-config.patch | 11 - ...an-4.3-maintain-different-v1v2-split.patch | 85 -- .../libreswan-4.9-2176248-authby-rsasig.patch | 52 - SPECS/libreswan.spec | 542 --------- libreswan-4.15-ipsec_import.patch | 20 + libreswan-5.3-helper-thread.patch | 97 ++ ...an-5.3-outstanding-ike-auth-crossing.patch | 1056 +++++++++++++++++ libreswan.spec | 669 +++++++++++ sources | 5 + 20 files changed, 1903 insertions(+), 1291 deletions(-) delete mode 100644 .libreswan.metadata create mode 100644 LIBRESWAN-OpenPGP-KEY.txt delete mode 100644 SOURCES/libreswan-3.32-1861360-nodefault-rsa-pss.patch delete mode 100644 SOURCES/libreswan-4.1-maintain-obsolete-keywords.patch delete mode 100644 SOURCES/libreswan-4.12-CVE-2026-12413.patch delete mode 100644 SOURCES/libreswan-4.12-CVE-2026-14957.patch delete mode 100644 SOURCES/libreswan-4.12-CVE-2026-50721.patch delete mode 100644 SOURCES/libreswan-4.12-CVE-2026-50722.patch delete mode 100644 SOURCES/libreswan-4.12-ikev1-compute-keymat-default.patch delete mode 100644 SOURCES/libreswan-4.12-ikev2-auth-delete-state.patch delete mode 100644 SOURCES/libreswan-4.3-1934186-config.patch delete mode 100644 SOURCES/libreswan-4.3-maintain-different-v1v2-split.patch delete mode 100644 SOURCES/libreswan-4.9-2176248-authby-rsasig.patch delete mode 100644 SPECS/libreswan.spec create mode 100644 libreswan-4.15-ipsec_import.patch create mode 100644 libreswan-5.3-helper-thread.patch create mode 100644 libreswan-5.3-outstanding-ike-auth-crossing.patch create mode 100644 libreswan.spec create mode 100644 sources diff --git a/.gitignore b/.gitignore index 13bd332..369978a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,5 @@ -SOURCES/ikev1_dsa.fax.bz2 -SOURCES/ikev1_psk.fax.bz2 -SOURCES/ikev2.fax.bz2 -SOURCES/libreswan-4.12.tar.gz +ikev1_dsa.fax.bz2 +ikev1_psk.fax.bz2 +ikev2.fax.bz2 +libreswan-5.3.2.tar.gz +libreswan-5.3.2.tar.gz.sig diff --git a/.libreswan.metadata b/.libreswan.metadata deleted file mode 100644 index 0dc2bf4..0000000 --- a/.libreswan.metadata +++ /dev/null @@ -1,4 +0,0 @@ -b35cd50b8bc0a08b9c07713bf19c72d53bfe66bb SOURCES/ikev1_dsa.fax.bz2 -861d97bf488f9e296cad8c43ab72f111a5b1a848 SOURCES/ikev1_psk.fax.bz2 -fcaf77f3deae3d8e99cdb3b1f8abea63167a0633 SOURCES/ikev2.fax.bz2 -786c14a4755311ea3103683a3294e1536b1e44a6 SOURCES/libreswan-4.12.tar.gz diff --git a/LIBRESWAN-OpenPGP-KEY.txt b/LIBRESWAN-OpenPGP-KEY.txt new file mode 100644 index 0000000..6862700 --- /dev/null +++ b/LIBRESWAN-OpenPGP-KEY.txt @@ -0,0 +1,51 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQINBFDjilcBEAChkfasfBKTzGys9DwgBsmDVsPConW60uyKnu16+wO1kIKMFWi6 +wGllwKUJmCBY2FSQHbOBy5eHPPT1ijJhYt4j7WU+YJVh5Ca5RE3trFt31FX0vzp+ +KMqdQ8HOofA7jO6bgyHUwOJ539YkqYj1jHKfrdRqOnzB9fFyEb7485sq1F8j/rHk +cSar1Hd9QfGAZHxXqgncgHFobB/xXEGRJIi+4kNL5SYasbw9tfYUGPrUXVol1+pn +tsG92736O5Qe5K+wH2nAS4hwPJ1Xr4XIKeNNwxQW25wWqn4mLa4Vly+PA2uSE7ZP +RcxE3yBCaLFMlw4rLhFAzd6TeslQONZ+9K51yfBYm7m0vWM3Ixq8yuD8E49OkKr8 +QRMaA2g89NW3AuNLExiTE0zQzAs/g6eX8WZdeWCvKxhRTAUYkw0QTimFgv6LXIeS +//5DOAAO9WwzlseTGmUgek3BbnnJJiGHVLBgnLaqWLOZ1Y8ON1uC8lQnbIeYbTQq +EE5R0cbVLVXBJoKakBF8gwHF51HC2pSBYmHNZsSbjMuHpJWJM4fVldNWPNaqriKC +OkL8QgvNoapgk20k1ajLl/ibv32k7QBKy3cTMtbQYPdreXcoZuMw38ysQcgFxPCs +Zh92aaWW0ceWowkJ7CFnes2jdPcMSOYE37wodmV3/VV7cusmTD8wikyUdQARAQAB +tCxMaWJyZXN3YW4gKFNpZ25pbmcgS2V5KSA8dGVhbUBsaWJyZXN3YW4ub3JnPokC +TgQTAQoAOBYhBJB+eQ8lwejlYc1ztYX/S0OzD8b5BQJi4cg4AhsDBQsJCAcDBRUK +CQgLBRYCAwEAAh4FAheAAAoJEIX/S0OzD8b5zNcP/RuDb05Xr+IpuGWtJ38yGMWG +mZglLHrzCAOXNAr/QXt6Kz3sThJoZFIh2E4Ab5yW59iFLFpW3VuZIGVCyh7vsuVw +MuKoJtrZtdbHSdLbE+FHpY7osQDrcuodTv5b7STfG2Wje18iG/dCATVIDDgbPmuJ +FpNLcR3scuoIlgxmP3Y1AFgufLR5MiN60PKnS2Husyj0f5Gqc3USLofWKgEQ4wFa +gT1iIjkf4zkFcVlJ5K0SE1ULn8K7umkOUvLcKg6ji+1sEwEM1kCNmxI8HkiNt296 +9Z/TLK1h8McFGwG7x1p8fZ7Kjmzwnv1TSxAt1wHMoa0m9LntQOXnn3hVJaC74AzX +heFtqDHmATpcGtQLR0zutrZ+ohUb6AEt+hAPfyDDYIR5y3oNdSLozJkJ1wlrhsYh +SR1Hv4b3fdD6XgyUPggituOYm+yv1PuHrSEaoznnlX2z0MaVJyJIN0zUHlPBmWKC +LmzQX2A7l9bHhkXYgHoSdeBHdwvcQQGWwkVmN2WUwsM/m9Abk8OdLdE13nI8824R +0+b6XzJ2g4L+RIsVseerX2WIMHSMvkbFuLpEE4ILOrL+9Lq5bdx9MvZPtsZ/ZutY +QVVvJ+nJtmPp0HpybnJdXzB7Za02A0r2gXIUrund32K97qe8XblCwxkZbZCeLcSL +5+mb8O1XPGD39S6CCZbRuQINBFDjilcBEADXDN9o3icyDy+ity45CsQfo1f84xL6 +oJIgCLGGwm3RFPgOzdgxaE7TiLzW2NBui+yHyw48WRTxZ9XC6HtGKjH6XPvP5nF4 +8wss7tjzRNzmNgTp7G47HkW3lD0VYX4NqfCmxQK9gTXob1+JFmWkEXkXmZYg2dbn +1REtHb03x370Z547rjvdpopQW6jaSw0C556DOxb9weJqLqAd2uZO4nwhuDs/VM+Q +yy+/MlHTbnsmnYIMozDLMmHZ1PMeJlTFPMfapaux9UDTgQ5dwLj2FiQ/uEMzvfVv +W23hxlpWVHsccwZR77PMDt4Nbj/7QlOIKpgid2r8SyBmhjET2u/USSzFYzK8J2Wj +oLcxiuMTwrnM6b3bqiuSDUMAEoNN814Cbpz6yLB2wyKs5N7ZA/lVLNE8MV7to8OD +ww1nS2bDDf5/JMNt5aWu/iO2bBrYE30LqHR3bSV6QP57JnzunM9Y4V1BnEKYW14A +9+rRH1k1e5CuS5tqxpSubniF80AdUyPjF8rXOY0URD6zY0s4843Nf9TNr8ke/1ma +qLEkUAF03AwBR8oz247ylu75q94ytpYUFJAkNeqpk8XypqKJMVcl4NfEP930JR82 +sGjNylVu/b4EsqKfmkoU8VFM1lfuaqX1u2ZDoUpG2Io/zpeV07RQ0KTHdKBejzix +2IN0T7W4G0JXcwARAQABiQIfBBgBAgAJBQJQ44pXAhsMAAoJEIX/S0OzD8b5KR8P +/jdWNVVw74/oCPtt79V1r0XN4I0ZBTQZgKp3JmZdcZlS2Uzx4u1VhxcevDQ7fh/Z +5Y1xDBh+IKwF83hJKXy56+PJBlYIGjc2GTEmU1yo4E9iudPq56FFb6eelX1qBfxI +0ZHdWgzWmrtnCF65zGTmeYMpck4ZuKdJAX2AM6kWcBikt4jT/SqrcS8t/duWRSSV +iikwXD8aPexAz9XuezI+y3Exupt/lqUyVtCV3t0/gWRAMuwrMH/RABEPTaQdmxKz +i0OkMDlHhweXZWg0/t32XLhhmy4f/30NhKYnntN6/pdNDb8vin5OP2MRyJDHIykA +2HZcYvjdZS43+PbiuqDCTILMvxUDYjxHszgEheLariRvmRwE1HRjZWNTzGTjUgyv +83XUhrIoAlgMVy2tQAatKbNVYAn5dmA0NCDKnSszas43gApSSjh2UXmq/owwpVj6 +zYHcoV0gdCuLJ1BPLstN0ZGO+g+eRpTI97+/04sgz/hImDsm7G3Diners/FDaebt +pMRzVshh5lIgVBnCT36hdHW8buyiAgRQtjq7bX8JLN4Ermxlq4a33OYc7TGNC3jF +Rm4XSY6RUDMd6uhRD5hKZB2N8az079603K7nc93x32CualHCJD+M7Z2/j9r3T3Tc +y69oM+pgP48wySo+XEGHCM5OG7YNNiJ8xQ/J+CKCyLQV +=ZaKB +-----END PGP PUBLIC KEY BLOCK----- diff --git a/SOURCES/libreswan-3.32-1861360-nodefault-rsa-pss.patch b/SOURCES/libreswan-3.32-1861360-nodefault-rsa-pss.patch deleted file mode 100644 index 631bfee..0000000 --- a/SOURCES/libreswan-3.32-1861360-nodefault-rsa-pss.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 1dddaa3226fe1b71b68ec9665d93864a5ec69801 Mon Sep 17 00:00:00 2001 -From: rpm-build -Date: Mon, 9 Jan 2023 23:26:10 +0900 -Subject: [PATCH] libreswan-3.32-1861360-nodefault-rsa-pss.patch - ---- - lib/libipsecconf/confread.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/lib/libipsecconf/confread.c b/lib/libipsecconf/confread.c -index 0444118..ec87646 100644 ---- a/lib/libipsecconf/confread.c -+++ b/lib/libipsecconf/confread.c -@@ -1501,9 +1501,14 @@ static bool load_conn(struct starter_conn *conn, - hunk_streq(val, "rsa")) { - conn->authby.rsasig = true; - conn->authby.rsasig_v1_5 = true; -+ /* -+ * These cause failure with RSA 1024 bits because it uses RSA-PSS -+ */ -+#if 0 - conn->sighash_policy |= POL_SIGHASH_SHA2_256; - conn->sighash_policy |= POL_SIGHASH_SHA2_384; - conn->sighash_policy |= POL_SIGHASH_SHA2_512; -+#endif - } else if (hunk_streq(val, "never")) { - conn->authby.never = true; - /* everything else is only supported for IKEv2 */ --- -2.39.0 - diff --git a/SOURCES/libreswan-4.1-maintain-obsolete-keywords.patch b/SOURCES/libreswan-4.1-maintain-obsolete-keywords.patch deleted file mode 100644 index 497dd3e..0000000 --- a/SOURCES/libreswan-4.1-maintain-obsolete-keywords.patch +++ /dev/null @@ -1,136 +0,0 @@ -From a2cc5f8c80e8cb9be0b65f8e8544689e8b093c09 Mon Sep 17 00:00:00 2001 -From: rpm-build -Date: Tue, 10 Jan 2023 00:18:48 +0900 -Subject: [PATCH] libreswan-4.1-maintain-obsolete-keywords.patch - ---- - lib/libipsecconf/keywords.c | 28 ++++++++++++++++++++++++++++ - 1 file changed, 28 insertions(+) - -diff --git a/lib/libipsecconf/keywords.c b/lib/libipsecconf/keywords.c -index fa8f0e0..03fb863 100644 ---- a/lib/libipsecconf/keywords.c -+++ b/lib/libipsecconf/keywords.c -@@ -343,6 +343,8 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "ikev1-policy", kv_config, kt_enum, KBF_GLOBAL_IKEv1, kw_global_ikev1_list, NULL, }, - { "curl-iface", kv_config, kt_string, KSF_CURLIFACE, NULL, NULL, }, - { "curl-timeout", kv_config, kt_time, KBF_CURLTIMEOUT_MS, NULL, NULL, }, -+ { "curl_iface", kv_config | kv_alias, kt_string, KSF_CURLIFACE, NULL, NULL, }, /* obsolete _ */ -+ { "curl_timeout", kv_config | kv_alias, kt_time, KBF_CURLTIMEOUT_MS, NULL, NULL, }, /* obsolete _ */ - - { "myvendorid", kv_config, kt_string, KSF_MYVENDORID, NULL, NULL, }, - { "syslog", kv_config, kt_string, KSF_SYSLOG, NULL, NULL, }, -@@ -350,6 +352,7 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "logfile", kv_config, kt_filename, KSF_LOGFILE, NULL, NULL, }, - { "plutostderrlog", kv_config, kt_filename, KSF_LOGFILE, NULL, NULL, }, /* obsolete name, but very common :/ */ - { "logtime", kv_config, kt_bool, KBF_LOGTIME, NULL, NULL, }, -+ { "plutostderrlogtime", kv_config | kv_alias, kt_bool, KBF_LOGTIME, NULL, NULL, }, /* obsolete */ - { "logappend", kv_config, kt_bool, KBF_LOGAPPEND, NULL, NULL, }, - { "logip", kv_config, kt_bool, KBF_LOGIP, NULL, NULL, }, - { "audit-log", kv_config, kt_bool, KBF_AUDIT_LOG, NULL, NULL, }, -@@ -369,13 +372,20 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "global-redirect-to", kv_config, kt_string, KSF_GLOBAL_REDIRECT_TO, NULL, NULL, }, - - { "crl-strict", kv_config, kt_bool, KBF_CRL_STRICT, NULL, NULL, }, -+ { "crl_strict", kv_config | kv_alias, kt_bool, KBF_CRL_STRICT, NULL, NULL, }, /* obsolete _ */ - { "crlcheckinterval", kv_config, kt_time, KBF_CRL_CHECKINTERVAL_MS, NULL, NULL, }, -+ { "strictcrlpolicy", kv_config | kv_alias, kt_bool, KBF_CRL_STRICT, NULL, NULL, }, /* obsolete; used on openswan */ - - { "ocsp-strict", kv_config, kt_bool, KBF_OCSP_STRICT, NULL, NULL, }, -+ { "ocsp_strict", kv_config | kv_alias, kt_bool, KBF_OCSP_STRICT, NULL, NULL, }, /* obsolete _ */ - { "ocsp-enable", kv_config, kt_bool, KBF_OCSP_ENABLE, NULL, NULL, }, -+ { "ocsp_enable", kv_config | kv_alias, kt_bool, KBF_OCSP_ENABLE, NULL, NULL, }, /* obsolete _ */ - { "ocsp-uri", kv_config, kt_string, KSF_OCSP_URI, NULL, NULL, }, -+ { "ocsp_uri", kv_config | kv_alias, kt_string, KSF_OCSP_URI, NULL, NULL, }, /* obsolete _ */ - { "ocsp-timeout", kv_config, kt_number, KBF_OCSP_TIMEOUT, NULL, NULL, }, -+ { "ocsp_timeout", kv_config | kv_alias, kt_number, KBF_OCSP_TIMEOUT, NULL, NULL, }, /* obsolete _ */ - { "ocsp-trustname", kv_config, kt_string, KSF_OCSP_TRUSTNAME, NULL, NULL, }, -+ { "ocsp_trust_name", kv_config | kv_alias, kt_string, KSF_OCSP_TRUSTNAME, NULL, NULL, }, /* obsolete _ */ - { "ocsp-cache-size", kv_config, kt_number, KBF_OCSP_CACHE_SIZE, NULL, NULL, }, - { "ocsp-cache-min-age", kv_config, kt_time, KBF_OCSP_CACHE_MIN_AGE_MS, NULL, NULL, }, - { "ocsp-cache-max-age", kv_config, kt_time, KBF_OCSP_CACHE_MAX_AGE_MS, NULL, NULL, }, -@@ -399,6 +409,7 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "virtual_private", kv_config, kt_string, KSF_VIRTUALPRIVATE, NULL, NULL, }, /* obsolete variant, very common */ - { "seedbits", kv_config, kt_number, KBF_SEEDBITS, NULL, NULL, }, - { "keep-alive", kv_config, kt_number, KBF_KEEPALIVE, NULL, NULL, }, -+ { "keep_alive", kv_config | kv_alias, kt_number, KBF_KEEPALIVE, NULL, NULL, }, /* obsolete _ */ - - { "listen-tcp", kv_config, kt_bool, KBF_LISTEN_TCP, NULL, NULL }, - { "listen-udp", kv_config, kt_bool, KBF_LISTEN_UDP, NULL, NULL }, -@@ -410,6 +421,8 @@ const struct keyword_def ipsec_conf_keywords[] = { - #ifdef HAVE_LABELED_IPSEC - { "ikev1-secctx-attr-type", kv_config, kt_number, KBF_SECCTX, NULL, NULL, }, /* obsolete: not a value, a type */ - { "secctx-attr-type", kv_config | kv_alias, kt_number, KBF_SECCTX, NULL, NULL, }, -+ { "secctx_attr_value", kv_config | kv_alias, kt_number, KBF_SECCTX, NULL, NULL, }, /* obsolete _ */ -+ { "secctx-attr-value", kv_config, kt_number, KBF_SECCTX, NULL, NULL, }, /* obsolete: not a value, a type */ - #endif - { "interfaces", kv_config, kt_obsolete, KNCF_WARNIGNORE, NULL, NULL, }, /* obsoleted but often present keyword */ - -@@ -446,6 +459,7 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "username", kv_conn | kv_leftright, kt_string, KSCF_USERNAME, NULL, NULL, }, - /* xauthusername is still used in NetworkManager-libreswan :/ */ - { "xauthusername", kv_conn | kv_leftright, kt_string, KSCF_USERNAME, NULL, NULL, }, /* old alias */ -+ { "xauthname", kv_conn | kv_leftright, kt_string, KSCF_USERNAME, NULL, NULL, }, /* old alias */ - { "addresspool", kv_conn | kv_leftright, kt_range, KSCF_ADDRESSPOOL, NULL, NULL, }, - { "auth", kv_conn | kv_leftright, kt_enum, KNCF_AUTH, kw_auth_list, NULL, }, - #ifdef HAVE_IPTABLES -@@ -471,6 +485,8 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "esn", kv_conn | kv_processed, kt_enum, KNCF_ESN, kw_esn_list, NULL, }, - { "decap-dscp", kv_conn | kv_processed, kt_bool, KNCF_DECAP_DSCP, NULL, NULL, }, - { "nopmtudisc", kv_conn | kv_processed, kt_bool, KNCF_NOPMTUDISC, NULL, NULL, }, -+ { "ike_frag", kv_conn | kv_processed | kv_alias, kt_enum, KNCF_IKE_FRAG, kw_ynf_list, NULL, }, /* obsolete _ */ -+ { "ike-frag", kv_conn | kv_processed | kv_alias, kt_enum, KNCF_IKE_FRAG, kw_ynf_list, NULL, }, /* obsolete name */ - { "fragmentation", kv_conn | kv_processed, kt_enum, KNCF_IKE_FRAG, kw_ynf_list, NULL, }, - { "mobike", kv_conn, kt_bool, KNCF_MOBIKE, NULL, NULL, }, - { "narrowing", kv_conn, kt_bool, KNCF_IKEv2_ALLOW_NARROWING, NULL, NULL, }, -@@ -481,13 +497,18 @@ const struct keyword_def ipsec_conf_keywords[] = { - { "accept-redirect-to", kv_conn, kt_string, KSCF_ACCEPT_REDIRECT_TO, NULL, NULL, }, - { "pfs", kv_conn, kt_bool, KNCF_PFS, NULL, NULL, }, - -+ { "nat_keepalive", kv_conn | kv_alias, kt_bool, KNCF_NAT_KEEPALIVE, NULL, NULL, }, /* obsolete _ */ - { "nat-keepalive", kv_conn, kt_bool, KNCF_NAT_KEEPALIVE, NULL, NULL, }, - -+ { "initial_contact", kv_conn | kv_alias, kt_bool, KNCF_INITIAL_CONTACT, NULL, NULL, }, /* obsolete _ */ - { "initial-contact", kv_conn, kt_bool, KNCF_INITIAL_CONTACT, NULL, NULL, }, -+ { "cisco_unity", kv_conn | kv_alias, kt_bool, KNCF_CISCO_UNITY, NULL, NULL, }, /* obsolete _ */ - { "cisco-unity", kv_conn, kt_bool, KNCF_CISCO_UNITY, NULL, NULL, }, - { "send-no-esp-tfc", kv_conn, kt_bool, KNCF_NO_ESP_TFC, NULL, NULL, }, - { "fake-strongswan", kv_conn, kt_bool, KNCF_VID_STRONGSWAN, NULL, NULL, }, -+ { "send_vendorid", kv_conn | kv_alias, kt_bool, KNCF_SEND_VENDORID, NULL, NULL, }, /* obsolete _ */ - { "send-vendorid", kv_conn, kt_bool, KNCF_SEND_VENDORID, NULL, NULL, }, -+ { "sha2_truncbug", kv_conn | kv_alias, kt_bool, KNCF_SHA2_TRUNCBUG, NULL, NULL, }, /* obsolete _ */ - { "sha2-truncbug", kv_conn, kt_bool, KNCF_SHA2_TRUNCBUG, NULL, NULL, }, - { "ms-dh-downgrade", kv_conn, kt_bool, KNCF_MSDH_DOWNGRADE, NULL, NULL, }, - { "require-id-on-certificate", kv_conn, kt_bool, KNCF_SAN_ON_CERT, NULL, NULL, }, -@@ -505,7 +526,10 @@ const struct keyword_def ipsec_conf_keywords[] = { - {"ikepad", kv_conn, kt_bool, KNCF_IKEPAD, NULL, NULL, }, - { "nat-ikev1-method", kv_conn | kv_processed, kt_enum, KNCF_IKEV1_NATT, kw_ikev1natt_list, NULL, }, - -+ { "labeled_ipsec", kv_conn, kt_obsolete, KNCF_WARNIGNORE, NULL, NULL, }, /* obsolete */ -+ { "labeled-ipsec", kv_conn, kt_obsolete, KNCF_WARNIGNORE, NULL, NULL, }, /* obsolete */ - { "policy-label", kv_conn, kt_string, KSCF_SA_SEC_LABEL, NULL, NULL, }, /* obsolete variant */ -+ { "policy_label", kv_conn, kt_string, KSCF_SA_SEC_LABEL, NULL, NULL, }, /* obsolete variant */ - { "sec-label", kv_conn, kt_string, KSCF_SA_SEC_LABEL, NULL, NULL, }, /* really stored into struct end */ - - /* Cisco interop: remote peer type */ -@@ -516,13 +540,17 @@ const struct keyword_def ipsec_conf_keywords[] = { - /* Network Manager support */ - #ifdef HAVE_NM - { "nm-configured", kv_conn, kt_bool, KNCF_NMCONFIGURED, NULL, NULL, }, -+ { "nm_configured", kv_conn, kt_bool, KNCF_NMCONFIGURED, NULL, NULL, }, /* obsolete _ */ - #endif - - { "xauthby", kv_conn, kt_enum, KNCF_XAUTHBY, kw_xauthby_list, NULL, }, - { "xauthfail", kv_conn, kt_enum, KNCF_XAUTHFAIL, kw_xauthfail_list, NULL, }, - { "modecfgpull", kv_conn, kt_invertbool, KNCF_MODECONFIGPULL, NULL, NULL, }, - { "modecfgdns", kv_conn, kt_string, KSCF_MODECFGDNS, NULL, NULL, }, -+ { "modecfgdns1", kv_conn | kv_alias, kt_string, KSCF_MODECFGDNS, NULL, NULL, }, /* obsolete */ -+ { "modecfgdns2", kv_conn, kt_obsolete, KNCF_WARNIGNORE, NULL, NULL, }, /* obsolete */ - { "modecfgdomains", kv_conn, kt_string, KSCF_MODECFGDOMAINS, NULL, NULL, }, -+ { "modecfgdomain", kv_conn | kv_alias, kt_string, KSCF_MODECFGDOMAINS, NULL, NULL, }, /* obsolete */ - { "modecfgbanner", kv_conn, kt_string, KSCF_MODECFGBANNER, NULL, NULL, }, - { "ignore-peer-dns", kv_conn, kt_bool, KNCF_IGNORE_PEER_DNS, NULL, NULL, }, - { "mark", kv_conn, kt_string, KSCF_CONN_MARK_BOTH, NULL, NULL, }, --- -2.39.0 - diff --git a/SOURCES/libreswan-4.12-CVE-2026-12413.patch b/SOURCES/libreswan-4.12-CVE-2026-12413.patch deleted file mode 100644 index 05320fc..0000000 --- a/SOURCES/libreswan-4.12-CVE-2026-12413.patch +++ /dev/null @@ -1,25 +0,0 @@ -From b702e3bd21a86214d80305710ddebee8b806a9fd Mon Sep 17 00:00:00 2001 -From: Paul Wouters -Date: Thu, 9 Jul 2026 14:49:51 +0900 -Subject: [PATCH 3/3] Fix for CVE-2026-12413 - ---- - programs/pluto/ikev2_message.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/programs/pluto/ikev2_message.c b/programs/pluto/ikev2_message.c -index 84b289ca8f..a691346218 100644 ---- a/programs/pluto/ikev2_message.c -+++ b/programs/pluto/ikev2_message.c -@@ -1000,7 +1000,7 @@ struct msg_digest *reassemble_v2_incoming_fragments(struct v2_incoming_fragments - passert(md->chain[ISAKMP_NEXT_v2SK] == NULL); - passert(md->chain[ISAKMP_NEXT_v2SKF] != NULL); - pexpect(md->chain[ISAKMP_NEXT_v2SKF]->payload.v2skf.isaskf_number == 1); -- passert(md->digest_roof < elemsof(md->digest)); -+ passert(md->digest_roof <= elemsof(md->digest)); - - /* - * Pass 1: Compute the total payload size. --- -2.54.0 - diff --git a/SOURCES/libreswan-4.12-CVE-2026-14957.patch b/SOURCES/libreswan-4.12-CVE-2026-14957.patch deleted file mode 100644 index 0bc7e24..0000000 --- a/SOURCES/libreswan-4.12-CVE-2026-14957.patch +++ /dev/null @@ -1,76 +0,0 @@ -From bb98559906f03b5d0eb5e598d36d6607f65dfa51 Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Thu, 9 Jul 2026 19:02:42 -0400 -Subject: [PATCH 1/2] x509: tighten nss_compat BER check - ---- - lib/libswan/x509dn.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/lib/libswan/x509dn.c b/lib/libswan/x509dn.c -index 913b944b56..d01f794d7d 100644 ---- a/lib/libswan/x509dn.c -+++ b/lib/libswan/x509dn.c -@@ -378,6 +378,7 @@ static err_t format_dn(struct jambuf *buf, asn1_t dn, - * #BER. - */ - (nss_compatible && -+ value_content.len > 0 && - ((const char*)value_content.ptr)[0] == '#')) { - /* BER */ - jam(buf, "#"); --- -2.54.0 - - -From 784a2d2bf54e38efdd2c6dd64835013c850ad1e0 Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Thu, 9 Jul 2026 19:04:01 -0400 -Subject: [PATCH 2/2] ikev2: check the cert's pubkey unpacked before using it - - cve-2026-14957 - ---- - programs/pluto/nss_cert_verify.c | 27 +++++++++++++++++---------- - 1 file changed, 17 insertions(+), 10 deletions(-) - -diff --git a/programs/pluto/nss_cert_verify.c b/programs/pluto/nss_cert_verify.c -index 3e16566fb1..43af788cb8 100644 ---- a/programs/pluto/nss_cert_verify.c -+++ b/programs/pluto/nss_cert_verify.c -@@ -392,16 +392,23 @@ static void add_decoded_cert(CERTCertDBHandle *handle, - */ - if (libreswan_fipsmode()) { - SECKEYPublicKey *pk = CERT_ExtractPublicKey(cert); -- passert(pk != NULL); -- unsigned key_bit_size = pk->u.rsa.modulus.len * BITS_PER_BYTE; -- if (pk->keyType == rsaKey && key_bit_size < FIPS_MIN_RSA_KEY_SIZE) { -- llog(RC_LOG, logger, -- "FIPS: rejecting peer cert with key size %u under %u: %s", -- key_bit_size, FIPS_MIN_RSA_KEY_SIZE, -- cert->subjectName); -- SECKEY_DestroyPublicKey(pk); -- CERT_DestroyCertificate(cert); -- return; -+ if (pk == NULL) { -+ llog_nss_error(RC_LOG, logger, -+ "extracting certificate public key using CERT_ExtractPublicKey() failed"); -+ return; -+ } -+ -+ if (pk->keyType == rsaKey) { -+ unsigned key_bit_size = pk->u.rsa.modulus.len * BITS_PER_BYTE; -+ if (key_bit_size < FIPS_MIN_RSA_KEY_SIZE) { -+ llog(RC_LOG, logger, -+ "FIPS: rejecting peer cert with key size %u under %u: %s", -+ key_bit_size, FIPS_MIN_RSA_KEY_SIZE, -+ cert->subjectName); -+ SECKEY_DestroyPublicKey(pk); -+ CERT_DestroyCertificate(cert); -+ return; -+ } - } - SECKEY_DestroyPublicKey(pk); - } --- -2.54.0 - diff --git a/SOURCES/libreswan-4.12-CVE-2026-50721.patch b/SOURCES/libreswan-4.12-CVE-2026-50721.patch deleted file mode 100644 index b81e5d2..0000000 --- a/SOURCES/libreswan-4.12-CVE-2026-50721.patch +++ /dev/null @@ -1,83 +0,0 @@ -From c3d8386105c66636d7a47c0a3912389ff2fa0f7d Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Thu, 9 Jul 2026 14:46:10 +0900 -Subject: [PATCH 1/3] crypto: in RSA_authenticate_hash_signature_raw_rsa() use - PK11_Verify() - ---- - lib/libswan/pubkey_rsa.c | 52 ++++++---------------------------------- - 1 file changed, 7 insertions(+), 45 deletions(-) - -diff --git a/lib/libswan/pubkey_rsa.c b/lib/libswan/pubkey_rsa.c -index 38b44ab61d..d2f36cb3da 100644 ---- a/lib/libswan/pubkey_rsa.c -+++ b/lib/libswan/pubkey_rsa.c -@@ -402,58 +402,20 @@ static bool RSA_authenticate_signature_raw_rsa(const struct crypt_mac *expected_ - *expected_hash); - } - -- /* -- * Use the same space used by the out going hash. -- */ -- -- SECItem decrypted_signature = { -- .type = siBuffer, -- }; -- -- if (SECITEM_AllocItem(NULL, &decrypted_signature, signature.len) == NULL) { -- llog_nss_error(RC_LOG, logger, "allocating space for decrypted RSA signature"); -- return false; -- } -- - /* NSS doesn't do const */ -- const SECItem encrypted_signature = { -- .type = siBuffer, -- .data = DISCARD_CONST(unsigned char *, signature.ptr), -- .len = signature.len, -- }; -- -- if (PK11_VerifyRecover(seckey_public, &encrypted_signature, &decrypted_signature, -- lsw_nss_get_password_context(logger)) != SECSuccess) { -- SECITEM_FreeItem(&decrypted_signature, PR_FALSE/*not-pointer*/); -- dbg("NSS RSA verify: decrypting signature is failed"); -- *fatal_diag = NULL; -- return false; -- } - -- if (DBGP(DBG_CRYPT)) { -- LLOG_JAMBUF(DEBUG_STREAM, logger, buf) { -- jam_string(buf, "NSS RSA verify: decrypted sig: "); -- jam_nss_secitem(buf, &decrypted_signature); -- } -- } -+ const SECItem signature_secitem = -+ same_shunk_as_secitem(signature, siBuffer); -+ const SECItem expected_hash_secitem = -+ same_shunk_as_secitem(HUNK_AS_SHUNK(*expected_hash), siBuffer); - -- /* -- * Expect the matching hash to appear at the end. See above -- * for length check. It may, or may not, be prefixed by a -- * PKCS#1 1.5 RSA ASN.1 blob. -- */ -- passert(decrypted_signature.len >= expected_hash->len); -- uint8_t *start = (decrypted_signature.data -- + decrypted_signature.len -- - expected_hash->len); -- if (!memeq(start, expected_hash->ptr, expected_hash->len)) { -- dbg("RSA Signature NOT verified"); -- SECITEM_FreeItem(&decrypted_signature, PR_FALSE/*not-pointer*/); -+ if (PK11_Verify(seckey_public, &signature_secitem, &expected_hash_secitem, -+ lsw_nss_get_password_context(logger)) != SECSuccess) { -+ dbg("NSS RSA verify: decrypting signature is failed"); - *fatal_diag = NULL; - return false; - } - -- SECITEM_FreeItem(&decrypted_signature, PR_FALSE/*not-pointer*/); - *fatal_diag = NULL; - return true; - } --- -2.54.0 - diff --git a/SOURCES/libreswan-4.12-CVE-2026-50722.patch b/SOURCES/libreswan-4.12-CVE-2026-50722.patch deleted file mode 100644 index 529bb78..0000000 --- a/SOURCES/libreswan-4.12-CVE-2026-50722.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 26382ee5fd03ab850c01ba96055636743bbe9c2f Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Thu, 9 Jul 2026 14:46:51 +0900 -Subject: [PATCH 2/3] crypto: in - RSA_authenticate_hash_signature_pkcs1_1_5_rsa() use VFY_VerifyDigestDirect() - ---- - lib/libswan/pubkey_rsa.c | 58 +++++++++------------------------------- - 1 file changed, 12 insertions(+), 46 deletions(-) - -diff --git a/lib/libswan/pubkey_rsa.c b/lib/libswan/pubkey_rsa.c -index d2f36cb3da..0c5a1c91e3 100644 ---- a/lib/libswan/pubkey_rsa.c -+++ b/lib/libswan/pubkey_rsa.c -@@ -491,7 +491,7 @@ static struct hash_signature RSA_sign_hash_pkcs1_1_5_rsa(const struct secret_stu - static bool RSA_authenticate_signature_pkcs1_1_5_rsa(const struct crypt_mac *expected_hash, - shunk_t signature, - struct pubkey *pubkey, -- const struct hash_desc *unused_hash_algo UNUSED, -+ const struct hash_desc *hash_alg, - diag_t *fatal_diag, - struct logger *logger) - { -@@ -509,58 +509,24 @@ static bool RSA_authenticate_signature_pkcs1_1_5_rsa(const struct crypt_mac *exp - *expected_hash); - } - -- /* -- * Use the same space used by the out going hash. -- */ -- -- SECItem decrypted_signature = { -- .type = siBuffer, -- }; -- -- if (SECITEM_AllocItem(NULL, &decrypted_signature, signature.len) == NULL) { -- llog_nss_error(RC_LOG, logger, "allocating space for decrypted RSA signature"); -- return false; -- } -+ SECItem hash_item = -+ same_shunk_as_secitem(HUNK_AS_SHUNK(*expected_hash), siBuffer); - - /* NSS doesn't do const */ -- const SECItem encrypted_signature = { -- .type = siBuffer, -- .data = DISCARD_CONST(unsigned char *, signature.ptr), -- .len = signature.len, -- }; -- -- if (PK11_VerifyRecover(seckey_public, &encrypted_signature, &decrypted_signature, -- lsw_nss_get_password_context(logger)) != SECSuccess) { -- SECITEM_FreeItem(&decrypted_signature, PR_FALSE/*not-pointer*/); -- dbg("NSS RSA verify: decrypting signature is failed"); -- *fatal_diag = NULL; -- return false; -- } -- -- if (DBGP(DBG_CRYPT)) { -- LLOG_JAMBUF(DEBUG_STREAM, logger, buf) { -- jam_string(buf, "NSS RSA verify: decrypted sig: "); -- jam_nss_secitem(buf, &decrypted_signature); -- } -- } -+ SECItem signature_item = -+ same_shunk_as_secitem(signature, siBuffer); - -- /* -- * Expect the matching hash to appear at the end. See above -- * for length check. It may, or may not, be prefixed by a -- * PKCS#1 1.5 RSA ASN.1 blob. -- */ -- passert(decrypted_signature.len >= expected_hash->len); -- uint8_t *start = (decrypted_signature.data -- + decrypted_signature.len -- - expected_hash->len); -- if (!memeq(start, expected_hash->ptr, expected_hash->len)) { -- dbg("RSA Signature NOT verified"); -- SECITEM_FreeItem(&decrypted_signature, PR_FALSE/*not-pointer*/); -+ if (VFY_VerifyDigestDirect(&hash_item, -+ seckey_public, -+ &signature_item, -+ /*pubkey algorithm*/SEC_OID_PKCS1_RSA_ENCRYPTION, -+ /*hash algorithm*/hash_alg->nss.oid_tag, -+ lsw_nss_get_password_context(logger)) != SECSuccess) { -+ ldbg_nss_error(logger, "NSS VFY_VerifyDigest() failed"); - *fatal_diag = NULL; - return false; - } - -- SECITEM_FreeItem(&decrypted_signature, PR_FALSE/*not-pointer*/); - *fatal_diag = NULL; - return true; - } --- -2.54.0 - diff --git a/SOURCES/libreswan-4.12-ikev1-compute-keymat-default.patch b/SOURCES/libreswan-4.12-ikev1-compute-keymat-default.patch deleted file mode 100644 index 7f283f0..0000000 --- a/SOURCES/libreswan-4.12-ikev1-compute-keymat-default.patch +++ /dev/null @@ -1,92 +0,0 @@ -From 5101913b1e623121a9222f11eefa18f0a2708b00 Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Wed, 27 Mar 2024 10:43:19 -0400 -Subject: [PATCH] ikev1: in compute_proto_keymat() only allow explicitly - handled ESP algorithms - ---- - programs/pluto/ikev1_quick.c | 41 ++++++++++++++---------------------- - 1 file changed, 16 insertions(+), 25 deletions(-) - -diff --git a/programs/pluto/ikev1_quick.c b/programs/pluto/ikev1_quick.c -index 81c522c148..22c346afb4 100644 ---- a/programs/pluto/ikev1_quick.c -+++ b/programs/pluto/ikev1_quick.c -@@ -203,7 +203,7 @@ static bool emit_subnet_id(enum perspective perspective, - * RFC 2409 "IKE" section 5.5 - * specifies how this is to be done. - */ --static void compute_proto_keymat(struct state *st, -+static bool compute_proto_keymat(struct state *st, - uint8_t protoid, - struct ipsec_proto_info *pi, - const char *satypename) -@@ -297,27 +297,13 @@ static void compute_proto_keymat(struct state *st, - } - break; - -- case ESP_CAST: -- case ESP_TWOFISH: -- case ESP_SERPENT: -- /* ESP_SEED is for IKEv1 only and not supported. Its number in IKEv2 has been re-used */ -- bad_case(pi->attrs.transattrs.ta_ikev1_encrypt); -- - default: -- /* bytes */ -- needed_len = encrypt_max_key_bit_length(pi->attrs.transattrs.ta_encrypt) / BITS_PER_BYTE; -- if (needed_len > 0) { -- /* XXX: check key_len coupling with kernel.c's */ -- if (pi->attrs.transattrs.enckeylen) { -- needed_len = -- pi->attrs.transattrs.enckeylen -- / BITS_PER_BYTE; -- dbg("compute_proto_keymat: key_len=%d from peer", -- (int)needed_len); -- } -- break; -- } -- bad_case(pi->attrs.transattrs.ta_ikev1_encrypt); -+ { -+ enum_buf eb; -+ llog(RC_LOG, st->st_logger, "rejecting request for keymat for %s", -+ str_enum(&esp_transformid_names, protoid, &eb)); -+ return false; -+ } - } - dbg("compute_proto_keymat: needed_len (after ESP enc)=%d", (int)needed_len); - needed_len += pi->attrs.transattrs.ta_integ->integ_keymat_size; -@@ -359,14 +345,17 @@ static void compute_proto_keymat(struct state *st, - DBG_dump_hunk(" inbound:", pi->inbound.keymat); - DBG_dump_hunk(" outbound:", pi->outbound.keymat); - } -+ -+ return true; - } - --static void compute_keymats(struct state *st) -+static bool compute_keymats(struct state *st) - { - if (st->st_ah.present) -- compute_proto_keymat(st, PROTO_IPSEC_AH, &st->st_ah, "AH"); -+ return compute_proto_keymat(st, PROTO_IPSEC_AH, &st->st_ah, "AH"); - if (st->st_esp.present) -- compute_proto_keymat(st, PROTO_IPSEC_ESP, &st->st_esp, "ESP"); -+ return compute_proto_keymat(st, PROTO_IPSEC_ESP, &st->st_esp, "ESP"); -+ return false; - } - - /* -@@ -1460,7 +1449,9 @@ static stf_status quick_inI1_outR1_continue12_tail(struct state *st, struct msg_ - fixup_v1_HASH(st, &hash_fixup, st->st_v1_msgid.id, rbody.cur); - - /* Derive new keying material */ -- compute_keymats(st); -+ if (!compute_keymats(st)) { -+ return STF_FATAL; -+ } - - /* Tell the kernel to establish the new inbound SA - * (unless the commit bit is set -- which we don't support). --- -2.45.0 - diff --git a/SOURCES/libreswan-4.12-ikev2-auth-delete-state.patch b/SOURCES/libreswan-4.12-ikev2-auth-delete-state.patch deleted file mode 100644 index c17b457..0000000 --- a/SOURCES/libreswan-4.12-ikev2-auth-delete-state.patch +++ /dev/null @@ -1,54 +0,0 @@ -From 2ec448884a7467743699803f8a36ee28d237666c Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Wed, 28 Feb 2024 08:29:53 -0500 -Subject: [PATCH] ikev2: return STF_FATAL when initiator fails to emit AUTH - packet - ---- - programs/pluto/ikev2_ike_auth.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/programs/pluto/ikev2_ike_auth.c b/programs/pluto/ikev2_ike_auth.c -index 192eb1b3b6..a54a109699 100644 ---- a/programs/pluto/ikev2_ike_auth.c -+++ b/programs/pluto/ikev2_ike_auth.c -@@ -1267,7 +1267,7 @@ static stf_status process_v2_IKE_AUTH_request_auth_signature_continue(struct ike - /* now send AUTH payload */ - - if (!emit_local_v2AUTH(ike, auth_sig, &ike->sa.st_v2_id_payload.mac, response.pbs)) { -- return STF_INTERNAL_ERROR; -+ return STF_FATAL; - } - ike->sa.st_v2_ike_intermediate.used = false; - --- -2.44.0 - -From 16272f2475d25baab58fbed2af7c67cfb459137f Mon Sep 17 00:00:00 2001 -From: Andrew Cagney -Date: Thu, 29 Feb 2024 12:19:20 -0500 -Subject: [PATCH] ikev2: always return STF_FATAL if emitting AUTH fails - -Fix: - ikev2: return STF_FATAL when initiator fails to emit AUTH packet -which really fixed the responder. ---- - programs/pluto/ikev2_ike_auth.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/programs/pluto/ikev2_ike_auth.c b/programs/pluto/ikev2_ike_auth.c -index a54a109699..491053fb10 100644 ---- a/programs/pluto/ikev2_ike_auth.c -+++ b/programs/pluto/ikev2_ike_auth.c -@@ -397,7 +397,7 @@ stf_status initiate_v2_IKE_AUTH_request_signature_continue(struct ike_sa *ike, - /* send out the AUTH payload */ - - if (!emit_local_v2AUTH(ike, auth_sig, &ike->sa.st_v2_id_payload.mac, request.pbs)) { -- return STF_INTERNAL_ERROR; -+ return STF_FATAL; - } - - if (LIN(POLICY_MOBIKE, ike->sa.st_connection->policy)) { --- -2.44.0 - diff --git a/SOURCES/libreswan-4.3-1934186-config.patch b/SOURCES/libreswan-4.3-1934186-config.patch deleted file mode 100644 index 022fb47..0000000 --- a/SOURCES/libreswan-4.3-1934186-config.patch +++ /dev/null @@ -1,11 +0,0 @@ -diff -Naur libreswan-4.3-orig/configs/ipsec.conf.in libreswan-4.3/configs/ipsec.conf.in ---- libreswan-4.3-orig/configs/ipsec.conf.in 2021-03-04 14:29:50.591912834 -0500 -+++ libreswan-4.3/configs/ipsec.conf.in 2021-03-04 14:30:27.227389433 -0500 -@@ -32,6 +32,7 @@ - # listen-tcp=yes - # To enable IKE and IPsec over TCP for VPN client, also specify - # tcp-remote-port=4500 in the client's conn section. -+ virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:25.0.0.0/8,%v4:100.64.0.0/10,%v6:fd00::/8,%v6:fe80::/10 - - # if it exists, include system wide crypto-policy defaults - # include /etc/crypto-policies/back-ends/libreswan.config diff --git a/SOURCES/libreswan-4.3-maintain-different-v1v2-split.patch b/SOURCES/libreswan-4.3-maintain-different-v1v2-split.patch deleted file mode 100644 index 68c94eb..0000000 --- a/SOURCES/libreswan-4.3-maintain-different-v1v2-split.patch +++ /dev/null @@ -1,85 +0,0 @@ -From 83487373fdd77437e51cfccd41532e270e279e05 Mon Sep 17 00:00:00 2001 -From: rpm-build -Date: Tue, 10 Jan 2023 00:11:26 +0900 -Subject: [PATCH] libreswan-4.3-maintain-different-v1v2-split.patch - ---- - configs/d.ipsec.conf/ikev2.xml | 14 +++++++------- - lib/libipsecconf/confread.c | 8 +++++++- - programs/whack/whack.c | 4 ++-- - 3 files changed, 16 insertions(+), 10 deletions(-) - -diff --git a/configs/d.ipsec.conf/ikev2.xml b/configs/d.ipsec.conf/ikev2.xml -index 3d03825..285db1b 100644 ---- a/configs/d.ipsec.conf/ikev2.xml -+++ b/configs/d.ipsec.conf/ikev2.xml -@@ -2,14 +2,14 @@ - ikev2 - - Whether to use IKEv2 (RFC 7296) or IKEv1 (RFC 4301). --Currently the accepted values are yes (the default), --signifying only IKEv2 is accepted, or no, -+Currently the accepted values are insist (the default), -+signifying only IKEv2 is accepted, or no (or never), - signifying only IKEv1 is accepted. Previous versions allowed the keywords --propose or permit --that would allow either IKEv1 or IKEv2, but this is no longer supported. The --permit option is interpreted as no and the propose option is interpreted as --yes. Older versions also supported keyword --insist which is now interpreted as yes. -+propose, yes or permit -+that would allow either IKEv1 or IKEv2, but this is no longer supported and both options -+now cause the connection to fail to load. WARNING: This behaviour differs from upstream -+libreswan, which only accepts yes or no where yes means -+the same as insist. - - - -diff --git a/lib/libipsecconf/confread.c b/lib/libipsecconf/confread.c -index b95c90a..e752441 100644 ---- a/lib/libipsecconf/confread.c -+++ b/lib/libipsecconf/confread.c -@@ -1340,11 +1340,17 @@ static bool load_conn(struct starter_conn *conn, - - switch (conn->options[KNCF_IKEv2]) { - case fo_never: -- case fo_permit: - conn->ike_version = IKEv1; - break; - -+ case fo_permit: -+ starter_error_append(perrl, "ikev2=permit is no longer accepted. Use ikev2=insist or ikev2=no|never"); -+ return true; -+ - case fo_propose: -+ starter_error_append(perrl, "ikev2=propose or ikev2=yes is no longer accepted. Use ikev2=insist or ikev2=no|never"); -+ return true; -+ - case fo_insist: - conn->ike_version = IKEv2; - break; -diff --git a/programs/whack/whack.c b/programs/whack/whack.c -index b512b04..3de020e 100644 ---- a/programs/whack/whack.c -+++ b/programs/whack/whack.c -@@ -815,7 +815,7 @@ static const struct option long_opts[] = { - { "ikev1-allow", no_argument, NULL, CD_IKEv1 + OO }, /* obsolete name */ - { "ikev2", no_argument, NULL, CD_IKEv2 +OO }, - { "ikev2-allow", no_argument, NULL, CD_IKEv2 +OO }, /* obsolete name */ -- { "ikev2-propose", no_argument, NULL, CD_IKEv2 +OO }, /* obsolete, map onto allow */ -+ /* not in RHEL8 { "ikev2-propose", no_argument, NULL, CD_IKEv2 +OO }, */ - - PS("allow-narrowing", IKEV2_ALLOW_NARROWING), - #ifdef AUTH_HAVE_PAM -@@ -1802,7 +1802,7 @@ int main(int argc, char **argv) - end_seen = LEMPTY; - continue; - -- /* --ikev1 --ikev2 --ikev2-propose */ -+ /* --ikev1 --ikev2 */ - case CD_IKEv1: - case CD_IKEv2: - { --- -2.39.0 - diff --git a/SOURCES/libreswan-4.9-2176248-authby-rsasig.patch b/SOURCES/libreswan-4.9-2176248-authby-rsasig.patch deleted file mode 100644 index 9569e86..0000000 --- a/SOURCES/libreswan-4.9-2176248-authby-rsasig.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 000b230258dd272ab15b384c330c31f996d0ba18 Mon Sep 17 00:00:00 2001 -From: Daiki Ueno -Date: Fri, 14 Apr 2023 14:10:47 +0900 -Subject: [PATCH] Ignore system crypto-policies for SHA-1 for legacy - authby=rsa-sha1 - -Signed-off-by: Daiki Ueno ---- - lib/libswan/pubkey_rsa.c | 24 ++++++++++++++++++++++++ - 1 file changed, 24 insertions(+) - -diff --git a/lib/libswan/pubkey_rsa.c b/lib/libswan/pubkey_rsa.c -index 38b44ab61d..9a7c0bc6a8 100644 ---- a/lib/libswan/pubkey_rsa.c -+++ b/lib/libswan/pubkey_rsa.c -@@ -501,9 +501,33 @@ static struct hash_signature RSA_sign_hash_pkcs1_1_5_rsa(const struct secret_stu - * used to generate the signature. - */ - SECItem signature_result = {0}; -+ -+ /* ignore system crypto-policies for the hash algorithm */ -+ PRUint32 saved_policy; -+ -+ if (NSS_GetAlgorithmPolicy(hash_algo->nss.oid_tag, &saved_policy) != SECSuccess) { -+ /* PR_GetError() returns the thread-local error */ -+ enum_buf tb; -+ llog_nss_error(RC_LOG_SERIOUS, logger, -+ "NSS_SetAlgorithmPolicy(%s) function failed", -+ str_nss_oid(hash_algo->nss.oid_tag, &tb)); -+ return (struct hash_signature) { .len = 0, }; -+ } -+ -+ if (!(saved_policy & NSS_USE_ALG_IN_SIGNATURE)) { -+ (void)NSS_SetAlgorithmPolicy(hash_algo->nss.oid_tag, -+ NSS_USE_ALG_IN_SIGNATURE, 0); -+ } -+ - SECStatus s = SGN_Digest(pks->u.pubkey.private_key, - hash_algo->nss.oid_tag, - &signature_result, &digest); -+ -+ if (!(saved_policy & NSS_USE_ALG_IN_SIGNATURE)) { -+ (void)NSS_SetAlgorithmPolicy(hash_algo->nss.oid_tag, -+ saved_policy, ~saved_policy); -+ } -+ - if (s != SECSuccess) { - /* PR_GetError() returns the thread-local error */ - enum_buf tb; --- -2.40.0 - diff --git a/SPECS/libreswan.spec b/SPECS/libreswan.spec deleted file mode 100644 index d757782..0000000 --- a/SPECS/libreswan.spec +++ /dev/null @@ -1,542 +0,0 @@ -%global _hardened_build 1 -# These are rpm macros and are 0 or 1 -%global with_efence 0 -%global with_development 0 -%global with_cavstests 1 -# minimum version for support for rhbz#1651314 -# should prob update for nss with IKEv1 quick mode support -%global nss_version 3.53.1 -%global unbound_version 1.6.6 -%global libreswan_config \\\ - FINALLIBEXECDIR=%{_libexecdir}/ipsec \\\ - FINALMANDIR=%{_mandir} \\\ - FINALNSSDIR=%{_sysconfdir}/ipsec.d \\\ - INITSYSTEM=systemd \\\ - NSS_HAS_IPSEC_PROFILE=true \\\ - NSS_REQ_AVA_COPY=false \\\ - PREFIX=%{_prefix} \\\ - PYTHON_BINARY=%{__python3} \\\ - SHELL_BINARY=%{_bindir}/sh \\\ - USE_DNSSEC=true \\\ - USE_FIPSCHECK=false \\\ - USE_LABELED_IPSEC=true \\\ - USE_LDAP=true \\\ - USE_LIBCAP_NG=true \\\ - USE_LIBCURL=true \\\ - USE_LINUX_AUDIT=true \\\ - USE_NM=true \\\ - USE_NSS_KDF=true \\\ - USE_SECCOMP=true \\\ - USE_AUTHPAM=true \\\ - USE_DH2=true \\\ -%{nil} - -#global prever rc1 - -Name: libreswan -Summary: IPsec implementation with IKEv1 and IKEv2 keying protocols -# version is generated in the release script -Version: 4.12 -Release: %{?prever:0.}2%{?prever:.%{prever}}%{?dist}.6 -License: GPLv2 -Url: https://libreswan.org/ - -Source0: https://download.libreswan.org/%{?prever:with_development/}%{name}-%{version}%{?prever}.tar.gz -%if 0%{with_cavstests} -Source1: https://download.libreswan.org/cavs/ikev1_dsa.fax.bz2 -Source2: https://download.libreswan.org/cavs/ikev1_psk.fax.bz2 -Source3: https://download.libreswan.org/cavs/ikev2.fax.bz2 -%endif - -Patch1: libreswan-4.3-maintain-different-v1v2-split.patch -Patch2: libreswan-3.32-1861360-nodefault-rsa-pss.patch -Patch3: libreswan-4.1-maintain-obsolete-keywords.patch -Patch6: libreswan-4.3-1934186-config.patch -Patch7: libreswan-4.9-2176248-authby-rsasig.patch -Patch8: libreswan-4.12-ikev2-auth-delete-state.patch -Patch9: libreswan-4.12-ikev1-compute-keymat-default.patch -Patch10: libreswan-4.12-CVE-2026-12413.patch -Patch11: libreswan-4.12-CVE-2026-50721.patch -Patch12: libreswan-4.12-CVE-2026-50722.patch -Patch13: libreswan-4.12-CVE-2026-14957.patch - -BuildRequires: audit-libs-devel -BuildRequires: bison -BuildRequires: curl-devel -BuildRequires: flex -BuildRequires: gcc make -BuildRequires: ldns-devel -BuildRequires: libcap-ng-devel -BuildRequires: libevent-devel -BuildRequires: libseccomp-devel -BuildRequires: libselinux-devel -BuildRequires: nspr-devel -BuildRequires: nss-devel >= %{nss_version} -BuildRequires: nss-tools -BuildRequires: openldap-devel -BuildRequires: pam-devel -BuildRequires: pkgconfig -BuildRequires: hostname -BuildRequires: redhat-rpm-config -BuildRequires: systemd-devel -BuildRequires: unbound-devel >= %{unbound_version} -BuildRequires: xmlto -%if 0%{with_efence} -BuildRequires: ElectricFence -%endif -Requires: iproute >= 2.6.8 -Requires: nss >= %{nss_version} -Requires: nss-softokn -Requires: nss-tools -Requires: unbound-libs >= %{unbound_version} -Requires(post): bash -Requires(post): coreutils -Requires(post): systemd -Requires(preun): systemd -Requires(postun): systemd - -%description -Libreswan is a free implementation of IKE/IPsec for Linux. IPsec is -the Internet Protocol Security and uses strong cryptography to provide -both authentication and encryption services. These services allow you -to build secure tunnels through untrusted networks. Everything passing -through the untrusted net is encrypted by the ipsec gateway machine and -decrypted by the gateway at the other end of the tunnel. The resulting -tunnel is a virtual private network or VPN. - -This package contains the daemons and userland tools for setting up -Libreswan. - -Libreswan also supports IKEv2 (RFC7296) and Secure Labeling - -Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04 - -%prep -%setup -q -n libreswan-%{version}%{?prever} -%patch1 -p1 -%patch2 -p1 -%patch3 -p1 -%patch6 -p1 -%patch7 -p1 -%patch8 -p1 -%patch9 -p1 -%patch10 -p1 -%patch11 -p1 -%patch12 -p1 -%patch13 -p1 - -# linking to freebl is not needed -sed -i "s/-lfreebl //" mk/config.mk - -# enable crypto-policies support -sed -i "s:#[ ]*include \(.*\)\(/crypto-policies/back-ends/libreswan.config\)$:include \1\2:" configs/ipsec.conf.in - -%build -make %{?_smp_mflags} \ -%if 0%{with_development} - OPTIMIZE_CFLAGS="%{?_hardened_cflags}" \ -%else - OPTIMIZE_CFLAGS="%{optflags}" \ -%endif -%if 0%{with_efence} - USE_EFENCE=true \ -%endif - WERROR_CFLAGS="-Werror -Wno-missing-field-initializers" \ - USERLINK="%{?__global_ldflags}" \ - %{libreswan_config} \ - programs -FS=$(pwd) - -%install -make \ - DESTDIR=%{buildroot} \ - %{libreswan_config} \ - install -FS=$(pwd) -rm -rf %{buildroot}/usr/share/doc/libreswan -rm -rf %{buildroot}%{_libexecdir}/ipsec/*check - -install -d -m 0755 %{buildroot}%{_rundir}/pluto -install -d %{buildroot}%{_sbindir} - -install -d %{buildroot}%{_sysconfdir}/sysctl.d -install -m 0644 packaging/fedora/libreswan-sysctl.conf \ - %{buildroot}%{_sysconfdir}/sysctl.d/50-libreswan.conf - -echo "include %{_sysconfdir}/ipsec.d/*.secrets" \ - > %{buildroot}%{_sysconfdir}/ipsec.secrets -rm -fr %{buildroot}%{_sysconfdir}/rc.d/rc* - -%if 0%{with_cavstests} -%check -# There is an elaborate upstream testing infrastructure which we do not -# run here - it takes hours and uses kvm -# We only run the CAVS tests. -cp %{SOURCE1} %{SOURCE2} %{SOURCE3} . -bunzip2 *.fax.bz2 - -: starting CAVS test for IKEv2 -%{buildroot}%{_libexecdir}/ipsec/cavp -v2 ikev2.fax | \ - diff -u ikev2.fax - > /dev/null -: starting CAVS test for IKEv1 RSASIG -%{buildroot}%{_libexecdir}/ipsec/cavp -v1dsa ikev1_dsa.fax | \ - diff -u ikev1_dsa.fax - > /dev/null -: starting CAVS test for IKEv1 PSK -%{buildroot}%{_libexecdir}/ipsec/cavp -v1psk ikev1_psk.fax | \ - diff -u ikev1_psk.fax - > /dev/null -: CAVS tests passed - -# Some of these tests will show ERROR for negative testing - it will exit on real errors -%{buildroot}%{_libexecdir}/ipsec/algparse -tp || { echo prooposal test failed; exit 1; } -%{buildroot}%{_libexecdir}/ipsec/algparse -ta || { echo algorithm test failed; exit 1; } -: Algorithm parser tests passed - -# self test for pluto daemon - this also shows which algorithms it allows in FIPS mode -tmpdir=$(mktemp -d /tmp/libreswan-XXXXX) -certutil -N -d sql:$tmpdir --empty-password -%{buildroot}%{_libexecdir}/ipsec/pluto --selftest --nssdir $tmpdir --rundir $tmpdir -: pluto self-test passed - verify FIPS algorithms allowed is still compliant with NIST - -%endif - -%post -%systemd_post ipsec.service - -%preun -%systemd_preun ipsec.service - -%postun -%systemd_postun_with_restart ipsec.service - -%files -%doc CHANGES COPYING CREDITS README* LICENSE -%doc docs/*.* docs/examples -%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ipsec.conf -%attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ipsec.secrets -%attr(0700,root,root) %dir %{_sysconfdir}/ipsec.d -%attr(0700,root,root) %dir %{_sysconfdir}/ipsec.d/policies -%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ipsec.d/policies/* -%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/sysctl.d/50-libreswan.conf -%attr(0755,root,root) %dir %{_rundir}/pluto -%attr(0644,root,root) %{_tmpfilesdir}/libreswan.conf -%attr(0644,root,root) %{_unitdir}/ipsec.service -%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/pam.d/pluto -%config(noreplace) %{_sysconfdir}/logrotate.d/libreswan -%{_sbindir}/ipsec -%{_libexecdir}/ipsec -%attr(0644,root,root) %doc %{_mandir}/*/* - -%changelog -* Thu Jul 23 2026 Daiki Ueno - 4.12-2.6 -- Backport fix for CVE-2026-14957 (RHEL-212498) - -* Thu Jul 09 2026 Daiki Ueno - 4.12-2.5 -- Backport fixes for CVE-2026-12413, CVE-2026-50721 and CVE-2026-50722 (RHEL-190146, RHEL-190140, RHEL-190132) - -* Thu Jun 6 2024 Daiki Ueno - 4.12-2.4 -- Fix CVE-2024-3652 (RHEL-32482) - -* Wed Apr 17 2024 Daiki Ueno - 4.12-2.3 -- Bump release to ensure el8 package is greater than el8_* packages - -* Tue Apr 16 2024 Daiki Ueno - 4.12-2.2 -- Fix patch application in the previous change - -* Mon Apr 15 2024 Daiki Ueno - 4.12-2.1 -- Fix CVE-2024-2357 (RHEL-28742) - -* Fri Aug 25 2023 Daiki Ueno - 4.12-2 -- Resolves: rhbz#2234731 authby=rsasig fails in FIPS policy - -* Wed Aug 9 2023 Daiki Ueno - 4.12-1 -- Update to 4.12 to fix CVE-2023-38710, CVE-2023-38711, CVE-2023-38712 -- Resolves: rhbz#2215955 - -* Thu May 04 2023 Sahana Prasad - 4.9-2 -- Fix CVE-2023-30570 Malicious IKEv1 Aggressive Mode packets can crash libreswan -- Resolves: rhbz#2187179 - -* Mon Jan 9 2023 Daiki Ueno - 4.9-1 -- Resolves: rhbz#2128672 Rebase libreswan to 4.9 -- Remove libreswan-4.4-ikev1-disable-diagnostics.patch no longer necessary - -* Thu Jan 13 2022 Daiki Ueno - 4.5-1 -- Resolves: rhbz#2017352 Rebase libreswan to 4.5 -- Resolves: rhbz#2036903 ikev1: disable diagnostics logging on receiving malformed packets - -* Wed May 26 2021 Daiki Ueno - 4.4-1 -- Resolves: rhbz#1958968 Rebase libreswan to 4.4 -- Resolves: rhbz#1954423 Libreswan: TS_UNACCEPTABLE on multiple connections between the same peers - -* Thu Mar 04 2021 Paul Wouters - 4.3-3 -- Resolves: rhbz#1933064 - IKEv2 support for Labeled IPsec -- Resolves: rhbz#1935150 RFE: Support IKE and ESP over TCP: RFC 8229 -- Resolves: rhbz#1935339 virtual_private setting is missing in the default config - -* Sun Feb 21 2021 Paul Wouters - 4.3-1 -- Resolves: rhbz#1025061 - IKEv2 support for Labeled IPsec [update] - -* Thu Feb 04 2021 Paul Wouters - 4.2-1 -- Resolves: rhbz#1891128 [Rebase] rebase libreswan to 4.2 -- Resolves: rhbz#1025061 - IKEv2 support for Labeled IPsec - -* Tue Oct 27 22:11:42 EDT 2020 Paul Wouters - 4.1-1 -- Resolves: rhbz#1891128 [Rebase] rebase libreswan to 4.1 -- Resolves: rhbz#1889836 libreswan: add 3.x compat patches for obsoleted/removed keywords of 4.0 and re-port ikev2= patch - -* Wed Jul 29 2020 Paul Wouters - 3.32-6 -- Resolves: rhbz#1861360 authby=rsasig must not imply usage of rsa-pss - -* Wed Jul 22 2020 Paul Wouters - 3.32-5 -- Resolves: rhbz#1820206 Rebase to libreswan 3.32 [rebuild for USE_NSS_PRF] - -* Wed Jul 01 2020 Paul Wouters - 3.32-4 -- Resolves: rhbz#1544463 ipsec service does not work correctly when seccomp filtering is enabled - -* Wed Jun 17 2020 Paul Wouters - 3.32-3 -- Resolves: rhbz#1842597 regression: libreswan does not send PLUTO_BYTES env variables to updown script -- Resolves: rhbz#1847766 subsequent xfrmi interfaces configured outside of libreswan are not recognised properly -- Resolves: rhbz#1840212 protect libreswan against unannounced nss ABI change - -* Thu Jun 11 2020 Paul Wouters - 3.32-2 -- Resolves: rhbz#1820206 Rebase to libreswan 3.32 [addconn fix] - -* Thu Apr 30 2020 Paul Wouters - 3.32-1 -- Resolves: rhbz#1820206 Rebase to libreswan 3.32 -- Resolves: rhbz#1816265 Use NSS to check whether FIPS mode is enabled -- Resolves: rhbz#1826337 libreswan in FIPS mode rejects ECDSA keys based on faulty RSA key size check being applied - -* Tue Aug 13 2019 Paul Wouters - 3.29-6 -- Resolves: rhbz#1714331 support NSS based IKE KDF's [require updated nss for rhbz 1738689, memleak fix] - -* Thu Aug 08 2019 Paul Wouters - 3.29-5 -- Resolves: rhbz#1714331 support NSS based IKE KDF's so libreswan does not need FIPS certification - -* Thu Aug 01 2019 Paul Wouters - 3.29-4 -- Resolves: rhbz#1699318 'ipsec show' has python3 invalid syntax - -* Thu Jul 04 2019 Paul Wouters - 3.29-3 -- Resolves: rhbz#1725205 XFRM policy for OE/32 peer is deleted when shunts for previous half-open state expire - -* Thu Jun 27 2019 Paul Wouters - 3.29-2 -- Resolves: rhbz#1723957 libreswan is missing linux audit calls for failed IKE SAs and failed IPsec SAs required for Common Criteria - -* Mon Jun 10 2019 Paul Wouters - 3.29-1 -- Resolves: rhbz#1712555 libreswan rebase to 3.29 - -* Tue May 28 2019 Paul Wouters - 3.28-2 -- Resolves: rhbz#1713734: barf: shell syntax error in barf diagnostic tool - -* Tue May 21 2019 Paul Wouters - 3.28-1 -- Resolves: rhbz#1712555 libreswan rebase to 3.28 -- Resolves: rhbz#1683706 Libreswan shows incorrect error messages -- Resolves: rhbz#1706180 Remove last usage of old (unused) PF_KEY API -- Resolves: rhbz#1677045 Opportunistic IPsec instances of /32 groups or auto=start that receive delete won't restart -- Resolves: rhbz#1686990 IKEv1 traffic interruption when responder deletes SAs 60 seconds before EVENT_SA_REPLACE -- Resolves: rhbz#1608353 /usr/sbin/ipsec part of the libreswan packages still invokes commands that were deprecated a decade ago -- Resolves: rhbz#1699318 'ipsec show' has python3 invalid syntax -- Resolves: rhbz#1679394 libreswan using NSS IPsec profiles regresses when critical flags are set causing validation failure - -* Thu Feb 21 2019 Paul Wouters - 3.27-9 -- Resolves: rhbz#1648776 limit connections to be ikev1only or ikev2only and make ikev2only the default [man page update] - -* Fri Feb 15 2019 Paul Wouters - 3.27-8 -- Resolves: rhbz#1664101 system wide crypto policies causing IKE_INIT packet fragmentation - -* Tue Feb 05 2019 Paul Wouters - 3.27-7 -- Resolves: rhbz#1671793 proessing ISAKMP_NEXT_D with additional payloads causes dangling pointer to deleted state - -* Fri Feb 01 2019 Paul Wouters - 3.27-6 -- Resolves: rhbz#1668342 SELinux prevents libreswan from using some outbound ports causing DNS resolution failures at connection at load time - -* Thu Jan 10 2019 Paul Wouters - 3.27-5 -- Resolves: rhbz#1664522 libreswan 3.25 in FIPS mode is incorrectly rejecting X.509 public keys that are >= 3072 bits - -* Mon Dec 10 2018 Paul Wouters - 3.27-4 -- Resolves: rhbz#1657846 libreswan no longer needs to provide openswan in rhel8 -- Resolves: rhbz#1643388 libreswan: Unable to verify certificate with non-empty Extended Key Usage which does not include serverAuth or clientAuth -- Resolves: rhbz#1657854 remove userland support for deprecated KLIPS IPsec stack support - -* Sun Dec 09 2018 Paul Wouters - 3.27-3 -- Resolves: rhbz#1648776 limit connections to be ikev1only or ikev2only and make ikev2only the default - -* Thu Nov 08 2018 Paul Wouters - 3.27-2 -- Resolves: rhbz#1645137 Libreswan segfaults when it loads configuration file with more then 5 connections - -* Mon Oct 08 2018 Paul Wouters - 3.27-1 -- Resolves: rhbz#1566574 Rebase to libreswan 3.27 - -* Mon Sep 17 2018 Paul Wouters - 3.26-1 -- Resolves: rhbz#1566574 Rebase to libreswan 3.26 -- Resolves: rhbz#1527037 libreswan IPSEC implementation: should follow the policies of system-wide crypto policy -- Resolves: rhbz#1375779 [IKEv2 Conformance] Test IKEv2.EN.R.1.1.6.7: Sending INVALID_KE_PAYLOAD failed -- Resolves: rhbz#1085758 [TAHI][IKEv2] IKEv2.EN.I.1.2.1.1: Can't observe CREATE_CHILD_SA request for rekey -- Resolves: rhbz#1053048 [TAHI][IKEv2] IKEv2.EN.I.1.2.4.1-7: libreswan doesn't sent CREATE_CHILD_SA after IKE_SA Lifetime timeout - -* Mon Aug 13 2018 Paul Wouters - 3.25-4 -- Resolves: rhbz#1590823 libreswan: Use Python 3 in RHEL 8 - -* Wed Aug 01 2018 Charalampos Stratakis - 3.25-3.1 -- Rebuild for platform-python - -* Mon Jul 09 2018 Paul Wouters - 3.25-3 -- Cleanup shebangs for python3 -- Use the same options via macro for make programs and make install -- Remove old ifdefs -- Sync up patches to new upstream version -- Add Requires: for unbound-libs >= 1.6.6 -- Enable crypto-policies support -- Make rundir world readable for easier permission granting for socket - -* Tue Jun 26 2018 Charalampos Stratakis - 3.23-2.2 -- Make python shebangs point to python3 - -* Fri Jun 22 2018 Troy Dawson - 3.23-2.1 -- Fix python shebangs (#1580773) - -* Mon Feb 19 2018 Paul Wouters - 3.23-2 -- Support crypto-policies package -- Pull in some patches from upstream and IANA registry updates -- gcc7 format-truncate fixes and workarounds - -* Wed Feb 07 2018 Fedora Release Engineering - 3.23-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild - -* Thu Jan 25 2018 Paul Wouters - 3.23-1 -- Updated to 3.23 - support for MOBIKE, PPK, CMAC, nic offload and performance improvements - -* Sat Jan 20 2018 Björn Esser - 3.22-1.1 -- Rebuilt for switch to libxcrypt - -* Mon Oct 23 2017 Paul Wouters - 3.22-1 -- Updated to 3.22 - many bugfixes, and unbound ipsecmod support - -* Wed Aug 9 2017 Paul Wouters - 3.21-1 -- Updated to 3.21 - -* Thu Aug 03 2017 Fedora Release Engineering - 3.20-1.2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild - -* Wed Jul 26 2017 Fedora Release Engineering - 3.20-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild - -* Tue Mar 14 2017 Paul Wouters - 3.20-1 -- Updated to 3.20 - -* Fri Mar 03 2017 Paul Wouters - 3.20-0.1.dr4 -- Update to 3.20dr4 to test mozbz#1336487 export CERT_CompareAVA - -* Fri Feb 10 2017 Fedora Release Engineering - 3.19-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild - -* Fri Feb 03 2017 Paul Wouters - 3.19-2 -- Resolves: rhbz#1392191 libreswan: crash when OSX client connects -- Improved uniqueid and session replacing support -- Test Buffer warning fix on size_t -- Re-introduce --configdir for backwards compatibility - -* Sun Jan 15 2017 Paul Wouters - 3.19-1 -- Updated to 3.19 (see download.libreswan.org/CHANGES) - -* Mon Dec 19 2016 Miro Hrončok - 3.18-1.1 -- Rebuild for Python 3.6 - -* Fri Jul 29 2016 Paul Wouters - 3.18-1 -- Updated to 3.18 for CVE-2016-5391 rhbz#1361164 and VTI support -- Remove support for /etc/sysconfig/pluto (use native systemd instead) - -* Thu May 05 2016 Paul Wouters - 3.17-2 -- Resolves: rhbz#1324956 prelink is gone, /etc/prelink.conf.d/* is no longer used - -* Thu Apr 07 2016 Paul Wouters - 3.17-1 -- Updated to 3.17 for CVE-2016-3071 -- Disable LIBCAP_NG as it prevents unbound-control from working properly -- Temporarilly disable WERROR due to a few minor known issues - -* Thu Feb 04 2016 Fedora Release Engineering - 3.16-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild - -* Fri Dec 18 2015 Paul Wouters - 3.16-1 -- Updated to 3.16 (see https://download.libreswan.org/CHANGES) - -* Tue Aug 11 2015 Paul Wouters - 3.15-1 -- Updated to 3.15 (see http://download.libreswan.org/CHANGES) -- Resolves: rhbz#CVE-2015-3240 IKE daemon restart when receiving a bad DH gx -- NSS database creation moved from spec file to service file -- Run CAVS tests on package build -- Added BuildRequire systemd-units and xmlto -- Bumped minimum required nss to 3.16.1 -- Install tmpfiles -- Install sysctl file -- Update doc files to include - -* Mon Jul 13 2015 Paul Wouters - 3.13-2 -- Resolves: rhbz#1238967 Switch libreswan to use python3 - -* Wed Jun 17 2015 Fedora Release Engineering - 3.13-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild - -* Mon Jun 01 2015 Paul Wouters - 3.13-1 -- Updated to 3.13 for CVE-2015-3204 - -* Fri Nov 07 2014 Paul Wouters - 3.12-1 -- Updated to 3.12 Various IKEv2 fixes - -* Wed Oct 22 2014 Paul Wouters - 3.11-1 -- Updated to 3.11 (many fixes, including startup fixes) -- Resolves: rhbz#1144941 libreswan 3.10 upgrade breaks old ipsec.secrets configs -- Resolves: rhbz#1147072 ikev1 aggr mode connection fails after libreswan upgrade -- Resolves: rhbz#1144831 Libreswan appears to start with systemd before all the NICs are up and running - -* Tue Sep 09 2014 Paul Wouters - 3.10-3 -- Fix some coverity issues, auto=route on bootup and snprintf on 32bit machines - -* Mon Sep 01 2014 Paul Wouters - 3.10-1 -- Updated to 3.10, major bugfix release, new xauth status options - -* Sun Aug 17 2014 Fedora Release Engineering - 3.9-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild - -* Thu Jul 10 2014 Paul Wouters - 3.9-1 -- Updated to 3.9. IKEv2 enhancements, ESP/IKE algo enhancements -- Mark libreswan-fips.conf as config file -- attr modifier for man pages no longer needed -- BUGS file no longer exists upstream - -* Sat Jun 07 2014 Fedora Release Engineering - 3.8-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild - -* Sat Jan 18 2014 Paul Wouters - 3.8-1 -- Updated to 3.8, fixes rhbz#CVE-2013-6467 (rhbz#1054102) - -* Wed Dec 11 2013 Paul Wouters - 3.7-1 -- Updated to 3.7, fixes CVE-2013-4564 -- Fixes creating a bogus NSS db on startup (rhbz#1005410) - -* Thu Oct 31 2013 Paul Wouters - 3.6-1 -- Updated to 3.6 (IKEv2, MODECFG, Cisco interop fixes) -- Generate empty NSS db if none exists - -* Mon Aug 19 2013 Paul Wouters - 3.5-3 -- Add a Provides: for openswan-doc - -* Sat Aug 03 2013 Fedora Release Engineering - 3.5-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild - -* Mon Jul 15 2013 Paul Wouters - 3.5-2 -- Added interop patch for (some?) Cisco VPN clients sending 16 zero - bytes of extraneous IKE data -- Removed fipscheck_version - -* Sat Jul 13 2013 Paul Wouters - 3.5-1 -- Updated to 3.5 - -* Thu Jun 06 2013 Paul Wouters - 3.4-1 -- Updated to 3.4, which only contains style changes to kernel coding style -- IN MEMORIAM: June 3rd, 2013 Hugh Daniel - -* Mon May 13 2013 Paul Wouters - 3.3-1 -- Updated to 3.3, which resolves CVE-2013-2052 - -* Sat Apr 13 2013 Paul Wouters - 3.2-1 -- Initial package for Fedora diff --git a/libreswan-4.15-ipsec_import.patch b/libreswan-4.15-ipsec_import.patch new file mode 100644 index 0000000..129fbfd --- /dev/null +++ b/libreswan-4.15-ipsec_import.patch @@ -0,0 +1,20 @@ +diff --git a/programs/ipsec/ipsec.in b/programs/ipsec/ipsec.in +index 40ff9f4138..41813b5258 100755 +--- a/programs/ipsec/ipsec.in ++++ b/programs/ipsec/ipsec.in +@@ -758,7 +758,14 @@ ipsec_import() { + exit 1 + fi + +- pk12util -i "${pkcs12bundle}" -d "${IPSEC_NSSDIR_SQL}" ++ # First try blanc password to avoid uselessly prompting interactively ++ pk12util -i "${pkcs12bundle}" -d "${IPSEC_NSSDIR_SQL}" -W '' 2>/dev/null ++ # check for SEC_ERROR_BAD_PASSWORD ++ if [ $? -eq 18 ]; then ++ # Not the empty password ++ pk12util -i "${pkcs12bundle}" -d "${IPSEC_NSSDIR_SQL}" ++ fi ++ + # check and correct trust bits + set_nss_db_trusts + exit 0 diff --git a/libreswan-5.3-helper-thread.patch b/libreswan-5.3-helper-thread.patch new file mode 100644 index 0000000..0693317 --- /dev/null +++ b/libreswan-5.3-helper-thread.patch @@ -0,0 +1,97 @@ +From eb31dda36d082e33749bc294d56ec493a094336d Mon Sep 17 00:00:00 2001 +From: Andrew Cagney +Date: Sun, 16 Nov 2025 10:33:53 -0500 +Subject: [PATCH] helpers: work around NSS by joining helper threads + +Much of the analysis and testing by Ondrej Moris + +NSS attaches stuff to the threads onexit queue that must +be run before the main thread exits (if it doesn't things +explode during shutdown). + +See: Race condition in helper_thread_stopped_callback() #2461 +See: PR_Cleanup() doesn't wait for pthread_create() threads +https://bugzilla.mozilla.org/show_bug.cgi?id=1992272 +--- + programs/pluto/server_pool.c | 42 +++++++++++++++++++++++++++++++----- + 1 file changed, 37 insertions(+), 5 deletions(-) + +diff --git a/programs/pluto/server_pool.c b/programs/pluto/server_pool.c +index 056a007301..5c7dc5e18d 100644 +--- a/programs/pluto/server_pool.c ++++ b/programs/pluto/server_pool.c +@@ -275,6 +275,22 @@ static void *helper_thread(void *arg) + dbg("helper %u: telling main thread that it is exiting", w->helper_id); + schedule_callback("helper stopped", deltatime(0), SOS_NOBODY, + helper_thread_stopped_callback, NULL); ++ /* ++ * Danger. This isn't the end. ++ * ++ * NSS still has stuff in thread-exit handlers to execute and ++ * there's no clean way of forcing its execution (and if it ++ * isn't allowed to run NSS crashes!). Hence, the main thread ++ * will need to wait for this thread to exit. ++ * ++ * But wait, there's more. The main thread also needs to keep ++ * the event loop running while these threads are exiting so ++ * ptread_join() needs to be called with care. ++ * ++ * See: Race condition in helper_thread_stopped_callback() #2461 ++ * See: PR_Cleanup() doesn't wait for pthread_create() threads ++ * https://bugzilla.mozilla.org/show_bug.cgi?id=1992272 ++ */ + return NULL; + } + +@@ -589,10 +605,6 @@ void start_server_helpers(uintmax_t nhelpers, struct logger *logger) + + /* + * Repeatedly nudge the helper threads until they all exit. +- * +- * Note that pthread_join() doesn't work here: an any-thread join may +- * end up joining an unrelated thread (for instance the CRL helper); +- * and a specific thread join may block waiting for the wrong thread. + */ + + static void (*server_helpers_stopped_callback)(void); +@@ -605,6 +617,17 @@ static void helper_thread_stopped_callback(const char *story UNUSED, + dbg("one helper thread exited, %u remaining", + helper_threads_started-helper_threads_stopped); + ++ /* ++ * Danger: ++ * ++ * Delay joining W.pid until all helper threads have exited. ++ * This way the event-loop is kept running. ++ * ++ * Even though W is on the exit path it still needs to execute ++ * NSS's thread exit code - who knows what that is doing and ++ * how long it will take - ++ */ ++ + /* wait for more? */ + if (helper_threads_started > helper_threads_stopped) { + /* poke threads waiting for work */ +@@ -612,9 +635,18 @@ static void helper_thread_stopped_callback(const char *story UNUSED, + return; + } + +- /* all done; cleanup */ ++ /* ++ * All done; cleanup ++ * ++ * All helper threads are on the exit war-path so, hopefully, ++ * this join will not block (but no telling what NSS did). ++ */ + for (unsigned h = 0; h < helper_threads_started; h++) { + struct helper_thread *w = &helper_threads[h]; ++ int e = pthread_join(w->pid, NULL); ++ if (e != 0) { ++ llog_errno(RC_LOG, w->logger, e, "WARNING: pthread_join() failed, "); ++ } + free_logger(&w->logger, HERE); + } + +-- +2.52.0 + diff --git a/libreswan-5.3-outstanding-ike-auth-crossing.patch b/libreswan-5.3-outstanding-ike-auth-crossing.patch new file mode 100644 index 0000000..cccf3a7 --- /dev/null +++ b/libreswan-5.3-outstanding-ike-auth-crossing.patch @@ -0,0 +1,1056 @@ +From f58dec967328c9b11b834c42b1506e2d261d8bb2 Mon Sep 17 00:00:00 2001 +From: Ondrej Moris +Date: Fri, 21 Nov 2025 22:42:33 +0100 +Subject: [PATCH 1/7] Add option reject-simultaneous-ike-auth + +Newly added option (default values is yes) decides what to +do when IKE_AUTH request is received from the peer while having +an outstanding IKE_AUTH request for the same connection. + +Signed-off-by: Ondrej Moris +Signed-off-by: Andrew Cagney +--- + .../reject-simultaneous-ike-auth.xml | 21 +++++++++++++++++++ + configs/ipsec.conf.5.xml | 2 ++ + include/ipsecconf/keywords.h | 1 + + include/whack.h | 1 + + lib/libswan/ipsecconf/keywords.c | 1 + + lib/libswan/ipsecconf/starterwhack.c | 1 + + programs/pluto/connections.c | 6 ++++++ + programs/pluto/connections.h | 2 ++ + programs/whack/whack.c | 7 +++++++ + 9 files changed, 42 insertions(+) + create mode 100644 configs/d.ipsec.conf/reject-simultaneous-ike-auth.xml + +diff --git a/configs/d.ipsec.conf/reject-simultaneous-ike-auth.xml b/configs/d.ipsec.conf/reject-simultaneous-ike-auth.xml +new file mode 100644 +index 0000000000..7c3f68c42d +--- /dev/null ++++ b/configs/d.ipsec.conf/reject-simultaneous-ike-auth.xml +@@ -0,0 +1,21 @@ ++ ++ ++ ++ ++ ++ ++ ++ When libreswan receives IKE_AUTH request from the peer while having ++ an outstanding IKE_AUTH request for the same connection, reject with ++ AUTHENTICATION_FAILED to avoid potential SA mismatch issues. This only ++ applies to permanent IKEv2 connections so that the revival mechanism ++ ensures connection retry. ++ ++ ++ ++ The accepted values are (the default) or ++ . ++ ++ ++ ++ +diff --git a/configs/ipsec.conf.5.xml b/configs/ipsec.conf.5.xml +index 03f04106ae..eb0f69007d 100644 +--- a/configs/ipsec.conf.5.xml ++++ b/configs/ipsec.conf.5.xml +@@ -25,6 +25,7 @@ + + + ++ + + + +@@ -377,6 +378,7 @@ + &failureshunt; + &negotiationshunt; + &debug; ++ &reject-simultaneous-ike-auth; + + + +diff --git a/include/ipsecconf/keywords.h b/include/ipsecconf/keywords.h +index bdbc00ee98..21b5954c52 100644 +--- a/include/ipsecconf/keywords.h ++++ b/include/ipsecconf/keywords.h +@@ -201,6 +201,7 @@ enum config_conn_keyword { + KWS_CISCO_SPLIT, /* send cisco unity VID */ + + KWYN_SEND_ESP_TFC_PADDING_NOT_SUPPORTED, ++ KWYN_REJECT_SIMULTANEOUS_IKE_AUTH, + KWYN_FAKE_STRONGSWAN, /* send strongswan VID (required for twofish/serpent) */ + KWYN_SEND_VENDORID, /* per conn sending of our own libreswan vendorid */ + KNCF_IKEPAD, /* pad IKE packets to 4 bytes */ +diff --git a/include/whack.h b/include/whack.h +index 85f38da0aa..76d6eb2908 100644 +--- a/include/whack.h ++++ b/include/whack.h +@@ -409,6 +409,7 @@ struct whack_message { + const char *priority; + const char *tfc; + enum yn_options send_esp_tfc_padding_not_supported; ++ enum yn_options reject_simultaneous_ike_auth; + + enum yn_options iptfs; + enum yn_options iptfs_fragmentation; +diff --git a/lib/libswan/ipsecconf/keywords.c b/lib/libswan/ipsecconf/keywords.c +index 1e42bf2a4a..6c662a9688 100644 +--- a/lib/libswan/ipsecconf/keywords.c ++++ b/lib/libswan/ipsecconf/keywords.c +@@ -162,6 +162,7 @@ static const struct keyword_def config_conn_keyword[] = { + + K("initial-contact", LEMPTY, kt_sparse_name, KWYN_INITIAL_CONTACT, .sparse_names = &yn_option_names), + K("send-esp-tfc-padding-not-supported", LEMPTY, kt_sparse_name, KWYN_SEND_ESP_TFC_PADDING_NOT_SUPPORTED, .sparse_names = &yn_option_names), ++ K("reject-simultaneous-ike-auth", LEMPTY, kt_sparse_name, KWYN_REJECT_SIMULTANEOUS_IKE_AUTH, .sparse_names = &yn_option_names), + + K("iptfs", LEMPTY, kt_sparse_name, KWYN_IPTFS, .sparse_names = &yn_option_names), + K("iptfs-fragmentation", LEMPTY, kt_sparse_name, KWYN_IPTFS_FRAGMENTATION, .sparse_names = &yn_option_names), +diff --git a/lib/libswan/ipsecconf/starterwhack.c b/lib/libswan/ipsecconf/starterwhack.c +index 0e09a8e8d5..9a73769c15 100644 +--- a/lib/libswan/ipsecconf/starterwhack.c ++++ b/lib/libswan/ipsecconf/starterwhack.c +@@ -232,6 +232,7 @@ int starter_whack_add_conn(const char *ctlsocket, + conn->values[KWYN_SEND_ESP_TFC_PADDING_NOT_SUPPORTED].option; + msg.nflog_group = conn->values[KWS_NFLOG_GROUP].string; + msg.reqid = conn->values[KWS_REQID].string; ++ msg.reject_simultaneous_ike_auth = conn->values[KWYN_REJECT_SIMULTANEOUS_IKE_AUTH].option; + + if (conn->values[KNCF_TCP_REMOTEPORT].set) { + msg.tcp_remoteport = conn->values[KNCF_TCP_REMOTEPORT].option; +diff --git a/programs/pluto/connections.c b/programs/pluto/connections.c +index e949f56ebd..ca98dfb1e9 100644 +--- a/programs/pluto/connections.c ++++ b/programs/pluto/connections.c +@@ -4894,6 +4894,12 @@ static diag_t extract_connection(const struct whack_message *wm, + wm->send_esp_tfc_padding_not_supported, + YN_NO, wm, c->logger); + ++ if (wm->reject_simultaneous_ike_auth && ike_version < IKEv2) { ++ return diag("cannot specify reject-simultaneous-ike-auth for IKEv1"); ++ } ++ config->reject_simultaneous_ike_auth = extract_yn("", "reject-simultaneous-ike-auth", ++ wm->reject_simultaneous_ike_auth, /*value_when_unset*/YN_YES, wm, c->logger); ++ + /* + * Since security labels use the same REQID for everything, + * pre-assign it. +diff --git a/programs/pluto/connections.h b/programs/pluto/connections.h +index 0910fc9930..cd9cb331b6 100644 +--- a/programs/pluto/connections.h ++++ b/programs/pluto/connections.h +@@ -431,6 +431,8 @@ struct config { + uint32_t id; + } ipsec_interface; + ++ bool reject_simultaneous_ike_auth; ++ + struct end_config end[END_ROOF]; + }; + +diff --git a/programs/whack/whack.c b/programs/whack/whack.c +index a5a95045bf..5e47e009b8 100644 +--- a/programs/whack/whack.c ++++ b/programs/whack/whack.c +@@ -111,6 +111,7 @@ static void help(void) + " [--mtu ] \\\n" + " [--priority ] [--reqid ] \\\n" + " [--tfc ] [--send-esp-tfc-padding-not-supported] \\\n" ++ " [--reject-simultaneous-ike-auth] \\\n" + " [--iptfs[={yes,no}] \\\n" + " [--iptfs-fragmentation[={yes,no}]] \\\n" + " [--iptfs-packet-size ] \\\n" +@@ -516,6 +517,7 @@ enum opt { + CD_PRIORITY, + CD_TFC, + CD_SEND_ESP_TFC_PADDING_NOT_SUPPORTED, ++ CD_REJECT_SIMULTANEOUS_IKE_AUTH, + CD_PFS, + CD_REQID, + CD_NFLOG_GROUP, +@@ -898,6 +900,7 @@ const struct option optarg_options[] = { + { "tfc\0", required_argument, NULL, CD_TFC }, + { "send-esp-tfc-padding-not-supported\0yes|no", optional_argument, NULL, CD_SEND_ESP_TFC_PADDING_NOT_SUPPORTED }, + { "send-no-esp-tfc\0", no_argument, NULL, CD_SEND_ESP_TFC_PADDING_NOT_SUPPORTED }, ++ { "reject-simultaneous-ike-auth\0yes|no", optional_argument, NULL, CD_REJECT_SIMULTANEOUS_IKE_AUTH }, + { "pfs\0", optional_argument, NULL, CD_PFS }, + { "reqid\01-65535", required_argument, NULL, CD_REQID }, + #ifdef USE_NFLOG +@@ -2085,6 +2088,10 @@ int main(int argc, char **argv) + optarg_yn(logger, YN_YES); + continue; + ++ case CD_REJECT_SIMULTANEOUS_IKE_AUTH: /* --reject-simultaneous-ike-auth */ ++ msg.reject_simultaneous_ike_auth = optarg_yn(logger, YN_YES); ++ continue; ++ + case CD_PFS: /* --pfs */ + msg.pfs = optarg_yn(logger, YN_YES); + continue; +-- +2.52.0 + + +From 31ce0692217e18c3e5ed6cc2cded7c937b7ae1c9 Mon Sep 17 00:00:00 2001 +From: Ondrej Moris +Date: Fri, 13 Mar 2026 15:00:05 +0100 +Subject: [PATCH 2/7] ikev2: reject simultaneous IKE_AUTH requests + +If initiator has another IKE SA with IKE_AUTH request +outstanding for the same permanent connection then send +AUTHENTICATION_FAILED instead of IKE_AUTH response for this +IKE_AUTH request and terminate current IKE SA. This is to +prevent potential crossing streams scenario. + +This is now the default behavior and can be disabled by +a connection option reject-simultaneous-ike-auth. + +Signed-off-by: Ondrej Moris +--- + programs/pluto/ikev2_auth.c | 53 +++++++++++++++++++++++++++++++++ + programs/pluto/ikev2_auth.h | 3 ++ + programs/pluto/ikev2_child.c | 13 ++++++++ + programs/pluto/ikev2_ike_auth.c | 13 ++++++++ + 4 files changed, 82 insertions(+) + +diff --git a/programs/pluto/ikev2_auth.c b/programs/pluto/ikev2_auth.c +index 6e89bce58b..2e1b6df655 100644 +--- a/programs/pluto/ikev2_auth.c ++++ b/programs/pluto/ikev2_auth.c +@@ -1044,3 +1044,56 @@ lset_t proposed_v2AUTH(struct ike_sa *ike, + } + } + } ++ ++/* ++ * Check if a given permanent connection has another IKE SA with ++ * IKE_AUTH request outstanding. This is useful to detect potential ++ * IKE_AUTH crossing streams scenarios. ++ */ ++bool has_outstanding_ike_auth_request(const struct connection *c, ++ const struct ike_sa *ike, ++ const struct msg_digest *md) ++{ ++ /* Check can be disabled in a connection config */ ++ if (!c->config->reject_simultaneous_ike_auth) { ++ return false; ++ } ++ ++ /* Connection must be permanent and request must be incoming */ ++ if (v2_msg_role(md) != MESSAGE_REQUEST || !is_permanent(c)) { ++ return false; ++ } ++ ++ struct state_filter sf = { ++ .connection_serialno = c->serialno, ++ .search = { ++ .order = NEW2OLD, ++ .verbose.logger = ike->sa.logger, ++ .where = HERE, ++ }, ++ }; ++ ++ while (next_state(&sf)) { ++ if (!IS_IKE_SA(sf.st)) { ++ continue; ++ } ++ ++ struct ike_sa *simultaneous_ike = pexpect_ike_sa(sf.st); ++ if (simultaneous_ike == NULL || simultaneous_ike == ike) { ++ continue; ++ } else if (simultaneous_ike->sa.st_sa_role != SA_INITIATOR) { ++ continue; ++ } else if (!v2_msgid_request_outstanding(simultaneous_ike)) { ++ continue; ++ } ++ ++ const struct v2_exchange *outstanding_request = ++ simultaneous_ike->sa.st_v2_msgid_windows.initiator.exchange; ++ if (outstanding_request != NULL && outstanding_request->type == ISAKMP_v2_IKE_AUTH) { ++ llog(RC_LOG, ike->sa.logger, "IKE SA "PRI_SO" has outstanding IKE_AUTH request", ++ pri_so(simultaneous_ike->sa.st_serialno)); ++ return true; ++ } ++ } ++ return false; ++} +diff --git a/programs/pluto/ikev2_auth.h b/programs/pluto/ikev2_auth.h +index 13ee71c36d..d616534507 100644 +--- a/programs/pluto/ikev2_auth.h ++++ b/programs/pluto/ikev2_auth.h +@@ -85,4 +85,7 @@ struct crypt_mac v2_remote_id_hash(const struct ike_sa *ike, const char *why, + + lset_t proposed_v2AUTH(struct ike_sa *ike, struct msg_digest *md); + ++bool has_outstanding_ike_auth_request(const struct connection *c, ++ const struct ike_sa *ike, ++ const struct msg_digest *md); + #endif +diff --git a/programs/pluto/ikev2_child.c b/programs/pluto/ikev2_child.c +index 49aaff98a2..e53f53f4b3 100644 +--- a/programs/pluto/ikev2_child.c ++++ b/programs/pluto/ikev2_child.c +@@ -68,6 +68,7 @@ + #include "ikev2_notification.h" + #include "iface.h" + #include "nat_traversal.h" ++#include "ikev2_auth.h" + + static bool emit_v2_child_response_payloads(struct ike_sa *ike, + const struct child_sa *child, +@@ -1029,6 +1030,18 @@ static v2_notification_t process_v2_IKE_AUTH_request_child_sa_payloads(struct ik + ldbg_sa(child, "skipping TS processing, mainly to stop tests failing but rumored to cause connection flips?!?"); + } + ++ /* It is possible that Child SA switched to permanent connection ++ * where initiator has IKE SA with IKE_AUTH request outstanding, ++ * in that case send AUTHENTICATION_FAILED and terminate this IKE SA. ++ * This is to prevent potential crossing streams scenario for ++ * IKE AUTH exchange. ++ */ ++ if (has_outstanding_ike_auth_request(child->sa.st_connection, ike, md)) { ++ record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, ++ empty_shunk, ENCRYPTED_PAYLOAD); ++ return v2N_AUTHENTICATION_FAILED; ++ } ++ + n = process_childs_v2SA_payload("IKE_AUTH responder matching remote ESP/AH proposals", + ike, child, md, + child->sa.st_connection->config->child_sa.v2_ike_auth_proposals, +diff --git a/programs/pluto/ikev2_ike_auth.c b/programs/pluto/ikev2_ike_auth.c +index ba5aeace88..f70c06e9ef 100644 +--- a/programs/pluto/ikev2_ike_auth.c ++++ b/programs/pluto/ikev2_ike_auth.c +@@ -683,6 +683,19 @@ stf_status process_v2_IKE_AUTH_request_standard_payloads(struct ike_sa *ike, str + */ + + const struct connection *c = ike->sa.st_connection; ++ ++ /* If initiator has another IKE SA with IKE_AUTH request ++ * outstanding for the same permanent connection then send ++ * AUTHENTICATION_FAILED instead of IKE_AUTH response for this ++ * IKE_AUTH request and terminate current IKE SA. This is to ++ * prevent potential crossing streams scenario. ++ */ ++ if (has_outstanding_ike_auth_request(c, ike, md)) { ++ record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, ++ empty_shunk, ENCRYPTED_PAYLOAD); ++ return STF_FATAL; ++ } ++ + bool found_ppk = false; + + /* +-- +2.52.0 + + +From 877c8c9c2fd963bb23842cdddf798b34f7e6d42f Mon Sep 17 00:00:00 2001 +From: Daiki Ueno +Date: Sat, 17 Jan 2026 13:28:39 +0900 +Subject: [PATCH 3/7] pluto: reject crossing IKE_AUTH request only for the one + side + +When an IKE_AUTH request is crossed, both sides previously rejected it +by sending AUTHENTICATION_FAILED, resulting in no IKE_SA being +established. This patch relaxes the condition and make the one outlive +the other. + +Suggested-by: Ondrej Moris +Signed-off-by: Daiki Ueno +--- + include/ike_spi.h | 1 + + programs/pluto/ike_spi.c | 11 ++++++++++ + programs/pluto/ikev2_auth.c | 10 ++++----- + programs/pluto/ikev2_auth.h | 2 +- + programs/pluto/ikev2_child.c | 35 ++++++++++++++++++++++++++++---- + programs/pluto/ikev2_ike_auth.c | 36 +++++++++++++++++++++++++++++---- + 6 files changed, 81 insertions(+), 14 deletions(-) + +diff --git a/include/ike_spi.h b/include/ike_spi.h +index 0c05542bae..376c120c0e 100644 +--- a/include/ike_spi.h ++++ b/include/ike_spi.h +@@ -39,6 +39,7 @@ typedef struct { + } ike_spis_t; + + bool ike_spis_eq(const ike_spis_t *lhs, const ike_spis_t *rhs); ++bool ike_spis_gt(const ike_spis_t *lhs, const ike_spis_t *rhs); + + /* + * Need to handle two cases: +diff --git a/programs/pluto/ike_spi.c b/programs/pluto/ike_spi.c +index 312c835bed..d7bb73a6e8 100644 +--- a/programs/pluto/ike_spi.c ++++ b/programs/pluto/ike_spi.c +@@ -42,6 +42,17 @@ bool ike_spis_eq(const ike_spis_t *lhs, const ike_spis_t *rhs) + ike_spi_eq(&lhs->responder, &rhs->responder)); + } + ++bool ike_spis_gt(const ike_spis_t *lhs, const ike_spis_t *rhs) ++{ ++ int d = memcmp(lhs->initiator.bytes, rhs->initiator.bytes, ++ sizeof(lhs->initiator.bytes)); ++ if (d == 0) { ++ d = memcmp(lhs->responder.bytes, rhs->responder.bytes, ++ sizeof(lhs->responder.bytes)); ++ } ++ return d > 0; ++} ++ + static struct { + uint8_t bytes[SHA2_256_DIGEST_SIZE]; + } ike_spi_secret; +diff --git a/programs/pluto/ikev2_auth.c b/programs/pluto/ikev2_auth.c +index 2e1b6df655..ee36ef8b03 100644 +--- a/programs/pluto/ikev2_auth.c ++++ b/programs/pluto/ikev2_auth.c +@@ -1050,18 +1050,18 @@ lset_t proposed_v2AUTH(struct ike_sa *ike, + * IKE_AUTH request outstanding. This is useful to detect potential + * IKE_AUTH crossing streams scenarios. + */ +-bool has_outstanding_ike_auth_request(const struct connection *c, ++struct ike_sa *get_sa_with_outstanding_ike_auth_request(const struct connection *c, + const struct ike_sa *ike, + const struct msg_digest *md) + { + /* Check can be disabled in a connection config */ + if (!c->config->reject_simultaneous_ike_auth) { +- return false; ++ return NULL; + } + + /* Connection must be permanent and request must be incoming */ + if (v2_msg_role(md) != MESSAGE_REQUEST || !is_permanent(c)) { +- return false; ++ return NULL; + } + + struct state_filter sf = { +@@ -1092,8 +1092,8 @@ bool has_outstanding_ike_auth_request(const struct connection *c, + if (outstanding_request != NULL && outstanding_request->type == ISAKMP_v2_IKE_AUTH) { + llog(RC_LOG, ike->sa.logger, "IKE SA "PRI_SO" has outstanding IKE_AUTH request", + pri_so(simultaneous_ike->sa.st_serialno)); +- return true; ++ return simultaneous_ike; + } + } +- return false; ++ return NULL; + } +diff --git a/programs/pluto/ikev2_auth.h b/programs/pluto/ikev2_auth.h +index d616534507..bb659ce88f 100644 +--- a/programs/pluto/ikev2_auth.h ++++ b/programs/pluto/ikev2_auth.h +@@ -85,7 +85,7 @@ struct crypt_mac v2_remote_id_hash(const struct ike_sa *ike, const char *why, + + lset_t proposed_v2AUTH(struct ike_sa *ike, struct msg_digest *md); + +-bool has_outstanding_ike_auth_request(const struct connection *c, ++struct ike_sa *get_sa_with_outstanding_ike_auth_request(const struct connection *c, + const struct ike_sa *ike, + const struct msg_digest *md); + #endif +diff --git a/programs/pluto/ikev2_child.c b/programs/pluto/ikev2_child.c +index e53f53f4b3..09b5862cd0 100644 +--- a/programs/pluto/ikev2_child.c ++++ b/programs/pluto/ikev2_child.c +@@ -69,6 +69,7 @@ + #include "iface.h" + #include "nat_traversal.h" + #include "ikev2_auth.h" ++#include "terminate.h" + + static bool emit_v2_child_response_payloads(struct ike_sa *ike, + const struct child_sa *child, +@@ -1036,10 +1037,36 @@ static v2_notification_t process_v2_IKE_AUTH_request_child_sa_payloads(struct ik + * This is to prevent potential crossing streams scenario for + * IKE AUTH exchange. + */ +- if (has_outstanding_ike_auth_request(child->sa.st_connection, ike, md)) { +- record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, +- empty_shunk, ENCRYPTED_PAYLOAD); +- return v2N_AUTHENTICATION_FAILED; ++ struct ike_sa *simultaneous_ike = ++ get_sa_with_outstanding_ike_auth_request(child->sa.st_connection, ike, md); ++ if (simultaneous_ike != NULL) { ++ /* Compare our initiated SPI vs their initiated SPI ++ * from the message. Note that the ordering doesn't ++ * matter, but it ensures that both sides have the ++ * same consensus on which IKE SA should be dropped. ++ */ ++ if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, ++ &ike->sa.st_ike_spis)) { ++ /* Our IKE SA with oustanding IKE AUTH request ++ * has SPI higher, delete this IKE SA, keep ++ * the simultaneous_ike. ++ */ ++ ldbg(ike->sa.logger, "preferring the outstanding "PRI_SO" over the current "PRI_SO, ++ pri_so(simultaneous_ike->sa.st_serialno), ++ pri_so(ike->sa.st_serialno)); ++ record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, ++ empty_shunk, ENCRYPTED_PAYLOAD); ++ return v2N_AUTHENTICATION_FAILED; ++ } else { ++ /* IKE SA for the current IKE AUTH request has ++ * SPI higher, continue with IKE AUTH reply ++ * and drop the other one. ++ */ ++ ldbg(ike->sa.logger, "preferring the current "PRI_SO" over the outstanding "PRI_SO"", ++ pri_so(ike->sa.st_serialno), ++ pri_so(simultaneous_ike->sa.st_serialno)); ++ terminate_ike_family(&simultaneous_ike, REASON_SUPERSEDED_BY_NEW_SA, HERE); ++ } + } + + n = process_childs_v2SA_payload("IKE_AUTH responder matching remote ESP/AH proposals", +diff --git a/programs/pluto/ikev2_ike_auth.c b/programs/pluto/ikev2_ike_auth.c +index f70c06e9ef..406469dc75 100644 +--- a/programs/pluto/ikev2_ike_auth.c ++++ b/programs/pluto/ikev2_ike_auth.c +@@ -76,6 +76,8 @@ + #include "ikev2_notification.h" + #include "peer_id.h" + #include "ddos.h" ++#include "ikev2_nat.h" ++#include "terminate.h" + + static ikev2_state_transition_fn process_v2_IKE_AUTH_request; + +@@ -690,10 +692,36 @@ stf_status process_v2_IKE_AUTH_request_standard_payloads(struct ike_sa *ike, str + * IKE_AUTH request and terminate current IKE SA. This is to + * prevent potential crossing streams scenario. + */ +- if (has_outstanding_ike_auth_request(c, ike, md)) { +- record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, +- empty_shunk, ENCRYPTED_PAYLOAD); +- return STF_FATAL; ++ struct ike_sa *simultaneous_ike = ++ get_sa_with_outstanding_ike_auth_request(c, ike, md); ++ if (simultaneous_ike != NULL) { ++ /* Compare our initiated SPIs vs their initiated SPIs ++ * from the message. Note that the ordering doesn't ++ * matter, but it ensures that both sides have the ++ * same consensus on which IKE SA should be dropped. ++ */ ++ if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, ++ &ike->sa.st_ike_spis)) { ++ /* Our IKE SA with oustanding IKE AUTH request ++ * has SPI higher, delete this IKE SA, keep ++ * the simultaneous_ike. ++ */ ++ ldbg(ike->sa.logger, "preferring the outstanding "PRI_SO" over the current "PRI_SO, ++ pri_so(simultaneous_ike->sa.st_serialno), ++ pri_so(ike->sa.st_serialno)); ++ record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, ++ empty_shunk, ENCRYPTED_PAYLOAD); ++ return STF_FATAL; ++ } else { ++ /* IKE SA for the current IKE AUTH request has ++ * SPI higher, continue with IKE AUTH reply ++ * and drop the other one. ++ */ ++ ldbg(ike->sa.logger, "preferring the current "PRI_SO" over the outstanding "PRI_SO"", ++ pri_so(ike->sa.st_serialno), ++ pri_so(simultaneous_ike->sa.st_serialno)); ++ terminate_ike_family(&simultaneous_ike, REASON_SUPERSEDED_BY_NEW_SA, HERE); ++ } + } + + bool found_ppk = false; +-- +2.52.0 + + +From f35e32abc6b1e8d027ce811f0954f4b5de618f68 Mon Sep 17 00:00:00 2001 +From: Ondrej Moris +Date: Sun, 25 Jan 2026 19:41:25 +0100 +Subject: [PATCH 4/7] ikev2: refactor simultaneous IKE_AUTH logic + +1. Moved decision which IKE to reject into the function. +2. Renamed function to better capture its new structure. + +Signed-off-by: Ondrej Moris +--- + programs/pluto/ikev2_auth.c | 80 +++++++++++++++++++++++---------- + programs/pluto/ikev2_auth.h | 6 +-- + programs/pluto/ikev2_child.c | 44 +++++------------- + programs/pluto/ikev2_ike_auth.c | 43 +++++------------- + 4 files changed, 80 insertions(+), 93 deletions(-) + +diff --git a/programs/pluto/ikev2_auth.c b/programs/pluto/ikev2_auth.c +index ee36ef8b03..3c61e45cdd 100644 +--- a/programs/pluto/ikev2_auth.c ++++ b/programs/pluto/ikev2_auth.c +@@ -1046,13 +1046,23 @@ lset_t proposed_v2AUTH(struct ike_sa *ike, + } + + /* +- * Check if a given permanent connection has another IKE SA with +- * IKE_AUTH request outstanding. This is useful to detect potential +- * IKE_AUTH crossing streams scenarios. ++ * Check relevant simultaneous IKE_AUTH requests and decide ++ * which IKE SA is going to be rejected (if any). This is goint ++ * to be called when processing IKE_AUTH request from the responder ++ * ++ * Relevant: ++ * - same connection ++ * - initiating IKE ++ * - non-established with IKE_AUTH request waiting for reply ++ * ++ * Returns: ++ * - ike: reject current IKE_AUTH request ++ * - other IKE SA than ike: terminate it, keep ike ++ * - NULL: no simultaneous IKE SA + */ +-struct ike_sa *get_sa_with_outstanding_ike_auth_request(const struct connection *c, +- const struct ike_sa *ike, +- const struct msg_digest *md) ++struct ike_sa *check_simultaneous_ike_auth(const struct connection *c, ++ const struct ike_sa *ike, ++ const struct msg_digest *md) + { + /* Check can be disabled in a connection config */ + if (!c->config->reject_simultaneous_ike_auth) { +@@ -1065,35 +1075,57 @@ struct ike_sa *get_sa_with_outstanding_ike_auth_request(const struct connection + } + + struct state_filter sf = { +- .connection_serialno = c->serialno, +- .search = { +- .order = NEW2OLD, +- .verbose.logger = ike->sa.logger, +- .where = HERE, +- }, ++ .connection_serialno = c->serialno, ++ .search = { ++ .order = NEW2OLD, ++ .verbose.logger = ike->sa.logger, ++ .where = HERE, ++ }, + }; + ++ struct ike_sa *simultaneous_ike = NULL; ++ + while (next_state(&sf)) { + if (!IS_IKE_SA(sf.st)) { + continue; + } + +- struct ike_sa *simultaneous_ike = pexpect_ike_sa(sf.st); +- if (simultaneous_ike == NULL || simultaneous_ike == ike) { +- continue; +- } else if (simultaneous_ike->sa.st_sa_role != SA_INITIATOR) { ++ struct ike_sa *candidate = pexpect_ike_sa(sf.st); ++ ++ if (candidate == NULL || candidate == ike) { + continue; +- } else if (!v2_msgid_request_outstanding(simultaneous_ike)) { ++ } else if (candidate->sa.st_sa_role != SA_INITIATOR) { + continue; + } + +- const struct v2_exchange *outstanding_request = +- simultaneous_ike->sa.st_v2_msgid_windows.initiator.exchange; +- if (outstanding_request != NULL && outstanding_request->type == ISAKMP_v2_IKE_AUTH) { +- llog(RC_LOG, ike->sa.logger, "IKE SA "PRI_SO" has outstanding IKE_AUTH request", +- pri_so(simultaneous_ike->sa.st_serialno)); +- return simultaneous_ike; ++ /* Does candidate has IKE_AUTH request outstanding? */ ++ if (v2_msgid_request_outstanding(candidate)) { ++ const struct v2_exchange *outstanding_request = candidate->sa.st_v2_msgid_windows.initiator.exchange; ++ if (outstanding_request != NULL && outstanding_request->type == ISAKMP_v2_IKE_AUTH) { ++ llog(RC_LOG, ike->sa.logger, "IKE SA "PRI_SO" has outstanding IKE_AUTH request", ++ pri_so(candidate->sa.st_serialno)); ++ simultaneous_ike = candidate; ++ break; ++ } + } + } +- return NULL; ++ ++ /* No simultaneous IKE found */ ++ if (simultaneous_ike == NULL) { ++ return NULL; ++ } ++ ++ /* Simultaneous IKE found, we need to decide if we keep that one or current IKE. ++ * ++ * We keep one with higher SPI. ++ */ ++ if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, &ike->sa.st_ike_spis)) { ++ ldbg(ike->sa.logger, "preferring the simultaneous IKE SA "PRI_SO" over the current IKE SA "PRI_SO, ++ pri_so(simultaneous_ike->sa.st_serialno), pri_so(ike->sa.st_serialno)); ++ return (struct ike_sa *) ike; ++ } else { ++ ldbg(ike->sa.logger, "preferring the current IKE SA "PRI_SO" over the simultanoues IKE SA "PRI_SO"", ++ pri_so(ike->sa.st_serialno), pri_so(simultaneous_ike->sa.st_serialno)); ++ return simultaneous_ike; ++ } + } +diff --git a/programs/pluto/ikev2_auth.h b/programs/pluto/ikev2_auth.h +index bb659ce88f..1c25479ed7 100644 +--- a/programs/pluto/ikev2_auth.h ++++ b/programs/pluto/ikev2_auth.h +@@ -85,7 +85,7 @@ struct crypt_mac v2_remote_id_hash(const struct ike_sa *ike, const char *why, + + lset_t proposed_v2AUTH(struct ike_sa *ike, struct msg_digest *md); + +-struct ike_sa *get_sa_with_outstanding_ike_auth_request(const struct connection *c, +- const struct ike_sa *ike, +- const struct msg_digest *md); ++struct ike_sa *check_simultaneous_ike_auth(const struct connection *c, ++ const struct ike_sa *ike, ++ const struct msg_digest *md); + #endif +diff --git a/programs/pluto/ikev2_child.c b/programs/pluto/ikev2_child.c +index 09b5862cd0..9763112ddf 100644 +--- a/programs/pluto/ikev2_child.c ++++ b/programs/pluto/ikev2_child.c +@@ -1032,41 +1032,19 @@ static v2_notification_t process_v2_IKE_AUTH_request_child_sa_payloads(struct ik + } + + /* It is possible that Child SA switched to permanent connection +- * where initiator has IKE SA with IKE_AUTH request outstanding, +- * in that case send AUTHENTICATION_FAILED and terminate this IKE SA. +- * This is to prevent potential crossing streams scenario for ++ * where initiator has IKE SA with IKE_AUTH request outstanding ++ * (or recently established IKE SA) in that case keep only one of ++ * them. This is to prevent potential crossing streams scenario for + * IKE AUTH exchange. + */ +- struct ike_sa *simultaneous_ike = +- get_sa_with_outstanding_ike_auth_request(child->sa.st_connection, ike, md); +- if (simultaneous_ike != NULL) { +- /* Compare our initiated SPI vs their initiated SPI +- * from the message. Note that the ordering doesn't +- * matter, but it ensures that both sides have the +- * same consensus on which IKE SA should be dropped. +- */ +- if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, +- &ike->sa.st_ike_spis)) { +- /* Our IKE SA with oustanding IKE AUTH request +- * has SPI higher, delete this IKE SA, keep +- * the simultaneous_ike. +- */ +- ldbg(ike->sa.logger, "preferring the outstanding "PRI_SO" over the current "PRI_SO, +- pri_so(simultaneous_ike->sa.st_serialno), +- pri_so(ike->sa.st_serialno)); +- record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, +- empty_shunk, ENCRYPTED_PAYLOAD); +- return v2N_AUTHENTICATION_FAILED; +- } else { +- /* IKE SA for the current IKE AUTH request has +- * SPI higher, continue with IKE AUTH reply +- * and drop the other one. +- */ +- ldbg(ike->sa.logger, "preferring the current "PRI_SO" over the outstanding "PRI_SO"", +- pri_so(ike->sa.st_serialno), +- pri_so(simultaneous_ike->sa.st_serialno)); +- terminate_ike_family(&simultaneous_ike, REASON_SUPERSEDED_BY_NEW_SA, HERE); +- } ++ struct ike_sa *ike_to_reject = check_simultaneous_ike_auth(child->sa.st_connection, ike, md); ++ if (ike_to_reject == ike) { ++ /* Reject current IKE_AUTH request */ ++ record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, empty_shunk, ENCRYPTED_PAYLOAD); ++ return v2N_AUTHENTICATION_FAILED; ++ } else if (ike_to_reject != NULL) { ++ /* Terminate the other IKE SA, continue with current */ ++ terminate_ike_family(&ike_to_reject, REASON_SUPERSEDED_BY_NEW_SA, HERE); + } + + n = process_childs_v2SA_payload("IKE_AUTH responder matching remote ESP/AH proposals", +diff --git a/programs/pluto/ikev2_ike_auth.c b/programs/pluto/ikev2_ike_auth.c +index 406469dc75..c9eb40e420 100644 +--- a/programs/pluto/ikev2_ike_auth.c ++++ b/programs/pluto/ikev2_ike_auth.c +@@ -687,41 +687,18 @@ stf_status process_v2_IKE_AUTH_request_standard_payloads(struct ike_sa *ike, str + const struct connection *c = ike->sa.st_connection; + + /* If initiator has another IKE SA with IKE_AUTH request +- * outstanding for the same permanent connection then send +- * AUTHENTICATION_FAILED instead of IKE_AUTH response for this +- * IKE_AUTH request and terminate current IKE SA. This is to ++ * outstanding for the same permanent connection (or recently ++ * established one) then we keep only one of them. This is to + * prevent potential crossing streams scenario. + */ +- struct ike_sa *simultaneous_ike = +- get_sa_with_outstanding_ike_auth_request(c, ike, md); +- if (simultaneous_ike != NULL) { +- /* Compare our initiated SPIs vs their initiated SPIs +- * from the message. Note that the ordering doesn't +- * matter, but it ensures that both sides have the +- * same consensus on which IKE SA should be dropped. +- */ +- if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, +- &ike->sa.st_ike_spis)) { +- /* Our IKE SA with oustanding IKE AUTH request +- * has SPI higher, delete this IKE SA, keep +- * the simultaneous_ike. +- */ +- ldbg(ike->sa.logger, "preferring the outstanding "PRI_SO" over the current "PRI_SO, +- pri_so(simultaneous_ike->sa.st_serialno), +- pri_so(ike->sa.st_serialno)); +- record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, +- empty_shunk, ENCRYPTED_PAYLOAD); +- return STF_FATAL; +- } else { +- /* IKE SA for the current IKE AUTH request has +- * SPI higher, continue with IKE AUTH reply +- * and drop the other one. +- */ +- ldbg(ike->sa.logger, "preferring the current "PRI_SO" over the outstanding "PRI_SO"", +- pri_so(ike->sa.st_serialno), +- pri_so(simultaneous_ike->sa.st_serialno)); +- terminate_ike_family(&simultaneous_ike, REASON_SUPERSEDED_BY_NEW_SA, HERE); +- } ++ struct ike_sa *ike_to_reject = check_simultaneous_ike_auth(c, ike, md); ++ if (ike_to_reject == ike) { ++ /* Reject current IKE_AUTH request */ ++ record_v2N_response(ike->sa.logger, ike, md, v2N_AUTHENTICATION_FAILED, empty_shunk, ENCRYPTED_PAYLOAD); ++ return STF_FATAL; ++ } else if (ike_to_reject != NULL) { ++ /* Terminate the other IKE SA, continue with current */ ++ terminate_ike_family(&ike_to_reject, REASON_SUPERSEDED_BY_NEW_SA, HERE); + } + + bool found_ppk = false; +-- +2.52.0 + + +From c956e30d304ac460559116dbf53487ebd2696f8a Mon Sep 17 00:00:00 2001 +From: Ondrej Moris +Date: Sun, 25 Jan 2026 19:46:45 +0100 +Subject: [PATCH 5/7] ikev2: extend check for simultaneous IKE_AUTH + +On initiator, if simultaneous IKE receives IKE_AUTH response +shortly before the current IKE_AUTH request is received, +then this simultaneous IKE gets established and hence it +incorrectly missed by the current check. This commit extends +the check for simultaneous IKE to capture such cases and if +there is such simultaneous IKE it will be keps and the current +one will be dropped. + +Signed-off-by: Ondrej Moris +--- + programs/pluto/ikev2_auth.c | 21 ++++++++++++++++++++- + 1 file changed, 20 insertions(+), 1 deletion(-) + +diff --git a/programs/pluto/ikev2_auth.c b/programs/pluto/ikev2_auth.c +index 3c61e45cdd..10d583b4c1 100644 +--- a/programs/pluto/ikev2_auth.c ++++ b/programs/pluto/ikev2_auth.c +@@ -1054,6 +1054,7 @@ lset_t proposed_v2AUTH(struct ike_sa *ike, + * - same connection + * - initiating IKE + * - non-established with IKE_AUTH request waiting for reply ++ * - established within 1 second of processing this IKE_AUTH request + * + * Returns: + * - ike: reject current IKE_AUTH request +@@ -1108,6 +1109,17 @@ struct ike_sa *check_simultaneous_ike_auth(const struct connection *c, + break; + } + } ++ ++ /* Was candidate established within the last second of the current IKE_AUTH request arrival? */ ++ if (candidate->sa.st_state->kind == STATE_V2_ESTABLISHED_IKE_SA) { ++ deltatime_t age = monotime_diff(mononow(), candidate->sa.st_v2_msgid_windows.initiator.last_recv); ++ if (deltatime_cmp(age, <, one_second)) { ++ llog(RC_LOG, ike->sa.logger, "IKE SA "PRI_SO" recently established", ++ pri_so(candidate->sa.st_serialno)); ++ simultaneous_ike = candidate; ++ break; ++ } ++ } + } + + /* No simultaneous IKE found */ +@@ -1117,8 +1129,15 @@ struct ike_sa *check_simultaneous_ike_auth(const struct connection *c, + + /* Simultaneous IKE found, we need to decide if we keep that one or current IKE. + * +- * We keep one with higher SPI. ++ * If simultaneous IKE is already established, we keep it. Otherwise we keep one ++ * with higher SPI. + */ ++ if (simultaneous_ike->sa.st_state->kind == STATE_V2_ESTABLISHED_IKE_SA) { ++ llog(RC_LOG, ike->sa.logger, "rejecting IKE_AUTH request; IKE SA "PRI_SO" already established", ++ pri_so(simultaneous_ike->sa.st_serialno)); ++ return (struct ike_sa *) ike; ++ } ++ + if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, &ike->sa.st_ike_spis)) { + ldbg(ike->sa.logger, "preferring the simultaneous IKE SA "PRI_SO" over the current IKE SA "PRI_SO, + pri_so(simultaneous_ike->sa.st_serialno), pri_so(ike->sa.st_serialno)); +-- +2.52.0 + + +From 182a09854935d505aa8cb5cfd7843bd133508452 Mon Sep 17 00:00:00 2001 +From: Ondrej Moris +Date: Tue, 24 Feb 2026 12:59:29 +0100 +Subject: [PATCH 6/7] ikev2: use nonces to tie-break simultaneous IKE + +Previously, SPI was used to tie-break simultaneous IKE_AUTH +request. Using nonces follows RFC 7296 better. + +Signed-off-by: Ondrej Moris +--- + include/ike_spi.h | 1 - + programs/pluto/ike_spi.c | 11 ----------- + programs/pluto/ikev2_auth.c | 4 ++-- + 3 files changed, 2 insertions(+), 14 deletions(-) + +diff --git a/include/ike_spi.h b/include/ike_spi.h +index 376c120c0e..0c05542bae 100644 +--- a/include/ike_spi.h ++++ b/include/ike_spi.h +@@ -39,7 +39,6 @@ typedef struct { + } ike_spis_t; + + bool ike_spis_eq(const ike_spis_t *lhs, const ike_spis_t *rhs); +-bool ike_spis_gt(const ike_spis_t *lhs, const ike_spis_t *rhs); + + /* + * Need to handle two cases: +diff --git a/programs/pluto/ike_spi.c b/programs/pluto/ike_spi.c +index d7bb73a6e8..312c835bed 100644 +--- a/programs/pluto/ike_spi.c ++++ b/programs/pluto/ike_spi.c +@@ -42,17 +42,6 @@ bool ike_spis_eq(const ike_spis_t *lhs, const ike_spis_t *rhs) + ike_spi_eq(&lhs->responder, &rhs->responder)); + } + +-bool ike_spis_gt(const ike_spis_t *lhs, const ike_spis_t *rhs) +-{ +- int d = memcmp(lhs->initiator.bytes, rhs->initiator.bytes, +- sizeof(lhs->initiator.bytes)); +- if (d == 0) { +- d = memcmp(lhs->responder.bytes, rhs->responder.bytes, +- sizeof(lhs->responder.bytes)); +- } +- return d > 0; +-} +- + static struct { + uint8_t bytes[SHA2_256_DIGEST_SIZE]; + } ike_spi_secret; +diff --git a/programs/pluto/ikev2_auth.c b/programs/pluto/ikev2_auth.c +index 10d583b4c1..7785860995 100644 +--- a/programs/pluto/ikev2_auth.c ++++ b/programs/pluto/ikev2_auth.c +@@ -1130,7 +1130,7 @@ struct ike_sa *check_simultaneous_ike_auth(const struct connection *c, + /* Simultaneous IKE found, we need to decide if we keep that one or current IKE. + * + * If simultaneous IKE is already established, we keep it. Otherwise we keep one +- * with higher SPI. ++ * with higher nonce. + */ + if (simultaneous_ike->sa.st_state->kind == STATE_V2_ESTABLISHED_IKE_SA) { + llog(RC_LOG, ike->sa.logger, "rejecting IKE_AUTH request; IKE SA "PRI_SO" already established", +@@ -1138,7 +1138,7 @@ struct ike_sa *check_simultaneous_ike_auth(const struct connection *c, + return (struct ike_sa *) ike; + } + +- if (ike_spis_gt(&simultaneous_ike->sa.st_ike_spis, &ike->sa.st_ike_spis)) { ++ if (hunk_cmp(simultaneous_ike->sa.st_ni, ike->sa.st_ni) > 0) { + ldbg(ike->sa.logger, "preferring the simultaneous IKE SA "PRI_SO" over the current IKE SA "PRI_SO, + pri_so(simultaneous_ike->sa.st_serialno), pri_so(ike->sa.st_serialno)); + return (struct ike_sa *) ike; +-- +2.52.0 + + +From be59b08e8f88937ae513c65902ce1af97f7a1eb3 Mon Sep 17 00:00:00 2001 +From: Ondrej Moris +Date: Tue, 24 Feb 2026 14:54:35 +0100 +Subject: [PATCH 7/7] impair: add impair option for setting nonces + +New impair options 'impair_initiator_nonce' and 'impair_responder_nonce' +allow setting all 32 bytes of nonce to specified value, e.g. to set high +nonce value one can use 'impair ike_initiator_nonce:0xff'. This might be +useful for testing. + +Signed-off-by: Ondrej Moris +--- + include/impair.h | 2 ++ + lib/libswan/impair.c | 2 ++ + programs/pluto/crypt_ke.c | 14 ++++++++++++++ + 3 files changed, 18 insertions(+) + +diff --git a/include/impair.h b/include/impair.h +index d3b2b68b3d..e6897e18d6 100644 +--- a/include/impair.h ++++ b/include/impair.h +@@ -111,6 +111,8 @@ struct impair { + + struct impair_unsigned ike_initiator_spi; + struct impair_unsigned ike_responder_spi; ++ struct impair_unsigned ike_initiator_nonce; ++ struct impair_unsigned ike_responder_nonce; + + bool bust_mi2; + bool bust_mr2; +diff --git a/lib/libswan/impair.c b/lib/libswan/impair.c +index 9e7cd829de..ba28d6420b 100644 +--- a/lib/libswan/impair.c ++++ b/lib/libswan/impair.c +@@ -210,6 +210,8 @@ struct impairment impairments[] = { + + U(ike_initiator_spi, "corrupt the IKE initiator SPI setting it to the value"), + U(ike_responder_spi, "corrupt the IKE responder SPI setting it to the value"), ++ U(ike_initiator_nonce, "corrupt the IKE initiator nonce setting it to the "), ++ U(ike_responder_nonce, "corrupt the IKE responder nonce setting it to the "), + + B(ikev1_del_with_notify, "causes pluto to send IKE Delete with additional bogus Notify payload"), + +diff --git a/programs/pluto/crypt_ke.c b/programs/pluto/crypt_ke.c +index 1d7dfd5ad5..8535a350fc 100644 +--- a/programs/pluto/crypt_ke.c ++++ b/programs/pluto/crypt_ke.c +@@ -52,12 +52,14 @@ + #include "ike_alg.h" + #include "crypt_dh.h" + #include "crypt_ke.h" ++#include "impair.h" + + struct task { + const struct dh_desc *dh; + chunk_t nonce; + struct dh_local_secret *local_secret; + ke_and_nonce_cb *cb; ++ enum sa_role role; + }; + + static void compute_ke_and_nonce(struct logger *logger, +@@ -72,6 +74,17 @@ static void compute_ke_and_nonce(struct logger *logger, + } + } + task->nonce = alloc_rnd_chunk(DEFAULT_NONCE_SIZE, "nonce"); ++ ++ if (impair.ike_initiator_nonce.enabled && task->role == SA_INITIATOR) { ++ uint8_t pattern = (uint8_t)impair.ike_initiator_nonce.value; ++ memset(task->nonce.ptr, pattern, task->nonce.len); ++ llog(RC_LOG, logger, "IMPAIR: forcing IKE initiator nonce to all 0x%02x bytes", pattern); ++ } else if (impair.ike_responder_nonce.enabled && task->role == SA_RESPONDER) { ++ uint8_t pattern = (uint8_t)impair.ike_responder_nonce.value; ++ memset(task->nonce.ptr, pattern, task->nonce.len); ++ llog(RC_LOG, logger, "IMPAIR: forcing IKE responder nonce to all 0x%02x bytes", pattern); ++ } ++ + if (LDBGP(DBG_CRYPT, logger)) { + LDBG_log_hunk(logger, "generated nonce:", task->nonce); + } +@@ -112,6 +125,7 @@ void submit_ke_and_nonce(struct state *callback_sa, + struct task *task = alloc_thing(struct task, "dh"); + task->dh = dh; + task->cb = cb; ++ task->role = task_sa->st_sa_role; + submit_task(/*callback*/callback_sa, /*task*/task_sa, md, detach_whack, + task, &ke_and_nonce_handler, where); + } +-- +2.52.0 + diff --git a/libreswan.spec b/libreswan.spec new file mode 100644 index 0000000..e374162 --- /dev/null +++ b/libreswan.spec @@ -0,0 +1,669 @@ +## START: Set by rpmautospec +## (rpmautospec version 0.8.1) +## RPMAUTOSPEC: autorelease, autochangelog +%define autorelease(e:s:pb:n) %{?-p:0.}%{lua: + release_number = 1; + base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}")); + print(release_number + base_release_number - 1); +}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}} +## END: Set by rpmautospec + +%global _hardened_build 1 +# These are rpm macros and are 0 or 1 +%global with_efence 0 +%global with_development 0 +%global with_cavstests 1 +%global nss_version 3.52 +%global unbound_version 1.6.6 +# Libreswan config options +%global libreswan_config \\\ + LIBEXECDIR=%{_libexecdir}/ipsec \\\ + MANDIR=%{_mandir} \\\ + PREFIX=%{_prefix} \\\ + INITSYSTEM=systemd \\\ + SBINDIR=%{_sbindir} \\\ + SHELL_BINARY=%{_bindir}/sh \\\ + USE_DNSSEC=true \\\ + USE_LABELED_IPSEC=true \\\ + USE_LDAP=true \\\ + USE_LIBCAP_NG=true \\\ + USE_LIBCURL=true \\\ + USE_LINUX_AUDIT=true \\\ + USE_NM=true \\\ + USE_NSS_IPSEC_PROFILE=true \\\ + USE_SECCOMP=true \\\ + USE_AUTHPAM=true \\\ +%{nil} + +#global prever dr1 + +Name: libreswan +Summary: Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec +# version is generated in the release script +Version: 5.3.2 +Release: %autorelease +# The code in lib/libswan/nss_copies.c is under MPL-2.0, while the +# rest is under GPL-2.0-or-later +License: GPL-2.0-or-later AND MPL-2.0 +Url: https://libreswan.org/ +Source0: https://download.libreswan.org/%{?prever:development/}%{name}-%{version}%{?prever}.tar.gz +Source1: https://download.libreswan.org/%{?prever:development/}%{name}-%{version}%{?prever}.tar.gz.sig +Source2: https://download.libreswan.org/LIBRESWAN-OpenPGP-KEY.txt +%if 0%{with_cavstests} +Source3: https://download.libreswan.org/cavs/ikev1_dsa.fax.bz2 +Source4: https://download.libreswan.org/cavs/ikev1_psk.fax.bz2 +Source5: https://download.libreswan.org/cavs/ikev2.fax.bz2 +%endif + +Patch1: libreswan-4.15-ipsec_import.patch +Patch2: libreswan-5.3-outstanding-ike-auth-crossing.patch +Patch3: libreswan-5.3-helper-thread.patch + +BuildRequires: audit-libs-devel +BuildRequires: bison +BuildRequires: curl-devel +BuildRequires: flex +BuildRequires: gcc +BuildRequires: gnupg2 +BuildRequires: hostname +BuildRequires: ldns-devel +BuildRequires: libcap-ng-devel +BuildRequires: libevent-devel +BuildRequires: libseccomp-devel +BuildRequires: libselinux-devel +BuildRequires: make +BuildRequires: nspr-devel +BuildRequires: nss-devel >= %{nss_version} +BuildRequires: nss-tools >= %{nss_version} +BuildRequires: openldap-devel +BuildRequires: pam-devel +BuildRequires: pkgconfig +BuildRequires: systemd +BuildRequires: systemd-devel +BuildRequires: systemd-rpm-macros +BuildRequires: unbound-devel >= %{unbound_version} +BuildRequires: xmlto +%if 0%{with_efence} +BuildRequires: ElectricFence +%endif +Requires: iproute >= 2.6.8 +Requires: nss >= %{nss_version} +Requires: nss-softokn +Requires: logrotate +# for pidof +Requires: procps-ng + +Requires: %{name}-minimal%{?_isa} = %{version}-%{release} +Obsoletes: %{name} < 5.3-5 +Requires(post): systemd +Requires(preun): systemd +Requires(postun): systemd + +%description +Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is +the Internet Protocol Security and uses strong cryptography to provide +both authentication and encryption services. These services allow you +to build secure tunnels through untrusted networks. Everything passing +through the untrusted net is encrypted by the ipsec gateway machine and +decrypted by the gateway at the other end of the tunnel. The resulting +tunnel is a virtual private network or VPN. + +This package contains the daemons and userland tools for setting up +Libreswan. + +Libreswan also supports IKEv2 (RFC7296) and Secure Labeling + +Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04 + +%package minimal +Summary: Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec (minimal version) +Requires(post): bash +Requires(post): coreutils +Requires: nss-tools +Requires: unbound-libs >= %{unbound_version} +Obsoletes: %{name} < 5.3-5 + +%description minimal +Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is +the Internet Protocol Security and uses strong cryptography to provide +both authentication and encryption services. These services allow you +to build secure tunnels through untrusted networks. Everything passing +through the untrusted net is encrypted by the ipsec gateway machine and +decrypted by the gateway at the other end of the tunnel. The resulting +tunnel is a virtual private network or VPN. + +This package contains the minimal set of daemons and userland tools +for setting up Libreswan. + +%prep +%{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}' +%setup -q -n libreswan-%{version}%{?prever} +# enable crypto-policies support +sed -i "s:#[ ]*include \(.*\)\(/crypto-policies/back-ends/libreswan.config\)$:include \1\2:" configs/ipsec.conf.in +%ifarch s390x +# throws error on s390x +sed -i "s/SUBDIRS += hunkcheck/#SUBDIRS += hunkcheck/" testing/programs/Makefile +%endif +%autopatch -p1 + +%build +%make_build \ +%if 0%{with_development} + OPTIMIZE_CFLAGS="%{?_hardened_cflags}" \ +%else + OPTIMIZE_CFLAGS="%{optflags}" \ +%endif + WERROR_CFLAGS="-Werror -Wno-missing-field-initializers -Wno-lto-type-mismatch -Wno-maybe-uninitialized" \ +%if 0%{with_efence} + USE_EFENCE=true \ +%endif + USERLINK="%{?__global_ldflags} -Wl,-z,relro -Wl,--as-needed -Wl,-z,now -flto --no-lto" \ + %{libreswan_config} \ + programs +FS=$(pwd) + + +%install +%make_install \ + %{libreswan_config} \ +FS=$(pwd) +rm -rf %{buildroot}/usr/share/doc/libreswan +rm -rf %{buildroot}%{_libexecdir}/ipsec/*check +# avoids python depency and are old / aging tools that are not very useful +rm -rf %{buildroot}%{_libexecdir}/ipsec/show +rm -rf %{buildroot}%{_libexecdir}/ipsec/verify + +install -d -m 0755 %{buildroot}%{_rundir}/pluto +install -d %{buildroot}%{_sbindir} + +install -d %{buildroot}%{_sysctldir} +install -m 0644 packaging/fedora/libreswan-sysctl.conf \ + %{buildroot}%{_sysctldir}/50-libreswan.conf + +echo "include %{_sysconfdir}/ipsec.d/*.secrets" \ + > %{buildroot}%{_sysconfdir}/ipsec.secrets +rm -fr %{buildroot}%{_sysconfdir}/rc.d/rc* + +%if 0%{with_cavstests} +%check +# There is an elaborate upstream testing infrastructure which we do not +# run here - it takes hours and uses kvm +# We only run the CAVS tests and startup selftest +cp %{SOURCE3} %{SOURCE4} %{SOURCE5} . +bunzip2 *.fax.bz2 + +: starting CAVS test for IKEv2 +%{buildroot}%{_libexecdir}/ipsec/cavp -v2 ikev2.fax | \ + diff -u ikev2.fax - > /dev/null +: starting CAVS test for IKEv1 RSASIG +%{buildroot}%{_libexecdir}/ipsec/cavp -v1dsa ikev1_dsa.fax | \ + diff -u ikev1_dsa.fax - > /dev/null +: starting CAVS test for IKEv1 PSK +%{buildroot}%{_libexecdir}/ipsec/cavp -v1psk ikev1_psk.fax | \ + diff -u ikev1_psk.fax - > /dev/null +: CAVS tests passed +%endif + +# Some of these tests will show ERROR for negative testing - it will exit on real errors +%{buildroot}%{_libexecdir}/ipsec/algparse -tp || { echo prooposal test failed; exit 1; } +%{buildroot}%{_libexecdir}/ipsec/algparse -ta || { echo algorithm test failed; exit 1; } +: Algorithm parser tests passed + +# self test for pluto daemon - this also shows which algorithms it allows in FIPS mode +tmpdir=$(mktemp -d /tmp/libreswan-XXXXX) +certutil -N -d sql:$tmpdir --empty-password +%{buildroot}%{_libexecdir}/ipsec/pluto --selftest --nssdir $tmpdir --rundir $tmpdir +: pluto self-test passed - verify FIPS algorithms allowed is still compliant with NIST + +%post +%systemd_post ipsec.service + +%post minimal +%sysctl_apply 50-libreswan.conf + +%preun +%systemd_preun ipsec.service + +%postun +%systemd_postun_with_restart ipsec.service + +%files +%doc CHANGES COPYING CREDITS README* LICENSE +%doc docs/*.* docs/examples +%attr(0644,root,root) %{_unitdir}/ipsec.service +%doc %{_mandir}/*/* + +%files minimal +%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ipsec.conf +%attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ipsec.secrets +%attr(0700,root,root) %dir %{_sysconfdir}/ipsec.d +%attr(0700,root,root) %dir %{_sysconfdir}/ipsec.d/policies +%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ipsec.d/policies/* +%attr(0644,root,root) %config(noreplace) %{_sysctldir}/50-libreswan.conf +%attr(0755,root,root) %dir %{_rundir}/pluto +%attr(0700,root,root) %dir %{_sharedstatedir}/ipsec +%attr(0700,root,root) %dir %{_sharedstatedir}/ipsec/nss +%attr(0644,root,root) %{_tmpfilesdir}/libreswan.conf +%attr(0644,root,root) %config(noreplace) %{_sysconfdir}/pam.d/pluto +%config(noreplace) %{_sysconfdir}/logrotate.d/libreswan +%{_sbindir}/ipsec +%{_libexecdir}/ipsec + +%changelog +## START: Generated by rpmautospec +* Thu Jul 23 2026 Daiki Ueno - 5.3.2-1 +- Update to libreswan-5.3.2 + +* Thu Jul 02 2026 Daiki Ueno - 5.3.1-1 +- Update to libreswan-5.3.1 + +* Wed Mar 18 2026 Daiki Ueno - 5.3-8 +- Bump release number + +* Tue Mar 17 2026 Ondrej Moris - 5.3-7 +- ikev2: use nonces to tie-break simultaneous IKE + +* Tue Mar 17 2026 Ondrej Moris - 5.3-6 +- CI: Update CI plan url + +* Mon Feb 23 2026 Daiki Ueno - 5.3-5 +- Subpackage minimal set of daemons into -minimal + +* Tue Feb 03 2026 Daiki Ueno - 5.3-4 +- pluto: reject crossing IKE_AUTH request only for the one side + +* Wed Jan 14 2026 Andrew Cagney - 5.3-3 +- helpers: work around NSS by joining helper threads + +* Fri Jan 09 2026 Ondrej Moris - 5.3-2 +- ikev2: reject simultaneous IKE_AUTH requests + +* Fri Jul 11 2025 Daiki Ueno - 5.3-1 +- Update to libreswan-5.3 + +* Wed Jun 18 2025 Daiki Ueno - 5.2-2 +- ipsec delete: expect no IKE only for orphan child + +* Thu Mar 06 2025 Daiki Ueno - 5.2-1 +- Update to libreswan 5.2 + +* Thu Jan 30 2025 Daiki Ueno - 5.1-6 +- ipsec: fix duplicate --ctlsocket option for whack + +* Fri Jan 24 2025 Daiki Ueno - 5.1-5 +- Avoid expectiation failure with crossing streams + +* Fri Jan 24 2025 Daiki Ueno - 5.1-4 +- Speed up parsing protoport configuration + +* Fri Jan 24 2025 Daiki Ueno - 5.1-3 +- showhostkey: fix regression after RHEL-69403 + +* Fri Nov 29 2024 Daiki Ueno - 5.1-2 +- crypto: refcnt struct secret_pubkey_stuff when passing to helper thread + +* Fri Nov 29 2024 Paul Wouters - 5.1-1 +- Update to libreswan 5.1 + +* Tue Oct 29 2024 Troy Dawson - 4.15-7 +- Bump release for October 2024 mass rebuild: + +* Thu Aug 08 2024 Ondrej Moris - 4.15-6 +- Add RHEL-10 CI and gating configuration + +* Tue Aug 06 2024 Daiki Ueno - 4.15-5 +- Make use of Netlink extack for additional error reporting + +* Tue Aug 06 2024 Daiki Ueno - 4.15-4 +- Fix auto=ondemand connection initialization with TCP + +* Tue Aug 06 2024 Daiki Ueno - 4.15-3 +- Re-introduce libreswan-4.6-ikev1-policy-defaults-to-drop.patch + +* Thu Jun 27 2024 Paul Wouters - 4.15-2 +- Add libreswan-4.15-ipsec_import.patch + +* Thu Jun 27 2024 Paul Wouters - 4.15-1 +- Update libreswan to 4.15 for CVE-2024-3652 +- Resolves rhbz#2274448 CVE-2024-3652 libreswan: IKEv1 default AH/ESP + responder can crash and restart +- Allow "ipsec import" to try importing PKCS#12 non-interactively if there + is no password + +* Thu Jun 27 2024 Paul Wouters - 4.14-1 +- Update to 4.14 for CVE-2024-2357 + +* Mon Jun 24 2024 Troy Dawson - 4.12-3.3 +- Bump release for June 2024 mass rebuild + +* Thu Jan 25 2024 Fedora Release Engineering - 4.12-3.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sun Jan 21 2024 Fedora Release Engineering - 4.12-3.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Fri Sep 08 2023 Paul Wouters - 4.12-3 +- Update libcap-ng patch, fix email addresses in changelog + +* Tue Sep 05 2023 Paul Wouters - 4.12-2 +- Remove ipsec show and ipsec verify sub commands (not very useful, causes python requirement) +- Patch for handling libcap-ng return values and fix capng_apply() call + +* Fri Aug 11 2023 Paul Wouters - 4.12-1 +- Update to 4.12 for CVE-2023-38710, CVE-2023-38711 and CVE-2023-38712 +- Resolves: rhbz#2230225 libreswan-4.12 is available + +* Thu Jul 20 2023 Fedora Release Engineering - 4.11-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu May 04 2023 Paul Wouters - 4.11-1 +- Update to 4.11 for CVE-2023-30570 + +* Wed Mar 01 2023 Paul Wouters - 4.10-1 +- Update to 4.10 for CVE-2023-23009 + +* Thu Jan 19 2023 Fedora Release Engineering - 4.9-2.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Tue Jan 10 2023 Paul Wouters - 4.9-2 +- Use new GPG key location. + +* Thu Oct 13 2022 Paul Wouters - 4.9-1 +- Update to 4.9 (maxbytes/maxpackets support, raw ECDSA support, misc fixes) + +* Thu Jul 21 2022 Fedora Release Engineering - 4.7-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Tue May 24 2022 Paul Wouters - 4.7-1 +- Updated to 4.7 (EAPTLS support, bugfixes) + +* Thu Jan 20 2022 Fedora Release Engineering - 4.6-2.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Thu Jan 13 2022 Paul Wouters - 4.6-2 +- Re-enable USE_DNSSEC again with patch to resolve header conflicts + +* Wed Jan 12 2022 Paul Wouters - 4.6-1 +- Resolves: CVE-2022-23094 +- Resolves: rhbz#2039604 libreswan-4.6 is available +- Add gpg key and signature check for build +- Temporarilly disable USE_DNSSEC in rawhide while we figure out openssl vs nss include clash + +* Thu Aug 26 2021 Paul Wouters - 4.5-1 +- Resolves rhbz#1996250 libreswan-4.5 is available + +* Tue Aug 03 2021 Paul Wouters - 4.4-3 +- Resolves rhbz#1989198 libreswan should depend on procps-ng or pidof + +* Thu Jul 22 2021 Fedora Release Engineering - 4.4-2.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Mon Jun 07 2021 Paul Wouters - 4.4-2 +- Properly handle rpm sysctl config + +* Wed May 12 2021 Paul Wouters - 4.4-1 +- Resolves: rhbz#1952602 libreswan-4.4 is available + +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 4.3-1.1 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + +* Sun Feb 21 2021 Paul Wouters - 4.3-1 +- update to 4.3 (minor bugfix release) + +* Wed Feb 03 2021 Paul Wouters - 4.2-1 +- Update to 4.2 + +* Tue Jan 26 2021 Fedora Release Engineering - 4.2-0.1.rc1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Sat Dec 19 19:59:55 EST 2020 Paul Wouters - 4.2-0.1.rc1 +- Resolves: rhbz#1867580 pluto process frequently dumps core + (disable USE_NSS_KDF until nss fixes have propagated) + +* Sat Dec 19 2020 Adam Williamson - 4.1-4 +- Rebuild for ldns soname bump + +* Mon Nov 23 11:50:41 EST 2020 Paul Wouters - 4.1-3 +- Resolves: rhbz#1894381 Libreswan 4.1-2 breaks l2tp connection to Windows VPN server + +* Mon Oct 26 10:21:57 EDT 2020 Paul Wouters - 4.1-2 +- Resolves: rhbz#1889538 libreswan's /var/lib/ipsec/nss missing + +* Sun Oct 18 21:49:39 EDT 2020 Paul Wouters - 4.1-1 +- Updated to 4.1 - interop fix for Cisco + +* Thu Oct 15 10:27:14 EDT 2020 Paul Wouters - 4.0-1 +- Resolves: rhbz#1888448 libreswan-4.0 is available + +* Wed Sep 30 14:05:58 EDT 2020 Paul Wouters - 4.0-0.2.rc1 +- Rebuild for libevent 2.1.12 with a soname bump + +* Sun Sep 27 22:49:40 EDT 2020 Paul Wouters - 4.0-0.1.rc1 +- Updated to 4.0rc1 + +* Thu Aug 27 2020 Paul Wouters - 3.32-4 +- Resolves: rhbz#1864043 libreswan: FTBFS in Fedora rawhide/f33 + +* Sat Aug 01 2020 Fedora Release Engineering - 3.32-3.2 +- Second attempt - Rebuilt for + https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Tue Jul 28 2020 Fedora Release Engineering - 3.32-3.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Tue Jun 30 2020 Jeff Law - 3.32-3 +- Initialize ppk_id_p in ikev2_parent_inR1outI2_tail to avoid uninitialized + object + +* Tue May 26 2020 Paul Wouters - 3.32-2 +- Backport NSS guarding fix for unannounced changed api in NSS causing segfault + +* Mon May 11 2020 Paul Wouters - 3.32-1 +- Resolves: rhbz#1809770 libreswan-3.32 is available + +* Tue Apr 14 2020 Paul Wouters - 3.31-2 +- Resolves: rhbz#1823823 Please drop the dependency on fipscheck + +* Tue Mar 03 2020 Paul Wouters - 3.31-1 +- Resolves: rhbz#1809770 libreswan-3.31 is available (fixes rekey regression) + +* Fri Feb 14 2020 Paul Wouters - 3.30-1 +- Resolves: rhbz#1802896 libreswan-3.30 is available +- Resolves: rhbz#1799598 libreswan: FTBFS in Fedora rawhide/f32 +- Resolves: rhbz#1760571 [abrt] libreswan: configsetupcheck(): verify:366:configsetupcheck:TypeError: + +* Wed Jan 29 2020 Fedora Release Engineering - 3.29-2.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Thu Jan 09 2020 Paul Wouters - 3.29-2 +- _updown.netkey: fix syntax error in checking routes + +* Thu Jul 25 2019 Fedora Release Engineering - 3.29-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Mon Jun 10 2019 Paul Wouters - 3.29-1 +- Resolves: rhbz#1718986 Updated to 3.29 for CVE-2019-10155 + +* Tue May 21 2019 Paul Wouters - 3.28-1 +- Updated to 3.28 (many imported bugfixes, including CVE-2019-12312) + +* Fri Feb 01 2019 Fedora Release Engineering - 3.27-1.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Mon Jan 14 2019 Björn Esser - 3.27-1.1 +- Rebuilt for libcrypt.so.2 (#1666033) + +* Mon Oct 08 2018 Paul Wouters - 3.27-1 +- Updated to 3.27 (various bugfixes) + +* Thu Sep 27 2018 Paul Wouters - 3.26-3 +- Add fedora python fixup for _unbound-hook + +* Mon Sep 17 2018 Paul Wouters - 3.26-2 +- linking against freebl is no longer needed (and wasn't done in 3.25) + +* Mon Sep 17 2018 Paul Wouters - 3.26-1 +- Updated to 3.26 (CHACHA20POLY1305, ECDSA and RSA-PSS support) + +* Fri Jul 13 2018 Fedora Release Engineering - 3.25-3.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Mon Jul 09 2018 Paul Wouters - 3.25-3 +- Fix Opportunistic IPsec _unbound-hook argument parsing +- Make rundir readable for all (so we can hand out permissions later) + +* Mon Jul 02 2018 Paul Wouters - 3.25-2 +- Relax deleting IKE SA's and IPsec SA's to avoid interop issues with third party VPN vendors + +* Wed Jun 27 2018 Paul Wouters - 3.25-1 +- Updated to 3.25 + +* Mon Feb 19 2018 Paul Wouters - 3.23-2 +- Support crypto-policies package +- Pull in some patches from upstream and IANA registry updates +- gcc7 format-truncate fixes and workarounds + +* Wed Feb 07 2018 Fedora Release Engineering - 3.23-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Thu Jan 25 2018 Paul Wouters - 3.23-1 +- Updated to 3.23 - support for MOBIKE, PPK, CMAC, nic offload and performance improvements + +* Sat Jan 20 2018 Björn Esser - 3.22-1.1 +- Rebuilt for switch to libxcrypt + +* Mon Oct 23 2017 Paul Wouters - 3.22-1 +- Updated to 3.22 - many bugfixes, and unbound ipsecmod support + +* Wed Aug 9 2017 Paul Wouters - 3.21-1 +- Updated to 3.21 + +* Thu Aug 03 2017 Fedora Release Engineering - 3.20-1.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Wed Jul 26 2017 Fedora Release Engineering - 3.20-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Tue Mar 14 2017 Paul Wouters - 3.20-1 +- Updated to 3.20 + +* Fri Mar 03 2017 Paul Wouters - 3.20-0.1.dr4 +- Update to 3.20dr4 to test mozbz#1336487 export CERT_CompareAVA + +* Fri Feb 10 2017 Fedora Release Engineering - 3.19-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Fri Feb 03 2017 Paul Wouters - 3.19-2 +- Resolves: rhbz#1392191 libreswan: crash when OSX client connects +- Improved uniqueid and session replacing support +- Test Buffer warning fix on size_t +- Re-introduce --configdir for backwards compatibility + +* Sun Jan 15 2017 Paul Wouters - 3.19-1 +- Updated to 3.19 (see download.libreswan.org/CHANGES) + +* Mon Dec 19 2016 Miro Hrončok - 3.18-1.1 +- Rebuild for Python 3.6 + +* Fri Jul 29 2016 Paul Wouters - 3.18-1 +- Updated to 3.18 for CVE-2016-5391 rhbz#1361164 and VTI support +- Remove support for /etc/sysconfig/pluto (use native systemd instead) + +* Thu May 05 2016 Paul Wouters - 3.17-2 +- Resolves: rhbz#1324956 prelink is gone, /etc/prelink.conf.d/* is no longer used + +* Thu Apr 07 2016 Paul Wouters - 3.17-1 +- Updated to 3.17 for CVE-2016-3071 +- Disable LIBCAP_NG as it prevents unbound-control from working properly +- Temporarilly disable WERROR due to a few minor known issues + +* Thu Feb 04 2016 Fedora Release Engineering - 3.16-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Fri Dec 18 2015 Paul Wouters - 3.16-1 +- Updated to 3.16 (see https://download.libreswan.org/CHANGES) + +* Tue Aug 11 2015 Paul Wouters - 3.15-1 +- Updated to 3.15 (see http://download.libreswan.org/CHANGES) +- Resolves: rhbz#CVE-2015-3240 IKE daemon restart when receiving a bad DH gx +- NSS database creation moved from spec file to service file +- Run CAVS tests on package build +- Added BuildRequire systemd-units and xmlto +- Bumped minimum required nss to 3.16.1 +- Install tmpfiles +- Install sysctl file +- Update doc files to include + +* Mon Jul 13 2015 Paul Wouters - 3.13-2 +- Resolves: rhbz#1238967 Switch libreswan to use python3 + +* Wed Jun 17 2015 Fedora Release Engineering - 3.13-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Mon Jun 01 2015 Paul Wouters - 3.13-1 +- Updated to 3.13 for CVE-2015-3204 + +* Fri Nov 07 2014 Paul Wouters - 3.12-1 +- Updated to 3.12 Various IKEv2 fixes + +* Wed Oct 22 2014 Paul Wouters - 3.11-1 +- Updated to 3.11 (many fixes, including startup fixes) +- Resolves: rhbz#1144941 libreswan 3.10 upgrade breaks old ipsec.secrets configs +- Resolves: rhbz#1147072 ikev1 aggr mode connection fails after libreswan upgrade +- Resolves: rhbz#1144831 Libreswan appears to start with systemd before all the NICs are up and running + +* Tue Sep 09 2014 Paul Wouters - 3.10-3 +- Fix some coverity issues, auto=route on bootup and snprintf on 32bit machines + +* Mon Sep 01 2014 Paul Wouters - 3.10-1 +- Updated to 3.10, major bugfix release, new xauth status options + +* Sun Aug 17 2014 Fedora Release Engineering - 3.9-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Thu Jul 10 2014 Paul Wouters - 3.9-1 +- Updated to 3.9. IKEv2 enhancements, ESP/IKE algo enhancements +- Mark libreswan-fips.conf as config file +- attr modifier for man pages no longer needed +- BUGS file no longer exists upstream + +* Sat Jun 07 2014 Fedora Release Engineering - 3.8-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sat Jan 18 2014 Paul Wouters - 3.8-1 +- Updated to 3.8, fixes rhbz#CVE-2013-6467 (rhbz#1054102) + +* Wed Dec 11 2013 Paul Wouters - 3.7-1 +- Updated to 3.7, fixes CVE-2013-4564 +- Fixes creating a bogus NSS db on startup (rhbz#1005410) + +* Thu Oct 31 2013 Paul Wouters - 3.6-1 +- Updated to 3.6 (IKEv2, MODECFG, Cisco interop fixes) +- Generate empty NSS db if none exists + +* Mon Aug 19 2013 Paul Wouters - 3.5-3 +- Add a Provides: for openswan-doc + +* Sat Aug 03 2013 Fedora Release Engineering - 3.5-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Mon Jul 15 2013 Paul Wouters - 3.5-2 +- Added interop patch for (some?) Cisco VPN clients sending 16 zero + bytes of extraneous IKE data +- Removed fipscheck_version + +* Sat Jul 13 2013 Paul Wouters - 3.5-1 +- Updated to 3.5 + +* Thu Jun 06 2013 Paul Wouters - 3.4-1 +- Updated to 3.4, which only contains style changes to kernel coding style +- IN MEMORIAM: June 3rd, 2013 Hugh Daniel + +* Mon May 13 2013 Paul Wouters - 3.3-1 +- Updated to 3.3, which resolves CVE-2013-2052 + +* Sat Apr 13 2013 Paul Wouters - 3.2-1 +- Initial package for Fedora + +## END: Generated by rpmautospec diff --git a/sources b/sources new file mode 100644 index 0000000..0052027 --- /dev/null +++ b/sources @@ -0,0 +1,5 @@ +SHA512 (ikev1_dsa.fax.bz2) = 627cbac14248bd68e8d22fbca247668a7749ef0c2e41df8d776d62df9a21403d3a246c0bd82c3faedce62de90b9f91a87f753e17b056319000bba7d2038461ac +SHA512 (ikev1_psk.fax.bz2) = 1b2daec32edc56b410c036db2688c92548a9bd9914994bc7e555b301dd6db4497a6b3e89dc12ddf36826ae90b40fcde501a5a45c0d59098e07839073d219d467 +SHA512 (ikev2.fax.bz2) = 0d3748d1bd574f6f1f3e4db847eca126ce649566ea710ef227426f433122752b80d1d6b8acf9d0df07b5597c1e45447e3a2fcb3391756e834e8e75f99df8e51e +SHA512 (libreswan-5.3.2.tar.gz) = 4dfe71bed06d356c5a33e1874ec934eab8a57a2bdedff8069ebcf65b09dd79490665cbb5b94b691d6e873a0a8e6eb131a4942ffa845a5836a5344436c8efb879 +SHA512 (libreswan-5.3.2.tar.gz.sig) = 55062be3c579316233e63ff44d0c46754517d3a829a9e6b7f2234e10f40eec451696e46695e1f4d4784c89e1b71aabaab8dcf66faa8ddd5e55107ed74f61dd2c