History log of /openbsd-current/sbin/isakmpd/isakmpd.policy.5
Revision (<<< Hide revision tags) (Show revision tags >>>) Date Author Comments
# 1.51 06-Feb-2022 jsg

remove please from manual pages
ok jmc@ sthen@ millert@


# 1.50 22-Oct-2021 jmc

remove some bad punctuation;


# 1.49 22-Oct-2021 bluhm

After deleting hifn(4) the only provider for the LZS compression
algorithm is gone. Reomve all LZS references from the tree. The
v42bis in isakmpd also looks unsupported.
OK mvs@ patrick@ sthen@


Revision tags: OPENBSD_5_9_BASE OPENBSD_6_0_BASE OPENBSD_6_1_BASE OPENBSD_6_2_BASE OPENBSD_6_3_BASE OPENBSD_6_4_BASE OPENBSD_6_5_BASE OPENBSD_6_6_BASE OPENBSD_6_7_BASE OPENBSD_6_8_BASE OPENBSD_6_9_BASE OPENBSD_7_0_BASE
# 1.48 11-Jan-2016 jmc

typo fix; from julian hsiao


# 1.47 08-Jan-2016 jmc

tweak; from julian hsiao


Revision tags: OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE OPENBSD_5_7_BASE OPENBSD_5_8_BASE
# 1.46 13-Jul-2012 mikeb

Support additional MODP DH groups in the Phase 1 and Phase 2.
lteo@ noticed that ipsecctl allowed them within the ike rules
while isakmpd failed to load the generated configuration.
The fix was verified by hshoexer, ok naddy


Revision tags: OPENBSD_5_1_BASE
# 1.45 29-Sep-2011 jmc

ssl.8: Certifying Authority -> Certificate Authority
isakmpd.8: rsa:1024 -> rsa:2048 (ok markus)
all: X509 -> X.509

from Lawrence Teo


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE
# 1.44 07-Jun-2010 jmc

make clearer the relationship between isakmpd and ikev1; and iked and ikev2;
ok reyk


# 1.43 06-Apr-2010 jmc

fix some more dodgy "-indent"; aucat.1 has some too, but i'll leave that for
ratchov, to avoid messing up his current diff...


# 1.42 26-Mar-2010 jmc

dispense with some wacky escape sequences;


Revision tags: OPENBSD_4_2_BASE OPENBSD_4_3_BASE OPENBSD_4_4_BASE OPENBSD_4_5_BASE OPENBSD_4_6_BASE OPENBSD_4_7_BASE
# 1.41 31-May-2007 jmc

convert to new .Dd format;


# 1.40 23-May-2007 hshoexer

Get rid of some obsolete exampels.

ok and prodding @jmc


Revision tags: OPENBSD_4_0_BASE OPENBSD_4_1_BASE
# 1.39 02-Jun-2006 hshoexer

Big spelling cleanup, no binary change. From david@


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE
# 1.38 05-May-2005 jmc

sort options;


# 1.37 05-May-2005 jmc

grammar/mdoc tweaks;


Revision tags: OPENBSD_3_7_BASE
# 1.36 13-Mar-2005 miod

Typo; spotted by Richard Ben Aleya


Revision tags: OPENBSD_3_5_BASE OPENBSD_3_6_BASE
# 1.35 25-Oct-2003 mcbride

OpenSSL generates DNs with emailAddress, not Email.


Revision tags: OPENBSD_3_4_BASE
# 1.34 25-Jul-2003 markus

add sha2


# 1.33 09-Jul-2003 jmc

- remove some .Ss's that worked around the old blank line bug
- remove some unnecessary .Pp's
- mdoc a list

ok ho@


# 1.32 04-Jun-2003 ho

Remove the rest of clauses 3 and 4. Approved by Niklas Hallqvist, Angelos
D. Keromytis and Niels Provos.


# 1.31 03-Jun-2003 jmc

- section reorder
- some mdoc fixes


Revision tags: OPENBSD_3_3_BASE
# 1.30 06-Mar-2003 jmc

.Xr typos;

ok deraadt@


# 1.29 20-Jan-2003 deraadt

typos; alan@alanday.com


# 1.28 19-Jan-2003 deraadt

typos; jmc@prioris.mini.pw.edu.pl


# 1.27 27-Nov-2002 ho

Update document date.


Revision tags: OPENBSD_3_2_BASE
# 1.26 15-Jun-2002 angelos

ecn_* policy attributes --- ok ho@


Revision tags: OPENBSD_3_1_BASE
# 1.25 21-Dec-2001 mpech

Initial patch for a new mdoc issue.
Powered by @mantoya:
o) kill extra line in the end of file;
o) kill extra space in the end of line;
o) replace blank lines with .Pp;

millert@ ok


# 1.24 13-Dec-2001 mpech

o) start new sentence on a new line;
o) wrap long lines;
o) fix bogus .Xr usage;
o) we don't like blank lines;
o) always close .Bl tags;
o) OpenBSD -> .Ox;
o) don't like .Pp before .Ss;

millert@ ok;


Revision tags: OPENBSD_3_0_BASE
# 1.23 05-Oct-2001 ho

{local,remote}_negotiation_address can also be IPv6.
Replace 'idea' with 'aes' in the examples.


# 1.22 04-Oct-2001 angelos

Update BUGS section (after some bugging from ho@)


# 1.21 05-Jul-2001 angelos

Document ASN1 DN.


# 1.20 04-Jul-2001 angelos

Better handling of Key IDs.


# 1.19 25-Jun-2001 angelos

Update copyright dates.


# 1.18 30-Apr-2001 ho

Add a FILES section describing default and sample file locations.


Revision tags: OPENBSD_2_9_BASE
# 1.17 07-Mar-2001 angelos

Add KEY_ID support (mostly from roland@digitalvampire.org)


# 1.16 19-Feb-2001 angelos

passphrase-md5-hex: and passphrase-sha1-hex: formats for passphrases.


# 1.15 23-Nov-2000 niklas

Merge with EOM 1.24

author: niklas
sync with OpenBSD

author: angelos
Update.


Revision tags: OPENBSD_2_8_BASE
# 1.14 29-Oct-2000 aaron

branches: 1.14.2;
Put .Dt's argument in all-caps; nate@


# 1.13 16-Oct-2000 niklas

ipsec_num.cst: Merge with EOM 1.5
isakmpd.policy.5: Merge with EOM 1.22

author: angelos
Add RIPEMD negotiation/configuration.


# 1.12 09-Oct-2000 niklas

samples/VPN-3way-template.conf: Merge with EOM 1.8
samples/VPN-east.conf: Merge with EOM 1.12
samples/VPN-west.conf: Merge with EOM 1.13
samples/policy: Merge with EOM 1.6
samples/singlehost-west.conf: Merge with EOM 1.9
samples/singlehost-east.conf: Merge with EOM 1.9
conf.c: Merge with EOM 1.37
ipsec.c: Merge with EOM 1.133
ipsec_num.cst: Merge with EOM 1.4
isakmpd.conf.5: Merge with EOM 1.48
isakmpd.policy.5: Merge with EOM 1.21
policy.c: Merge with EOM 1.46

author: angelos
AES support.


# 1.11 03-Aug-2000 niklas

Merge with EOM 1.20

author: angelos
Add "phase1_group_desc" attribute, and explain the various values.


# 1.10 08-Jun-2000 niklas

Merge with EOM 1.19

author: angelos
Point back to isakmpd.conf(5)

author: angelos
Remove fixed item from BUGs section.

author: angelos
Talk about re-loading of policies on SIGHUP.


Revision tags: OPENBSD_2_7_BASE
# 1.9 02-May-2000 niklas

Merge with EOM 1.16

author: angelos
Fix typo.

author: angelos
Add etherip and protocol numbers in the transport protocol entries,
document.


# 1.8 07-Apr-2000 niklas

Merge with EOM 1.14

author: angelos
*_ike_address -> *_negotiation_address (so it's not IKE specific)


# 1.7 07-Apr-2000 niklas

apps/certpatch/certpatch.8: Merge with EOM 1.5
isakmpd.8: Merge with EOM 1.20
isakmpd.conf.5: Merge with EOM 1.40
isakmpd.policy.5: Merge with EOM 1.13

author: niklas
Changes from OpenBSD


# 1.6 07-Apr-2000 niklas

Merge with EOM 1.12

author: angelos
Add phase_1 attribute.


# 1.5 23-Mar-2000 aaron

More pedantic man page formatting insanity, lalala


# 1.4 11-Feb-2000 niklas

Merge with EOM 1.11

author: angelos
Rename the "CN:" tag to "DN:", after Jorgen's suggestion.

author: angelos
Add an initiator attribute, and make the code amenable to be invoked
by the initiator as well (for policy compliance checking).

author: angelos
Fix typo, noted by Jorgen.Granstam@abc.se


# 1.3 07-Feb-2000 niklas

Merge with EOM 1.8

author: angelos
Add Canonical Names as policy targets (so they can be specified in the
Licensees field), with the "CN:..." format.

author: angelos
Done.

author: angelos
One missing item left...

author: angelos
More text.

author: angelos
Passphrases are encoded as "passphrase:xxxx" now, to distinguish
between passphrases and logic labels.

author: angelos
Consistent references.

author: angelos
Minor tweak.


# 1.2 26-Jan-2000 niklas

regress/exchange/def-i.1: Sync with EOM
regress/exchange/def-r.1: Sync with EOM
isakmpd.policy.5: Sync with EOM
.cvsignore: Add isakmpd.policy.cat5


Revision tags: OPENBSD_2_6_BASE
# 1.1 16-Oct-1999 angelos

Manpage describing policy.


# 1.50 22-Oct-2021 jmc

remove some bad punctuation;


# 1.49 22-Oct-2021 bluhm

After deleting hifn(4) the only provider for the LZS compression
algorithm is gone. Reomve all LZS references from the tree. The
v42bis in isakmpd also looks unsupported.
OK mvs@ patrick@ sthen@


Revision tags: OPENBSD_5_9_BASE OPENBSD_6_0_BASE OPENBSD_6_1_BASE OPENBSD_6_2_BASE OPENBSD_6_3_BASE OPENBSD_6_4_BASE OPENBSD_6_5_BASE OPENBSD_6_6_BASE OPENBSD_6_7_BASE OPENBSD_6_8_BASE OPENBSD_6_9_BASE OPENBSD_7_0_BASE
# 1.48 11-Jan-2016 jmc

typo fix; from julian hsiao


# 1.47 08-Jan-2016 jmc

tweak; from julian hsiao


Revision tags: OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE OPENBSD_5_7_BASE OPENBSD_5_8_BASE
# 1.46 13-Jul-2012 mikeb

Support additional MODP DH groups in the Phase 1 and Phase 2.
lteo@ noticed that ipsecctl allowed them within the ike rules
while isakmpd failed to load the generated configuration.
The fix was verified by hshoexer, ok naddy


Revision tags: OPENBSD_5_1_BASE
# 1.45 29-Sep-2011 jmc

ssl.8: Certifying Authority -> Certificate Authority
isakmpd.8: rsa:1024 -> rsa:2048 (ok markus)
all: X509 -> X.509

from Lawrence Teo


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE
# 1.44 07-Jun-2010 jmc

make clearer the relationship between isakmpd and ikev1; and iked and ikev2;
ok reyk


# 1.43 06-Apr-2010 jmc

fix some more dodgy "-indent"; aucat.1 has some too, but i'll leave that for
ratchov, to avoid messing up his current diff...


# 1.42 26-Mar-2010 jmc

dispense with some wacky escape sequences;


Revision tags: OPENBSD_4_2_BASE OPENBSD_4_3_BASE OPENBSD_4_4_BASE OPENBSD_4_5_BASE OPENBSD_4_6_BASE OPENBSD_4_7_BASE
# 1.41 31-May-2007 jmc

convert to new .Dd format;


# 1.40 23-May-2007 hshoexer

Get rid of some obsolete exampels.

ok and prodding @jmc


Revision tags: OPENBSD_4_0_BASE OPENBSD_4_1_BASE
# 1.39 02-Jun-2006 hshoexer

Big spelling cleanup, no binary change. From david@


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE
# 1.38 05-May-2005 jmc

sort options;


# 1.37 05-May-2005 jmc

grammar/mdoc tweaks;


Revision tags: OPENBSD_3_7_BASE
# 1.36 13-Mar-2005 miod

Typo; spotted by Richard Ben Aleya


Revision tags: OPENBSD_3_5_BASE OPENBSD_3_6_BASE
# 1.35 25-Oct-2003 mcbride

OpenSSL generates DNs with emailAddress, not Email.


Revision tags: OPENBSD_3_4_BASE
# 1.34 25-Jul-2003 markus

add sha2


# 1.33 09-Jul-2003 jmc

- remove some .Ss's that worked around the old blank line bug
- remove some unnecessary .Pp's
- mdoc a list

ok ho@


# 1.32 04-Jun-2003 ho

Remove the rest of clauses 3 and 4. Approved by Niklas Hallqvist, Angelos
D. Keromytis and Niels Provos.


# 1.31 03-Jun-2003 jmc

- section reorder
- some mdoc fixes


Revision tags: OPENBSD_3_3_BASE
# 1.30 06-Mar-2003 jmc

.Xr typos;

ok deraadt@


# 1.29 20-Jan-2003 deraadt

typos; alan@alanday.com


# 1.28 19-Jan-2003 deraadt

typos; jmc@prioris.mini.pw.edu.pl


# 1.27 27-Nov-2002 ho

Update document date.


Revision tags: OPENBSD_3_2_BASE
# 1.26 15-Jun-2002 angelos

ecn_* policy attributes --- ok ho@


Revision tags: OPENBSD_3_1_BASE
# 1.25 21-Dec-2001 mpech

Initial patch for a new mdoc issue.
Powered by @mantoya:
o) kill extra line in the end of file;
o) kill extra space in the end of line;
o) replace blank lines with .Pp;

millert@ ok


# 1.24 13-Dec-2001 mpech

o) start new sentence on a new line;
o) wrap long lines;
o) fix bogus .Xr usage;
o) we don't like blank lines;
o) always close .Bl tags;
o) OpenBSD -> .Ox;
o) don't like .Pp before .Ss;

millert@ ok;


Revision tags: OPENBSD_3_0_BASE
# 1.23 05-Oct-2001 ho

{local,remote}_negotiation_address can also be IPv6.
Replace 'idea' with 'aes' in the examples.


# 1.22 04-Oct-2001 angelos

Update BUGS section (after some bugging from ho@)


# 1.21 05-Jul-2001 angelos

Document ASN1 DN.


# 1.20 04-Jul-2001 angelos

Better handling of Key IDs.


# 1.19 25-Jun-2001 angelos

Update copyright dates.


# 1.18 30-Apr-2001 ho

Add a FILES section describing default and sample file locations.


Revision tags: OPENBSD_2_9_BASE
# 1.17 07-Mar-2001 angelos

Add KEY_ID support (mostly from roland@digitalvampire.org)


# 1.16 19-Feb-2001 angelos

passphrase-md5-hex: and passphrase-sha1-hex: formats for passphrases.


# 1.15 23-Nov-2000 niklas

Merge with EOM 1.24

author: niklas
sync with OpenBSD

author: angelos
Update.


Revision tags: OPENBSD_2_8_BASE
# 1.14 29-Oct-2000 aaron

branches: 1.14.2;
Put .Dt's argument in all-caps; nate@


# 1.13 16-Oct-2000 niklas

ipsec_num.cst: Merge with EOM 1.5
isakmpd.policy.5: Merge with EOM 1.22

author: angelos
Add RIPEMD negotiation/configuration.


# 1.12 09-Oct-2000 niklas

samples/VPN-3way-template.conf: Merge with EOM 1.8
samples/VPN-east.conf: Merge with EOM 1.12
samples/VPN-west.conf: Merge with EOM 1.13
samples/policy: Merge with EOM 1.6
samples/singlehost-west.conf: Merge with EOM 1.9
samples/singlehost-east.conf: Merge with EOM 1.9
conf.c: Merge with EOM 1.37
ipsec.c: Merge with EOM 1.133
ipsec_num.cst: Merge with EOM 1.4
isakmpd.conf.5: Merge with EOM 1.48
isakmpd.policy.5: Merge with EOM 1.21
policy.c: Merge with EOM 1.46

author: angelos
AES support.


# 1.11 03-Aug-2000 niklas

Merge with EOM 1.20

author: angelos
Add "phase1_group_desc" attribute, and explain the various values.


# 1.10 08-Jun-2000 niklas

Merge with EOM 1.19

author: angelos
Point back to isakmpd.conf(5)

author: angelos
Remove fixed item from BUGs section.

author: angelos
Talk about re-loading of policies on SIGHUP.


Revision tags: OPENBSD_2_7_BASE
# 1.9 02-May-2000 niklas

Merge with EOM 1.16

author: angelos
Fix typo.

author: angelos
Add etherip and protocol numbers in the transport protocol entries,
document.


# 1.8 07-Apr-2000 niklas

Merge with EOM 1.14

author: angelos
*_ike_address -> *_negotiation_address (so it's not IKE specific)


# 1.7 07-Apr-2000 niklas

apps/certpatch/certpatch.8: Merge with EOM 1.5
isakmpd.8: Merge with EOM 1.20
isakmpd.conf.5: Merge with EOM 1.40
isakmpd.policy.5: Merge with EOM 1.13

author: niklas
Changes from OpenBSD


# 1.6 07-Apr-2000 niklas

Merge with EOM 1.12

author: angelos
Add phase_1 attribute.


# 1.5 23-Mar-2000 aaron

More pedantic man page formatting insanity, lalala


# 1.4 11-Feb-2000 niklas

Merge with EOM 1.11

author: angelos
Rename the "CN:" tag to "DN:", after Jorgen's suggestion.

author: angelos
Add an initiator attribute, and make the code amenable to be invoked
by the initiator as well (for policy compliance checking).

author: angelos
Fix typo, noted by Jorgen.Granstam@abc.se


# 1.3 07-Feb-2000 niklas

Merge with EOM 1.8

author: angelos
Add Canonical Names as policy targets (so they can be specified in the
Licensees field), with the "CN:..." format.

author: angelos
Done.

author: angelos
One missing item left...

author: angelos
More text.

author: angelos
Passphrases are encoded as "passphrase:xxxx" now, to distinguish
between passphrases and logic labels.

author: angelos
Consistent references.

author: angelos
Minor tweak.


# 1.2 26-Jan-2000 niklas

regress/exchange/def-i.1: Sync with EOM
regress/exchange/def-r.1: Sync with EOM
isakmpd.policy.5: Sync with EOM
.cvsignore: Add isakmpd.policy.cat5


Revision tags: OPENBSD_2_6_BASE
# 1.1 16-Oct-1999 angelos

Manpage describing policy.


Revision tags: OPENBSD_5_9_BASE OPENBSD_6_0_BASE OPENBSD_6_1_BASE OPENBSD_6_2_BASE
# 1.48 11-Jan-2016 jmc

typo fix; from julian hsiao


# 1.47 08-Jan-2016 jmc

tweak; from julian hsiao


Revision tags: OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE OPENBSD_5_7_BASE OPENBSD_5_8_BASE
# 1.46 13-Jul-2012 mikeb

Support additional MODP DH groups in the Phase 1 and Phase 2.
lteo@ noticed that ipsecctl allowed them within the ike rules
while isakmpd failed to load the generated configuration.
The fix was verified by hshoexer, ok naddy


Revision tags: OPENBSD_5_1_BASE
# 1.45 29-Sep-2011 jmc

ssl.8: Certifying Authority -> Certificate Authority
isakmpd.8: rsa:1024 -> rsa:2048 (ok markus)
all: X509 -> X.509

from Lawrence Teo


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE
# 1.44 07-Jun-2010 jmc

make clearer the relationship between isakmpd and ikev1; and iked and ikev2;
ok reyk


# 1.43 06-Apr-2010 jmc

fix some more dodgy "-indent"; aucat.1 has some too, but i'll leave that for
ratchov, to avoid messing up his current diff...


# 1.42 26-Mar-2010 jmc

dispense with some wacky escape sequences;


Revision tags: OPENBSD_4_2_BASE OPENBSD_4_3_BASE OPENBSD_4_4_BASE OPENBSD_4_5_BASE OPENBSD_4_6_BASE OPENBSD_4_7_BASE
# 1.41 31-May-2007 jmc

convert to new .Dd format;


# 1.40 23-May-2007 hshoexer

Get rid of some obsolete exampels.

ok and prodding @jmc


Revision tags: OPENBSD_4_0_BASE OPENBSD_4_1_BASE
# 1.39 02-Jun-2006 hshoexer

Big spelling cleanup, no binary change. From david@


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE
# 1.38 05-May-2005 jmc

sort options;


# 1.37 05-May-2005 jmc

grammar/mdoc tweaks;


Revision tags: OPENBSD_3_7_BASE
# 1.36 13-Mar-2005 miod

Typo; spotted by Richard Ben Aleya


Revision tags: OPENBSD_3_5_BASE OPENBSD_3_6_BASE
# 1.35 25-Oct-2003 mcbride

OpenSSL generates DNs with emailAddress, not Email.


Revision tags: OPENBSD_3_4_BASE
# 1.34 25-Jul-2003 markus

add sha2


# 1.33 09-Jul-2003 jmc

- remove some .Ss's that worked around the old blank line bug
- remove some unnecessary .Pp's
- mdoc a list

ok ho@


# 1.32 04-Jun-2003 ho

Remove the rest of clauses 3 and 4. Approved by Niklas Hallqvist, Angelos
D. Keromytis and Niels Provos.


# 1.31 03-Jun-2003 jmc

- section reorder
- some mdoc fixes


Revision tags: OPENBSD_3_3_BASE
# 1.30 06-Mar-2003 jmc

.Xr typos;

ok deraadt@


# 1.29 20-Jan-2003 deraadt

typos; alan@alanday.com


# 1.28 19-Jan-2003 deraadt

typos; jmc@prioris.mini.pw.edu.pl


# 1.27 27-Nov-2002 ho

Update document date.


Revision tags: OPENBSD_3_2_BASE
# 1.26 15-Jun-2002 angelos

ecn_* policy attributes --- ok ho@


Revision tags: OPENBSD_3_1_BASE
# 1.25 21-Dec-2001 mpech

Initial patch for a new mdoc issue.
Powered by @mantoya:
o) kill extra line in the end of file;
o) kill extra space in the end of line;
o) replace blank lines with .Pp;

millert@ ok


# 1.24 13-Dec-2001 mpech

o) start new sentence on a new line;
o) wrap long lines;
o) fix bogus .Xr usage;
o) we don't like blank lines;
o) always close .Bl tags;
o) OpenBSD -> .Ox;
o) don't like .Pp before .Ss;

millert@ ok;


Revision tags: OPENBSD_3_0_BASE
# 1.23 05-Oct-2001 ho

{local,remote}_negotiation_address can also be IPv6.
Replace 'idea' with 'aes' in the examples.


# 1.22 04-Oct-2001 angelos

Update BUGS section (after some bugging from ho@)


# 1.21 05-Jul-2001 angelos

Document ASN1 DN.


# 1.20 04-Jul-2001 angelos

Better handling of Key IDs.


# 1.19 25-Jun-2001 angelos

Update copyright dates.


# 1.18 30-Apr-2001 ho

Add a FILES section describing default and sample file locations.


Revision tags: OPENBSD_2_9_BASE
# 1.17 07-Mar-2001 angelos

Add KEY_ID support (mostly from roland@digitalvampire.org)


# 1.16 19-Feb-2001 angelos

passphrase-md5-hex: and passphrase-sha1-hex: formats for passphrases.


# 1.15 23-Nov-2000 niklas

Merge with EOM 1.24

author: niklas
sync with OpenBSD

author: angelos
Update.


Revision tags: OPENBSD_2_8_BASE
# 1.14 29-Oct-2000 aaron

branches: 1.14.2;
Put .Dt's argument in all-caps; nate@


# 1.13 16-Oct-2000 niklas

ipsec_num.cst: Merge with EOM 1.5
isakmpd.policy.5: Merge with EOM 1.22

author: angelos
Add RIPEMD negotiation/configuration.


# 1.12 09-Oct-2000 niklas

samples/VPN-3way-template.conf: Merge with EOM 1.8
samples/VPN-east.conf: Merge with EOM 1.12
samples/VPN-west.conf: Merge with EOM 1.13
samples/policy: Merge with EOM 1.6
samples/singlehost-west.conf: Merge with EOM 1.9
samples/singlehost-east.conf: Merge with EOM 1.9
conf.c: Merge with EOM 1.37
ipsec.c: Merge with EOM 1.133
ipsec_num.cst: Merge with EOM 1.4
isakmpd.conf.5: Merge with EOM 1.48
isakmpd.policy.5: Merge with EOM 1.21
policy.c: Merge with EOM 1.46

author: angelos
AES support.


# 1.11 03-Aug-2000 niklas

Merge with EOM 1.20

author: angelos
Add "phase1_group_desc" attribute, and explain the various values.


# 1.10 08-Jun-2000 niklas

Merge with EOM 1.19

author: angelos
Point back to isakmpd.conf(5)

author: angelos
Remove fixed item from BUGs section.

author: angelos
Talk about re-loading of policies on SIGHUP.


Revision tags: OPENBSD_2_7_BASE
# 1.9 02-May-2000 niklas

Merge with EOM 1.16

author: angelos
Fix typo.

author: angelos
Add etherip and protocol numbers in the transport protocol entries,
document.


# 1.8 07-Apr-2000 niklas

Merge with EOM 1.14

author: angelos
*_ike_address -> *_negotiation_address (so it's not IKE specific)


# 1.7 07-Apr-2000 niklas

apps/certpatch/certpatch.8: Merge with EOM 1.5
isakmpd.8: Merge with EOM 1.20
isakmpd.conf.5: Merge with EOM 1.40
isakmpd.policy.5: Merge with EOM 1.13

author: niklas
Changes from OpenBSD


# 1.6 07-Apr-2000 niklas

Merge with EOM 1.12

author: angelos
Add phase_1 attribute.


# 1.5 23-Mar-2000 aaron

More pedantic man page formatting insanity, lalala


# 1.4 11-Feb-2000 niklas

Merge with EOM 1.11

author: angelos
Rename the "CN:" tag to "DN:", after Jorgen's suggestion.

author: angelos
Add an initiator attribute, and make the code amenable to be invoked
by the initiator as well (for policy compliance checking).

author: angelos
Fix typo, noted by Jorgen.Granstam@abc.se


# 1.3 07-Feb-2000 niklas

Merge with EOM 1.8

author: angelos
Add Canonical Names as policy targets (so they can be specified in the
Licensees field), with the "CN:..." format.

author: angelos
Done.

author: angelos
One missing item left...

author: angelos
More text.

author: angelos
Passphrases are encoded as "passphrase:xxxx" now, to distinguish
between passphrases and logic labels.

author: angelos
Consistent references.

author: angelos
Minor tweak.


# 1.2 26-Jan-2000 niklas

regress/exchange/def-i.1: Sync with EOM
regress/exchange/def-r.1: Sync with EOM
isakmpd.policy.5: Sync with EOM
.cvsignore: Add isakmpd.policy.cat5


Revision tags: OPENBSD_2_6_BASE
# 1.1 16-Oct-1999 angelos

Manpage describing policy.