ipsec-tools - IPsec utilities

IPsec (Internet Protocol security) offers end-to-end security for network traffic at the IP layer. This package is a Linux port of the utilities from the KAME IPsec implementation on BSD.



    Install Howto

    1. Update the package index:
      # sudo apt-get update
    2. Install ipsec-tools deb package:
      # sudo apt-get install ipsec-tools


    2015-05-22 - Salvatore Bonaccorso <carnil@debian.org> ipsec-tools (1:0.8.2+20140711-2+deb8u1) jessie-security; urgency=high * Non-maintainer upload by the Security Team. * Add bug785778-null-pointer-deref.patch patch. CVE-2015-4047: Fix NULL pointer dereference in racoon in gssapi.c leading to a possible crash and denial of service attack. (Closes: #785778)

    2014-10-13 - Noah Meyerhans <noahm@debian.org> ipsec-tools (1:0.8.2+20140711-2) unstable; urgency=low * Stop using hardening-wrapper * Import patch for checkpoint xauth. (Closes: 650176) * Bump standards version to 3.9.6 (no changes)

    2014-07-11 - Noah Meyerhans <noahm@debian.org> ipsec-tools (1:0.8.2+20140711-1) unstable; urgency=medium * Repackage upstream release 0.8.2 for real. Previous releases were based on an incomplete import and were essentially 0.8.0. * Remove patch debian/patches/gcc-4.8.diff, which has been incorportated upstream. * Remove patch debian/patches/patch-to-support-cast128, which has been incorportated upstream. * Import patch for x509 IPv6 literal address subjectAltName support from Adam Majer <adamm@zombino.com> (Closes: #738573)

    2014-06-29 - Christian Hofstaedtler <zeha@debian.org> ipsec-tools (1:0.8.2-4) unstable; urgency=medium * Fix newly introduced FTBFS on kFreeBSD. The previous patch defined __USE_GNU in a fragile way, but as we're really on a glibc platform, we can just define _GNU_SOURCE, similar to what is done on Linux. * Refresh patch "configure-pass-Wl-with-R"

    2014-06-28 - Christian Hofstaedtler <zeha@debian.org> ipsec-tools (1:0.8.2-3) unstable; urgency=medium * Update patch gcc-4.8.diff. As per NetBSD CVS, the memset is unneeded after (racoon_)calloc(). * Support building with automake 1.14. Set required options to restore old automake behavior, and run autoreconf during build. Removed patches to configure, removed explicit rpath setting and chrpath. Dropped superfluous symbols files, as we are not a library package and these were probably added by accident. * Only use UTF8 encoding in ASN.1 strings. This is recommended by RFC2459 (2004), and has been made the default in OpenSSL 1.0.1h. Fixes the FTBFS caused by the OpenSSL change. (Closes: #752946) * Add myself to Uploaders * Set Vcs-Git to a git:// URL

    2014-05-08 - Noah Meyerhans <noahm@debian.org> ipsec-tools (1:0.8.2-2) unstable; urgency=low * Fix FTBFS on kfreebsd.

    2014-04-27 - Noah Meyerhans <noahm@debian.org> ipsec-tools (1:0.8.2-1) unstable; urgency=medium * New upstream release 0.8.2 * Add a systemd unit file for racoon. * Update maintainer and VCS details in debian/control. * Update standards compliance to 3.9.5 (no changes) * Update config.{sub,guess} (Closes: 727294) * Add dependency on lsb-base for /lib/lsb/init-functions (Closes: 695074) * Update Dutch debconf translation (Closes: #692817) * Update Japanese debconf translation (Closes: #715193)

    2013-11-23 - gregor herrmann <gregoa@debian.org> ipsec-tools (1:0.8.0-14.1) unstable; urgency=low * Non-maintainer upload. * Fix "ftbfs with GCC-4.8": add patch from Ubuntu / Matthias Klose, which dereferences argument to 'sizeof' in 'memset' (Closes: #701299)