libreswan-3.12-10.1.0.1.el7.AXS7

エラータID: AXSA:2015-218:01

Release date: 
Saturday, July 25, 2015 - 13:58
Subject: 
libreswan-3.12-10.1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is
the Internet Protocol Security and uses strong cryptography to provide
both authentication and encryption services. These services allow you
to build secure tunnels through untrusted networks. Everything passing
through the untrusted net is encrypted by the ipsec gateway machine and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network or VPN.

This package contains the daemons and userland tools for setting up
Libreswan. To build KLIPS, see the kmod-libreswan.spec file.

Libreswan also supports IKEv2 (RFC4309) and Secure Labeling

Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04

Security issues fixed with this release:

CVE-2015-3204

Fixed bugs:

* Previously, the programs/pluto/state.h and programs/pluto/kernel_netlink.c files had a maximum SELinux context size of 257 and 1024 respectively. These restrictions set by libreswan limited the size of the context that can be exchanged by pluto (the IPSec daemon) when using a Labeled Internet Protocol Security (IPsec). With this update, fixed it.
* On some architectures, the kernel AES_GCM IPsec algorithm did not work properly with acceleration drivers. On those kernels, some acceleration modules are added to the modprobe blacklist. However, Libreswan was ignoring this blacklist, leading to AES_GCM failures. With this update, fixed it.
* An IPv6 issue has been resolved that prevented ipv6-icmp Neighbour Discovery from working properly once an IPsec tunnel is established (and one endpoint reboots). When upgrading, ensure that /etc/ipsec.conf is loading all /etc/ipsec.d/*conf files using the /etc/ipsec.conf "include" statement, or explicitly include this new configuration file in /etc/ipsec.conf.
* A FIPS self-test prevented libreswan from properly starting in FIPS mode. This bug has been fixed and libreswan now works in FIPS mode as expected.

Enhancements:

* A new option "seedbits=" has been added to pre-seed the Network Security Services (NSS) pseudo random number generator (PRNG) function with entropy from the /dev/random file on startup. This option is disabled by default. It can be enabled by setting the "seedbits=" option in the "config setup" section in the /etc/ipsec.conf file.
* The build process now runs a Cryptographic Algorithm Validation Program (CAVP) certification test on the Internet Key Exchange version 1 and 2 (IKEv1 and IKEv2) PRF/PRF+ functions.

Solution: 

Update package.

Additional Info: 

N/A

Download: 

SRPMS
  1. libreswan-3.12-10.1.0.1.el7.AXS7.src.rpm
    MD5: 230008f055f8b4780de8c0e20e11290c
    SHA-256: f4627096027fa49b2c1438a949ef8eb255ad51b0b617820882be151e7e828e92
    Size: 18.42 MB

Asianux Server 7 for x86_64
  1. libreswan-3.12-10.1.0.1.el7.AXS7.x86_64.rpm
    MD5: 0397b25f6a3c638abb1613d79144ad41
    SHA-256: ae5dfc10b6d5ea51461f77b8dbcdd320ba7af542fe5f2a795adb33729f3d12ff
    Size: 1.23 MB