diff options
| author | Justin Pettit <jpettit@nicira.com> | 2010-12-01 17:23:33 -0800 |
|---|---|---|
| committer | Justin Pettit <jpettit@nicira.com> | 2010-12-28 14:30:36 -0800 |
| commit | e16a28b5854823e2d67099d49f7690235162b555 (patch) | |
| tree | 85366fe0f7c33b7bbed60f9266fec6dcb7f336d9 /lib/odp-util.c | |
| parent | 4c2fa71d662cde318940c4cd555aacd687538510 (diff) | |
| download | openvswitch-e16a28b5854823e2d67099d49f7690235162b555.tar.gz | |
vswitch: Use "ipsec_gre" vport instead of "gre" with "other_config"
Previously, a GRE-over-IPsec tunnel was created as an interface with a
"type" of "gre" and the "other_config" column with "ipsec_cert" or
"ipsec_psk" set. This could lead to a potential security problem if a user
intended to create a GRE-over-IPsec tunnel, but misconfigured the
"ipsec_*" config and created an unencrypted GRE tunnel.
This commit defines an "ipsec_gre" tunnel type, which should prevent
users from inadvertently establishing insecure tunnels.
Diffstat (limited to 'lib/odp-util.c')
| -rw-r--r-- | lib/odp-util.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/lib/odp-util.c b/lib/odp-util.c index 1f6d93e9a..29f536dae 100644 --- a/lib/odp-util.c +++ b/lib/odp-util.c @@ -222,6 +222,7 @@ void format_odp_port_type(struct ds *ds, const struct odp_port *p) { if (!strcmp(p->type, "gre") + || !strcmp(p->type, "ipsec_gre") || !strcmp(p->type, "capwap")) { const struct tnl_port_config *config; |
