Re: BGP: can't set sockopt TCP_MD5SIG 0 to socket 16

From: Nik <nikruzhan_at_gmail.com>
Date: Mon, 3 Apr 2006 16:27:13 +0000
If that is the case then I only need to recompile my kernel as what Thomas
said. Thanks a lot Thomas & Chuck.

# quagga needs this for MD5 passwords on BGP sessions
options         TCP_SIGNATURE
options         FAST_IPSEC
device          crypto
device          cryptodev

On 4/3/06, Chuck Swiger <cswiger_at_mac.com> wrote:
>
> Nik wrote:
> > I'm curious why I need to enable MD5 because in my system I don't use
> any
> > authentication method. [ ... ]
>
> Using the MD5 signature TCP option for BGP has become a common requirement
> since
> the RST-window vulnerability was published...
>
> --
> -Chuck
>
>
Received on Mon Apr 03 2006 - 14:27:17 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:38:54 UTC