| ▲ | Improving and Stabilizing the Racoon2 IKE Daemon in NetBSD(blog.netbsd.org) | |||||||||||||||||||||||||||||||||||||||||||
| 15 points by jaypatelani 3 days ago | 8 comments | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | yjftsjthsd-h 4 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||
I suspect I'm in a bubble, so perhaps someone might tell me what I'm missing... > racoon2 is a system to exchange and install security parameters for IPsec. It consists of an IKEv1/IKEv2 key exchange daemon, a security policy management daemon, and a Kerberos-based key exchange daemon. When would you use this over wireguard? There's a hint in > for built-in Windows, iOS and Android VPN clients. where I can see value if you want to provide a VPN without needing to install anything on the client, but that doesn't seem like a big thing to me. Or maybe legacy ipsec setups? | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | eqvinox an hour ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||
> NAT-OA payloads in IKEv1 Quick Mode (RFC 3947) > IPv6 support fixed and enabled by default Oof. Bad sign to see either of these, though for opposite reasons. Broken IPv6 points to way insufficient testing & use. IKEv1 meanwhile is deprecated and rather ought to be removed entirely. | ||||||||||||||||||||||||||||||||||||||||||||