Novell-SUSE Sponsors Openswan
hsjones writes "Concerned about the demise of FreeS/WAN? Well, looks like Openswan is going to be a good, strong open source IPsec project going forward. Novell and SUSE have jumped in with Astaro to back the project and move it along. See the press release. The Openswan project is at http://www.openswan.org. SUSE Linux and Astaro Security Linux both use FreeS/WAN in their current releases. It will be very interesting to watch what they do now with Openswan!"
Stop looking at me Swan!
Distributed proteome folding @ WorldCommunityGrid.org
Team Slashdot - Members:#1 Run Time:#1 Points:#1 Results:#1
is bleeding, oh please reply with a cure i think it's a vein!
rel?
Building on its contributions to the open source community and commitment to interoperability
As one of many people who vividly remembers the success of NetWare 3.x, the current situation seems very alien. Novell virtually died when the fact of the matter is their product was by far the best. Today they have good products, yet they really can't claim an enormous technological edge. Their second coming is, instead, based on commitment to a thriving community, and feeds off anti-Microsoft sentiment. If best-of-breed products didn't work, will this perhaps be the strategy that finally works for them? I don't know, but I certainly wouldn't complain to see Novell take back a sizeable bite of the business that was stolen from them.
Yeah, I understand how SuSE & Novell become involved in this, but can someone explain what this does? I mean, what's the hoopla about?
Error 407 - No creative sig found
This message brought to you by the National Association for Humane Action for Dogs and the Euthenasia for Canus Familourous Association. Gadgets For The Elimination Of Dogs is announcing a BRAND NEW product designed to exterminate canine pests of all sizes. Our economical K9Zap product retails for just $49.95 and takes only 2 seconds for a 60 lb dog. Our $5 bakers chocolate will kill up to 500 lbs of dog per package!
/. to join our club. If you have MOD POINTS and would like to support the ECFA, moderate this post UP.
Gadgets For The Elimination Of Dogs is a division of ECFA (Euthenasia for Canus Familourous Association). The GFTEOD/ECFA would like you to do one thing - KILL A DOG. By KILLING A DOG, you will ELIMINATE one USELESSLY RESPIRATING animal from this planet. Are you TIRED of having your TAXES increased? Humane Societies cost our country over $100 million annually. By eliminating DOGS, this money can EDUCATE OUR KIDS. OVERPOPULATION of DOGS is RAPANT in this country. Take a stand! Help rid this INFESTATION. KILL A DOG TODAY!!!!
Have you ever stepped in DOG DOO-DOO
Are you MAD?
Do you KILL DOGS?
Are you a MAD DOG KILLER?
If you answered "YES" to any of the above questions the ECFA (Euthenasia for Canus Familourous Association) is for you! Why change your sexual lifestyle or change your skin color to join an EVIL ORGANIZATION when you can simply INCREASE OUR SUPPLY OF O2! Did you know that DOGS turn BENEFICIAL O2 into CO2 simply to gain their energy to bark, drool, and howl? They ACTUALLY BOND their carbon TO OUR OXYGEN SUPPLY!!! One dog can waste 2 moles of O2 PER HOUR! This country has MANY UNWANTED, ABANDONED DOGS that WE ARE PAYING MONEY TO KEEP ALIVE. We are FEEDING them our food supply while making the homeless STARVE! By using a Dog Killing Gadget, a dog can be turned into beneficial food, helping us all. We let children go hungry yet feed our **UNWANTED** dogs like royalty.
Do you own a dog? Are you tired of its mess? Then get it euthanized. Euthanasia is a painless way for a dog to... terminate. However, it can be too expensive to buy these drugs for the LARGE NUMBER of DOGS in the HUMANE SOCIETIES. It is thus proposed that these dogs be turned into food for the homeless.
WANT TO SUPPORT THE ECFA? Simply form picket lines around your nearest humane society or gain a FIRST POST on
==This post brought to you by proud dog killer PickaBu on EFNET.
The Mark of The Beast.. will it require wireless technology everywhere for this to emerge? Chips in the body = cashless transactions. It's only a matter of time. Hell, there's news stories about people in a club somewhere waving their hands with microchips embedded in them to order drinks.
buttsex makes the baby jesus cry.
Open anus
SUSE is now one of the premier players on the linux scene now, with Novell's help of course. SUSE was my first disro and I am very happy it has found succes. I just hope it does not go the way of redhat and not try to make their distro the best one out there and rely on the name alone, also like metallica but that is for another time.
Fin
Even since FreeS/WAN gave up on changing the world to Opportunistic Encryption (not my favorite idea, but I suppose if I feel too strongly I can write my own damn implementation :) ), I've been looking into alternatives, and obviously OpenS/WAN is the first choice. A frustration I had when looking into it was that I couldn't find any documentation describing the differences between the two projects. I didn't do any diffs on the documentations, but from a brief perusal it looks pretty much like the FreeS/WAN docs. Does anyone out there have a list of specific differences between the projects - other than the included patches for things like x.509 NAT traversal, etc that are also included in Super FreeS/WAN (I'm kind of assuming that there are more changes)?
Help save the critically endangered Blue Iguana
What does FreeSWAN do that OpenVPN does not ?
I have never tried SWAN because OpenVPN is so easy.
Are there any compelling reasons to try it ??
Care you explain that comment without resorting to your catch phrases, cliches, and slogans? You pathetic liberals, you are like little sheep (yes I can tell you are a liberal). Sad little man.
Rooting Corpse
I don't get it. Why don't use isakmpd for key management?
It easy to set up, and works just fine on my gentoo box.
Openswan is a good example of a patent hurting an Open Source app. I *need* LZS compression for my company's VPN, but Openswan won't work cuz of IPCP LZS compression. I was offered an internal version of super-freeswan with the LZS code but refuse to use it cuz it's not Free. i'm stupid that way
If thou see a fair woman pay court to her, for thus thou wilt obtain love
Concerned about the demise of FreeS/WAN?
I can think of about 49,309 things I'm more concerned about.
Check out the competition.
Best. Troll. Ever.
This story sux.
Until they fix the braindead configuration, fuck *SWAN.
Now what I've had to use Linux more, I'm used to spending a couple of hours figuring out how some bullshit works, I probably have the skills to suss it out.
What is it about concise, detailed and _useful_ manpages that the Linux community couldn't give a toss over?
There has been a working and tested IPSec implementation from Kame Project in the vanilla Linux kernel for some time now. Why go with a competing and conflicting IPSec implementation that was once formed because the official Linus tree lacked the support. Diversity is a richness etc. on but in this case I feel like these efforts seem fruitless. But big companies such as Novell don't do things because they just can so maybe there's something I don't quite get. I'd love to be englightened, though.
Novell got complacent, made some dumb moves (eg, buying WordPerfect) and hit some real competition when Microsoft started muscling in on their traditional turf. Whilst the competition was coming right at it, Novell just looked on, doe-eyed.
A littany of bad management decisions is why they are where they are today. Maybe Novell can regain some of its lost market share but you'll have to wait a very long time if you want to see it regain market dominance.
"Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
http://whatsnewkohza.ytmnd.com
I'm so very pleased by this news. My biggest concern from Novell's acquistion of SuSE and Ximian was whether or not they would continue to support Free Software. With other major Linux vendors (well, vendor) seemingly moving more and more toward closing their software, and locking users into their products, it's refreshing to see Novell opening more software up and supporting community projects.
We've seen it now with their support of OpenSWAN, the open-sourcing of YaST and iFolder, and the continuing free releases of SuSE 9.1.
As I said, I'm very pleased to see this, and I suspect we'll see even more support of the open source and free software community from the reborn phoenix that is Novell.
"Adventure? Excitement? A Jedi craves not these things."
The following comment will likely be labelled as -1: Troll, but I have to say it:
Stop using the asinine phrase "going forward". It reeks of stupid managerial dialect and, for me anyway, cheapens whatever point you're trying to make.
You have the Rawanda virus. (just touching your skin causes the cell walls to rupture; thus bleed).
There is no cure, so please don't infect anyone: die with honor, that you hath first lost your family's jewels before you lost your living soul.
But the real performance killer on lots of networks was all the chatty SAP announcements - even on a medium-sized network, all the printers advertising themselves can clog up any useful bandwidth, which often meant 56kbps back when this sort of networking was common for users like banks, retail stores, and branch offices of big companies. Yes, we learned how to do SAP filtering, and eventually Novell came out with NLSP which helped a lot.
The more important problems were pricing - upgrading to Netware 5 which could use TCP/IP instead of IPX tended to cost too much for the types of companies that were big Netware users back in mumblety-95, so they stayed with IPX way past its prime, around the time that Microsoft was figuring out how to make NetBIOS-over-IP perform badly over long distances (as opposed to NetBIOS-over-NETBEUI.) While Microsoft _still_ doesn't have a clue about decent networking, they were good enough to beat Netware in the market, and small networks of either Netware or NetBEUI could both be self-configuring, a lesson we're trying to relearn for IPv6.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
A BSD bo8 that Also dead, its
be treated by your and some of the Percent Of the *BSD the goodwill erosion of user a8d shouting that [gay-sex-access.com]?
___
internet, productivity blog
The real difference is that IPSEC is encrypting at the IP layer of the protocol stack, aka Layer 3 in OSI terms, while OpenVPN is creating a TCP Layer 4 tunnel. Inside the tunnel, IPSEC normally puts Layer 3 IP packets, while OpenVPN does something with a TUN/TAP driver on the ends, so they could be doing Layer 3 IP packets or Layer 2 Ethernet packets, and I haven't read the docs enough to know which they did. Layer 4 has more overhead, but has a potentially easier time going through NAT.
For both of these applications, you have to create an association between two endpoints, and then tell your endpoints' packet handlers to use that association when they want to get packets somewhere. The choice of protocol layers for the inside and outside of the crypto tunnel has a major impact on how you get the routing mechanisms (or whatever) to decide to set up a tunnel and send packets through it.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
It sounds more like an ugly duckling.
If my call is important, why am I talking to a recording?
When is SLES 9 coming out?
OpenVPN (http://openvpn.sf.net/) is an excellent alternative to IPSec. It's using UDP or TCP as transport layer and doesn't care about NAT. You can have NAT on the both sides. The client and server share the same code and can be used on WIN32 or GNU/Linux (and more). The version 2.0 can handle routing per X.509 certificate... and much more.
Novell-Suse-... should sponsor this excellent project instead of the brain damaged(tm) IPSec.
a Cisco solution?
More widely tested and secure.
OpenVPN by default uses udp port 5000, but if you want to, you can configure it to use any other port, and tcp rather than udp. But as you wrote, tcp over tcp can bring trouble
KAME also has problems with netfilter; specifically it doesn't work with all NAT rules, which are VERY common on ipsec gateways. It also doesn't work at the interface level, so many of the advanced routing tools don't work like you'd expect (try using tc with it, on an inteface level...).
I don't know why 2.6 and the Linux ipsec-tools project standardized on KAME. It may be from BSD, but we already have better userland tools, and they already (mostly) work with the new 2.6 ipsec intefaces. Hopefully these tools will get better with time, but right now pluto/openswan are simply more mature, stable and just plain better.
The wheel is turning, but the hamster is dead.
Strongswan has been mucho more active since Freeswan dead. Also has more features. Why not to go for Strongswan instead of Freeswan?
Omar
YHBT
YHL
HAND.
1) I wonder why they didn't sponsor the original FreeSWAN project in the first place? Why did FreeSWAN have to die bacause of lack of funding? Now THE FreeSWANs source is used by the OpenSWAN project, and they get sponsoring. Can anyone explain?
2) Is opportunistic encryption still a priority for the FreeSWAN project as it was for OpenSWAN? I didn't see any mention of it on their starting page.