The OpenBSD project has released OpenIKED 7.1, a portable implementation of the IKEv2 protocol for IPsec

The release of OpenIKED 7.1 has been announced, an implementation of the IKEv2 protocol developed by the OpenBSD project. Originally, IKEv2 components were an inseparable part of the OpenBSD IPsec stack, but now they have been separated into a standalone portable package that can be used on other operating systems. For instance, the operation of OpenIKED has been tested on FreeBSD, NetBSD, macOS, and various Linux distributions including Arch, Debian, Fedora, and Ubuntu. The code is written in C and distributed under the ISC license.

OpenIKED enables the deployment of virtual private networks based on IPsec. The IPsec stack is formed by two main protocols: the key exchange protocol (IKE) and the encrypted traffic transmission protocol (ESP). OpenIKED implements authentication, configuration, key exchange, and security policy maintenance elements, while the ESP protocol for encrypting traffic is typically provided by the operating systems' kernels. Authentication methods in OpenIKED can include pre-shared keys, EAP MSCHAPv2 with X.509 certificates, and RSA and ECDSA public keys.

The new version includes the command 'ikectl show certinfo' to display loaded certificates and certificate authorities, improved support for IKEv2 message fragmentation, enhanced configuration stream capabilities, added support for isolating background processes using the AppArmor mechanism in Linux, and new tests to detect regressions across different platforms.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster