Add UCI support to Openswan
authorjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Tue, 20 Dec 2011 04:36:42 +0000 (04:36 +0000)
committerjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Tue, 20 Dec 2011 04:36:42 +0000 (04:36 +0000)
commit52cf8701e712143e94ee3d483214cc3959b65a3f
treefaf45bd915c8a513d68eabcf8015639db70a60b1
parent6d1726c72dca369dcc598d562c77efc684a59e2c
Add UCI support to Openswan

The Openswan and UCI configuration file formats are very similar.
Implement the conversion from UCI to IPsec configuration file format in
the ipsec init script and store the converted information in
/etc/ipsec.uci.{conf,secrets} then reference these files from
/etc/ipsec.{conf,secrets}.  This scheme allows for
backwards-compatibility during upgrades (since the original
configuration is preserved) and allows for users to implement any exotic
configurations that they require without conflicting with the
configuration in UCI.

Also add a nearly empty ipsec config file which enables nat_traversal.
This option should be safe in all configurations and is required in
many, which makes it a good default.

Signed-off-by: Kevin Locke <kevin@kevinlocke.name>
git-svn-id: svn://svn.openwrt.org/openwrt/packages@29585 3c298f89-4303-0410-b956-a3cf2f4a3e73
net/openswan/Makefile
net/openswan/files/ipsec.conf [new file with mode: 0644]
net/openswan/files/ipsec.config [new file with mode: 0644]
net/openswan/files/ipsec.init
net/openswan/files/ipsec.secrets [new file with mode: 0644]