summaryrefslogtreecommitdiff
path: root/src/migration-scripts/ipsec
diff options
context:
space:
mode:
authorrockfish-vyos <321823801+rockfish-vyos@users.noreply.github.com>2026-09-14 08:17:41 +0000
committerrockfish-vyos <321823801+rockfish-vyos@users.noreply.github.com>2026-09-14 08:19:12 +0000
commit0db7521a96f3d314ec4914c72932cfbcced2dc98 (patch)
tree1a8e2155f9de42c54c42148f4b44d0b2070b545e /src/migration-scripts/ipsec
parent712c1520f8ebfecf3bc35d9aca21d73d7188f0c2 (diff)
downloadvyos-1x-0db7521a96f3d314ec4914c72932cfbcced2dc98.tar.gz
vyos-1x-0db7521a96f3d314ec4914c72932cfbcced2dc98.zip
ipsec: T9254: split get_esp_ike_cipher() into get_esp_cipher() / get_ike_cipher()
get_esp_ike_cipher() took an esn flag defaulting to True (ESP/CHILD_SA semantics), and every IKE_SA call site had to remember to pass esn=False. Nothing enforced that, so a future call site could reintroduce the ESN-in-IKE bug this task fixed. Following review feedback from hedrok, split it into two public filters: get_esp_cipher(group_config, ike_group=None) ESP/CHILD_SA, esn=True get_ike_cipher(group_config) IKE_SA, esn=False always The shared implementation moves to _get_esp_ike_cipher() (no register_filter), so a template can no longer call it directly and skip picking one of the two entry points. Updated call sites: peer.j2, profile.j2, remote_access.j2, l2tp.j2 (proposals -> get_ike_cipher, esp_proposals -> get_esp_cipher), and test_template.py.
Diffstat (limited to 'src/migration-scripts/ipsec')
0 files changed, 0 insertions, 0 deletions