HomeFreeBSD

Update comments about IVs used in IPsec ESP.

Description

Update comments about IVs used in IPsec ESP.

Add some prose and a diagram describing the layout of the cipher IV
for AES-CTR and AES-GCM and how it relates to the ESP IV stored in the
packet after the ESP header. Also, remove an XXX comment about the
initial block counter value used for AES-CTR in esp_output as the
current code matches the RFC (and the equivalent code in esp_input
didn't have the XXX comment).

Discussed with: cem

Details

Provenance
jhbAuthored on Apr 20 2020, 10:57 PM
Parents
rG29fe41ddd714: Retire the CRYPTO_F_IV_GENERATE flag.
Branches
Unknown
Tags
Unknown

Event Timeline