From f777614c20ed6cd6ad10bfce3191ac8b1431bd5f Mon Sep 17 00:00:00 2001 From: Luiz Otavio O Souza Date: Wed, 16 Sep 2015 08:07:37 -0500 Subject: MFC r286000: RFC4868 section 2.3 requires that the output be half... This fixes problems that was introduced in r285336... I have verified that HMAC-SHA2-256 both ah only and w/ AES-CBC interoperate w/ a NetBSD 6.1.5 vm... Reviewed by: gnn TAG: IPSEC-HEAD Issue: #4841 --- sys/netipsec/xform.h | 1 + 1 file changed, 1 insertion(+) (limited to 'sys/netipsec/xform.h') diff --git a/sys/netipsec/xform.h b/sys/netipsec/xform.h index 132717f..fee457b 100644 --- a/sys/netipsec/xform.h +++ b/sys/netipsec/xform.h @@ -105,6 +105,7 @@ struct xformsw { #ifdef _KERNEL extern void xform_register(struct xformsw*); extern int xform_init(struct secasvar *sav, int xftype); +extern int xform_ah_authsize(struct auth_hash *esph); struct cryptoini; -- cgit v1.1