52cf8701e7
The Openswan and UCI configuration file formats are very similar. Implement the conversion from UCI to IPsec configuration file format in the ipsec init script and store the converted information in /etc/ipsec.uci.{conf,secrets} then reference these files from /etc/ipsec.{conf,secrets}. This scheme allows for backwards-compatibility during upgrades (since the original configuration is preserved) and allows for users to implement any exotic configurations that they require without conflicting with the configuration in UCI. Also add a nearly empty ipsec config file which enables nat_traversal. This option should be safe in all configurations and is required in many, which makes it a good default. Signed-off-by: Kevin Locke <kevin@kevinlocke.name> git-svn-id: svn://svn.openwrt.org/openwrt/packages@29585 3c298f89-4303-0410-b956-a3cf2f4a3e73
8 lines
219 B
Plaintext
8 lines
219 B
Plaintext
# /etc/ipsec.secrets - IPsec sensitive configuration file
|
|
|
|
# Include configuration information from UCI
|
|
include /etc/ipsec.uci.secrets
|
|
|
|
# Add non-UCI secrets below
|
|
# This file will be preserved across restarts/upgrades
|