<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processorsのトピックimx6ul: IPSec encryption problem for outgoing packets</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616777#M93380</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm facing different problems with IPSec aes-ctr encryption, based on different kernel.&lt;/P&gt;&lt;P&gt;Linux 4.1.15_2.0.0_ga:&lt;/P&gt;&lt;P&gt;aes-ctr out encryption seems to be wrong. All packages are dropped by the receiver. Unfortunately I'm not able to find the cause of this issue. Receiving and decryption works fine. Only outgoing packages are affected. Maybe related to this issue:&amp;nbsp;&lt;A href="https://community.nxp.com/thread/394154"&gt; Encryption of IPSEC ESP-packets coming from eth0 fails with CAAM when using AES&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linux 3.14.52_1.1.1_ga:&lt;/P&gt;&lt;P&gt;I'm getting an error on calling /etc/init.d/setkey restart. Seems to be already know key length issue of aes-ctr, as I'm getting the same response as mentioned here:&amp;nbsp;&lt;A class="" href="http://serverfault.com/questions/517861/ipsec-aes-key-length-in-kernel-3-9-3" title="http://serverfault.com/questions/517861/ipsec-aes-key-length-in-kernel-3-9-3"&gt;IPSEC AES key length in kernel 3.9.3 - Server Fault&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a different platform (not NXP) and there everything works fine. So my configuration is definitely correct. The only difference is kernel and platform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas how to fix this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Feb 2017 08:26:45 GMT</pubDate>
    <dc:creator>alampret</dc:creator>
    <dc:date>2017-02-09T08:26:45Z</dc:date>
    <item>
      <title>imx6ul: IPSec encryption problem for outgoing packets</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616777#M93380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm facing different problems with IPSec aes-ctr encryption, based on different kernel.&lt;/P&gt;&lt;P&gt;Linux 4.1.15_2.0.0_ga:&lt;/P&gt;&lt;P&gt;aes-ctr out encryption seems to be wrong. All packages are dropped by the receiver. Unfortunately I'm not able to find the cause of this issue. Receiving and decryption works fine. Only outgoing packages are affected. Maybe related to this issue:&amp;nbsp;&lt;A href="https://community.nxp.com/thread/394154"&gt; Encryption of IPSEC ESP-packets coming from eth0 fails with CAAM when using AES&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linux 3.14.52_1.1.1_ga:&lt;/P&gt;&lt;P&gt;I'm getting an error on calling /etc/init.d/setkey restart. Seems to be already know key length issue of aes-ctr, as I'm getting the same response as mentioned here:&amp;nbsp;&lt;A class="" href="http://serverfault.com/questions/517861/ipsec-aes-key-length-in-kernel-3-9-3" title="http://serverfault.com/questions/517861/ipsec-aes-key-length-in-kernel-3-9-3"&gt;IPSEC AES key length in kernel 3.9.3 - Server Fault&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a different platform (not NXP) and there everything works fine. So my configuration is definitely correct. The only difference is kernel and platform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas how to fix this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2017 08:26:45 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616777#M93380</guid>
      <dc:creator>alampret</dc:creator>
      <dc:date>2017-02-09T08:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: imx6ul: IPSec encryption problem for outgoing packets</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616778#M93381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Perhaps it makes sense to apply to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.nxp.com/kr/support/nxp-professional-services:PROFESSIONAL-SERVICE" title="http://www.nxp.com/kr/support/nxp-professional-services:PROFESSIONAL-SERVICE"&gt;NXP Professional Services|NXP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.nxp.com/products/software-and-tools/run-time-software/professional-services-software-technology:PROFESSIONAL-SERVICES-SOFTWARE" title="http://www.nxp.com/products/software-and-tools/run-time-software/professional-services-software-technology:PROFESSIONAL-SERVICES-SOFTWARE"&gt;Professional Services Software Technology|NXP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Feb 2017 06:23:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616778#M93381</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-02-28T06:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: imx6ul: IPSec encryption problem for outgoing packets</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616779#M93382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I switched to yocto kernel 4.10 and now it works fine&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jun 2017 09:39:00 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/imx6ul-IPSec-encryption-problem-for-outgoing-packets/m-p/616779#M93382</guid>
      <dc:creator>alampret</dc:creator>
      <dc:date>2017-06-11T09:39:00Z</dc:date>
    </item>
  </channel>
</rss>

