# # CDDL HEADER START # # The contents of this file are subject to the terms of the # Common Development and Distribution License (the "License"). # You may not use this file except in compliance with the License. # # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE # or http://www.opensolaris.org/os/licensing. # See the License for the specific language governing permissions # and limitations under the License. # # When distributing Covered Code, include this CDDL HEADER in each # file and include the License file at usr/src/OPENSOLARIS.LICENSE. # If applicable, add the following below this CDDL HEADER, with the # fields enclosed by brackets "[]" replaced with your own identifying # information: Portions Copyright [yyyy] [name of copyright owner] # # CDDL HEADER END # # Copyright 2009 Sun Microsystems, Inc. All rights reserved. # Use is subject to license terms. # # cmd/cmd-inet/etc/secret/Makefile # SECRETDIR= secret PRIVATEKEYDIR= ike.privatekeys ETCPROG= ike.preshared ipseckeys.sample tcpkeys.sample include ../../../Makefile.cmd ETCINETSECRETDIR= $(ROOTETC)/inet/$(SECRETDIR) ETCINETPRIVATEKEYDIR= $(ROOTETC)/inet/$(SECRETDIR)/$(PRIVATEKEYDIR) ETCINETSECRETPROG= $(ETCPROG:%=$(ETCINETSECRETDIR)/%) # Be extra paranoid about /etc/inet/secret $(ETCINETSECRETDIR): DIRMODE= 700 $(ETCINETPRIVATEKEYDIR): DIRMODE= 700 DIRMODE= 700 FILEMODE= 600 .KEEP_STATE: all: $(ETCPROG) install: all $(ETCINETSECRETDIR) $(ETCINETPRIVATEKEYDIR) $(ETCINETSECRETPROG) $(ETCINETSECRETDIR)/% : % $(INS.file) $(ETCINETSECRETDIR): $(INS.dir) $(ETCINETPRIVATEKEYDIR): $(INS.dir) FRC: clean clobber lint: # # Copyright 2005 Sun Microsystems, Inc. All rights reserved. # Use is subject to license terms. # # CDDL HEADER START # # The contents of this file are subject to the terms of the # Common Development and Distribution License, Version 1.0 only # (the "License"). You may not use this file except in compliance # with the License. # # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE # or http://www.opensolaris.org/os/licensing. # See the License for the specific language governing permissions # and limitations under the License. # # When distributing Covered Code, include this CDDL HEADER in each # file and include the License file at usr/src/OPENSOLARIS.LICENSE. # If applicable, add the following below this CDDL HEADER, with the # fields enclosed by brackets "[]" replaced with your own identifying # information: Portions Copyright [yyyy] [name of copyright owner] # # CDDL HEADER END # # ike.preshared - Pre-shared secrets for IKE authentication. # # Entries are of the form: # # { # # ... # } # # Consult the man page for ike.preshared(5) for details. # # Copyright 2005 Sun Microsystems, Inc. All rights reserved. # Use is subject to license terms. # # CDDL HEADER START # # The contents of this file are subject to the terms of the # Common Development and Distribution License, Version 1.0 only # (the "License"). You may not use this file except in compliance # with the License. # # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE # or http://www.opensolaris.org/os/licensing. # See the License for the specific language governing permissions # and limitations under the License. # # When distributing Covered Code, include this CDDL HEADER in each # file and include the License file at usr/src/OPENSOLARIS.LICENSE. # If applicable, add the following below this CDDL HEADER, with the # fields enclosed by brackets "[]" replaced with your own identifying # information: Portions Copyright [yyyy] [name of copyright owner] # # CDDL HEADER END # # ipseckeys - This file takes the file format documented in ipseckey(8). # Note that naming services might not be available when this file # loads, just like ipsecinit.conf. # # This file should be copied into /etc/inet/secret/ipseckeys to load the # IPsec Security Association Database (SADB). A side-effect of this is that # IPsec kernel modules will load. # tcpkeys - This file takes the file format documented in tcpkey(8). # Note that naming services might not be available when this file # loads, just like ipsecinit.conf. # # This file should be copied into /etc/inet/secret/tcpkeys and modified, and # the svc:/network/tcpkey:default service enabled in order for the keys to be # loaded into the TCP Security Association Database at boot. # add src 192.168.1.1 dst 192.168.1.2 dport 179 authalg md5 authstring s3kr1t # add src 192.168.1.2 dst 192.168.1.1 sport 179 authalg md5 authstring s3kr1t