X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ian/git?p=secnet.git;a=blobdiff_plain;f=TODO;h=c7d82489dffabbc343dfc13b854ddd223a43caa2;hp=b75c6335954939b12f5137aa0d8db204f1e51d15;hb=d3fe100dfc120244d316e083ce87b1eb130fe4fd;hpb=2fe58dfd10216a37f1ece081f926971882de112e diff --git a/TODO b/TODO index b75c633..c7d8248 100644 --- a/TODO +++ b/TODO @@ -1,24 +1,30 @@ -conffile.c: deal with line numbers from included conffiles correctly +dh.c: change format to binary from decimal string (without introducing +endianness problems) -dh.c: change format to binary from decimal string +netlink.c: test the 'allow_route' option properly. -netlink.c: initial implementation done, needs basic router functionality -adding. Can wait. Also support tun device. +process.c: capture output from children in sys_cmd() and log it -random.c: test +random.c: test properly -resolver.c: done +resolver.c: ought to return a list of addresses for each address; the +site code ought to remember them and try contacting them in turn. rsa.c: check padding type, change format to binary from decimal string - -secnet.c: done +(without introducing endianness problems) site.c: the site_incoming() routing could be implemented much more cleanly using a table. There's still quite a lot of redundancy in this -file. - -transform.c: done - -udp.c: done - -util.c: sort out logging +file. Abandon key exchanges when a bad packet is received. Modify +protocol to include version fields, as described in the NOTES +file. Implement keepalive mode. Make policy about when to initiate key +exchanges more configurable (how many NAKs / bad reverse-transforms +does it take to prompt a key exchange?) + +slip.c: restart userv-ipif to cope with soft routes? Restart it if it +fails in use? + +transform.c: separate the transforms into multiple parts, which can +then be combined in the configuration file. Will allow the user to +plug in different block ciphers, invent an authenticity-only mode, +etc.