X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=secnet.git;a=blobdiff_plain;f=TODO;h=2d5e447edeb162360ff15fbeb94e1a1754d691b3;hp=e02c6279dd20ea5ae65abac430a61594d2647de7;hb=b3877445fa32f46d70057212cb38347ae1bf4955;hpb=794f2398b8fe84bf398bb10d6eeca6fe6737f65f diff --git a/TODO b/TODO index e02c627..2d5e447 100644 --- a/TODO +++ b/TODO @@ -1,14 +1,10 @@ -Makefile.in: autodep stuff -Make it work using the distributed install.sh (which doesn't support -D) - dh.c: change format to binary from decimal string (without introducing endianness problems) netlink.c: test the 'allow_route' option properly. +Add fragmentation code. Check that we comply with RFC1812. -process.c: capture output from children in sys_cmd() and log it - -random.c: test +random.c: test properly resolver.c: ought to return a list of addresses for each address; the site code ought to remember them and try contacting them in turn. @@ -16,9 +12,7 @@ site code ought to remember them and try contacting them in turn. rsa.c: check padding type, change format to binary from decimal string (without introducing endianness problems) -site.c: the site_incoming() routing could be implemented much more -cleanly using a table. There's still quite a lot of redundancy in this -file. Abandon key exchanges when a bad packet is received. Modify +site.c: Abandon key exchanges when a bad packet is received. Modify protocol to include version fields, as described in the NOTES file. Implement keepalive mode. Make policy about when to initiate key exchanges more configurable (how many NAKs / bad reverse-transforms @@ -30,4 +24,11 @@ fails in use? transform.c: separate the transforms into multiple parts, which can then be combined in the configuration file. Will allow the user to plug in different block ciphers, invent an authenticity-only mode, -etc. +etc. (similar to udptunnel) + +udp.c: option for path-MTU discovery (once fragmentation support is +implemented in netlink) + + +global: +consider using liboop for the event loop