[openstack-dev] [neutron] Can Neutron VPNaaS work with strongswan? (Openswan removed from Debian)

Thomas Goirand zigo at debian.org
Sun Oct 12 04:24:29 UTC 2014


Hi,

As you may know, OpenSwan has been largely unmaintained in Debian, and
then was removed from Testing, and then Sid last summer. OpenSwan had
some unaddressed security issues, and removing it from Debian was IMO
the correct thing to do. Ubuntu followed, and Utopic doesn't have
OpenSwan anymore either.

Though there's StrongSwan, which is apparently an alternative. But can
Neutron work with it? If not, how much work would it be to make Neutron
use StrongSwan instead of OpenSwan, and could the maintainers of the
VPNaaS people do this be worked on for Kilo? BTW, why not using
something as popular as OpenVPN, which has more chances to be well
maintained?

Cheers,

Thomas Goirand (zigo)



More information about the OpenStack-dev mailing list