42dcd39528
This is useful for WireGuard which uses a nonce of 8 bytes rather than the 12 bytes used for IPsec and TLS. Note that this also fixes a (should be) harmless bug in ossl(4) where the counter was incorrectly treated as a 64-bit counter instead of a 32-bit counter in terms of wrapping when using a 12 byte nonce. However, this required a single message (TLS record) longer than 64 * (2^32 - 1) bytes (about 256 GB) to trigger. Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D32122 |
||
---|---|---|
.. | ||
arch.7 | ||
ascii.7 | ||
bsd.snmpmod.mk.7 | ||
build.7 | ||
c.7 | ||
clocks.7 | ||
crypto.7 | ||
development.7 | ||
environ.7 | ||
ffs.7 | ||
firewall.7 | ||
growfs.7 | ||
hier.7 | ||
hostname.7 | ||
intro.7 | ||
maclabel.7 | ||
Makefile | ||
Makefile.depend | ||
operator.7 | ||
orders.7 | ||
ports.7 | ||
release.7 | ||
sdoc.7 | ||
security.7 | ||
sprog.7 | ||
stats.7 | ||
stdint.7 | ||
sticky.7 | ||
tests.7 | ||
tuning.7 |