[ovs-dev] [PATCH] netdev-vport: Don't create port when ovs-monitor-ipsec not running.

Ben Pfaff blp at nicira.com
Mon Mar 14 20:21:52 UTC 2011


On Mon, Mar 14, 2011 at 01:18:58PM -0700, Justin Pettit wrote:
> It was suggested by Jesse that it would be better to just not create
> IPsec tunnel devices if the ovs-monitor-ipsec daemon is not running.  He
> had legitimate concerns about users missing the warning message printed
> and traffic possibly going out unencrypted.
> 
> Suggested-by: Jesse Gross <jesse at nicira.com>

I'd upgrade the warning to an error, since we've decided "for sure"
that it is a bad configuration, and change the phrasing so that it's
clear that we've disabled the port entirely.  (There's no "may" about
it anymore.)



More information about the dev mailing list