From: Martin Willi Date: Mon, 16 Apr 2012 14:57:18 +0000 (+0200) Subject: Added a note about DH/keymat lifecycle for custom implementations X-Git-Tag: 4.6.3~27 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=d0d600e1ef8d2a4e5fedeb57bd5fda5650b63b48;p=thirdparty%2Fstrongswan.git Added a note about DH/keymat lifecycle for custom implementations --- diff --git a/src/libcharon/sa/keymat.h b/src/libcharon/sa/keymat.h index 11e0fa79a9..6c2b5d4b5d 100644 --- a/src/libcharon/sa/keymat.h +++ b/src/libcharon/sa/keymat.h @@ -40,7 +40,12 @@ struct keymat_t { * * The diffie hellman is either for IKE negotiation/rekeying or * CHILD_SA rekeying (using PFS). The resulting DH object must be passed - * to derive_keys or to derive_child_keys and destroyed after use + * to derive_keys or to derive_child_keys and destroyed after use. + * + * Only DH objects allocated through this method are passed to other + * keymat_t methods, allowing private DH implementations. In some cases + * (such as retrying with a COOKIE), a DH object allocated from a different + * keymat_t instance may be passed to other methods. * * @param group diffie hellman group * @return DH object, NULL if group not supported