ipsec: allow null cipher with dpdk esp 64/22364/2
authorChristian E. Hopps <chopps@chopps.org>
Fri, 27 Sep 2019 19:19:19 +0000 (15:19 -0400)
committerNeale Ranns <nranns@cisco.com>
Mon, 30 Sep 2019 08:26:59 +0000 (08:26 +0000)
The NULL cipher is a (valid) non-AEAD choice for ESP encrypt path.
Allow it.

Type: fix
Signed-off-by: Christian E. Hopps <chopps@chopps.org>
Change-Id: I6d8b66223a0ffb0952c2dd6fa898a8a2289fef7a

src/plugins/dpdk/ipsec/esp_encrypt.c

index 4d57909..1d29841 100644 (file)
@@ -511,7 +511,8 @@ dpdk_esp_encrypt_inline (vlib_main_t * vm,
          u64 digest_paddr =
            mb0->buf_physaddr + digest - ((u8 *) mb0->buf_addr);
 
-         if (!is_aead && cipher_alg->alg == RTE_CRYPTO_CIPHER_AES_CBC)
+         if (!is_aead && (cipher_alg->alg == RTE_CRYPTO_CIPHER_AES_CBC ||
+                          cipher_alg->alg == RTE_CRYPTO_CIPHER_NULL))
            {
              cipher_off = sizeof (esp_header_t);
              cipher_len = iv_size + pad_payload_len;