And not just the IKE daemon and certificate stuff; also the kernel
pieces (ESP etc.). If so, is this a crazy thing to do?

I'm trying to figure out if I can construct a FIPS-approved IPsec
implementation for a government customer.

Thanks for any help.

Jim Knoke

