Project

General

Profile

Actions

Feature #10221

closed

Update DH group warnings to say that group 5 is also weak

Added by Viktor Gurov almost 5 years ago. Updated over 4 years ago.

Status:
Resolved
Priority:
Normal
Category:
IPsec
Target version:
Start date:
01/29/2020
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:

Description

from https://wiki.strongswan.org/projects/strongswan/wiki/SecurityRecommendations:
It is advised to adhere to the recommendation of the appropriate security authority when choosing ciphers
to secure the tunnel cryptographically. www.keylength.com lists some of the standards for western Europe
and the US. It is strongly advised to use at least 2048 bit key length for MODP Diffie-Hellman groups.

DH group 5 = 1536 bits

Actions

Also available in: Atom PDF