Project

General

Profile

Actions

Bug #17089

open
JP

Warn the user that IKEv1 is deprecated and will be removed

Bug #17089: Warn the user that IKEv1 is deprecated and will be removed

Added by Jim Pingle about 12 hours ago. Updated about 11 hours ago.

Status:
New
Priority:
High
Assignee:
-
Category:
IPsec
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
26.10
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

strongSwan 6.1.0 disables IKEv1 by default and considers it deprecated, but it can still be enabled (for now) at compile time. We don't need to remove it yet, but since it will be removed upstream in less than a year, we need to give users some notice.

At this time we do not need to make any configuration changes to users tunnels, only notify the user.

  • We need to warn users somehow that IKEv1 is deprecated when it is selected on a tunnel and warn against its usage.

    We have done this for other settings before, so the same sort of mechanism can be used here as well when editing a tunnel.

  • Highlight tunnels with deprecated settings on the tunnel list as well, maybe a caution icon with a tooltip that states it's deprecated.
  • Generate a one-time notice if any IKEv1 tunnels are configured.

Related issues 1 (1 open0 closed)

Follows Bug #17088: Ensure IKEv1 is enabled when updating to strongSwan 6.1.0 or laterFeedbackChristian McDonald

Actions

JP Updated by Jim Pingle about 12 hours ago Actions #1

  • Follows Bug #17088: Ensure IKEv1 is enabled when updating to strongSwan 6.1.0 or later added

JP Updated by Jim Pingle about 12 hours ago Actions #2

  • Description updated (diff)
Actions

Also available in: Atom