Project

General

Profile

Feature #9757

DH groups 25,26,27 not listed for phase1 & phase2

Added by Viktor Gurov about 1 month ago. Updated 25 days ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
Start date:
09/13/2019
Due date:
% Done:

100%

Estimated time:

Description

groups 25 (ecp192), 26 (ecp224) and 27 (ecp224bp) is in list of supported by strongswan:

# ipsec listalgs | grep ECP
  dh-group:   ECP_256[openssl] ECP_384[openssl] ECP_521[openssl] ECP_224[openssl] ECP_192[openssl] ECP_256_BP[openssl]
              ECP_384_BP[openssl] ECP_512_BP[openssl] ECP_224_BP[openssl] MODP_3072[openssl] MODP_4096[openssl]

but not listed in DH Group / PFS selection menu

2.5.0-DEVELOPMENT (amd64)
built on Thu Sep 12 23:59:20 EDT 2019
FreeBSD 12.0-RELEASE-p10

Associated revisions

Revision 21bee028 (diff)
Added by Jim Pingle about 1 month ago

Add IPsec DH/PFS groups 25/26/27. Implements #9757

Revision 13980a4f (diff)
Added by Jim Pingle about 1 month ago

Add IPsec DH/PFS groups 25/26/27. Implements #9757

(cherry picked from commit 21bee0287caf76bb7ab63ec29b0ecf7435940a06)

History

#1 Updated by Jim Pingle about 1 month ago

  • Tracker changed from Bug to Feature
  • Target version set to 2.5.0
  • Affected Version deleted (2.5.0)

Not a bug, but a missing feature.

#2 Updated by Jim Pingle about 1 month ago

Added them in and tried 26. Showed as working and in-use on both ends, so it looks OK, no extra plugins to enable or anything fancy needed.

Commit coming momentarily.

#3 Updated by Jim Pingle about 1 month ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

#4 Updated by Viktor Gurov 25 days ago

Jim Pingle wrote:

Applied in changeset 21bee0287caf76bb7ab63ec29b0ecf7435940a06.

it's ok now
Resolved

#5 Updated by Jim Pingle 25 days ago

  • Status changed from Feedback to Resolved

Also available in: Atom PDF