[strongSwan-dev] why DH group NEWHOPE_128 inacceptable ?

Noel Kuntze noel at familie-kuntze.de
Fri Oct 21 14:52:31 CEST 2016

On 21.10.2016 13:58, Trump DD wrote:
> 02[CFG] selected proposal: ESP:AES_GCM_16_256/NO_EXT_SEQ

That's normal. With a certain IKE version (don't remember which),
the DH-Group only is important when rekeying, because the initial setup of
a CHILD_SA doesn't include a DH exchange, it is only done when rekeying


