[strongSwan] Does StrongSwan Support DH Group24 (a 2048-bit MODP group defined in [RFC5114])

Andreas Steffen andreas.steffen at strongswan.org
Thu Dec 16 05:08:57 CET 2010


Hello Michalle,

have a look at our wik page:

http://wiki.strongswan.org/projects/strongswan/wiki/IKEv2CipherSuites

which defines the algorithms from RFC 5114 as

Modulo Prime Groups with Prime Order Subgroup¶
Keyword       DH Group 	Modulus    Subgroup
modp1024s160  22        1024 bits  160 bits
modp2048s224  23        2048 bits  224 bits
modp2048s256  24        2048 bits  256 bits

Regards

Andreas

On 12/16/2010 03:41 AM, michalle OY wrote:
> 
>  Hi, all
> Does StrongSwan Support DH Group24 (a 2048-bit MODP group defined in
> [RFC5114]).
> If yes, how to configure IPsec.conf file to make it happen?
>  
> Thanks
> Michalle
> 

======================================================================
Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==




More information about the Users mailing list