[strongSwan] charon support for DES_MAC?

François Ouellet fouell at gmail.com
Wed Oct 19 22:18:29 CEST 2011


Thank you for your quick response.

> as you can see from our IKEv2 algorithm overview, strongSwan does
> not support the DES_MAC integrity algorithm:
>
> http://wiki.strongswan.org/projects/strongswan/wiki/IKEv2CipherSuites
>
> Why would you want to use such a weak algorithm anyway?

It's the only thing the WR44 supports.  It has configurable
encryption/authentication/prf/modp group algorithms but the integrity
algorithm is fixed (hardware limitation?).

Would it be possible to add support for the DES_MAC integrity
algorithm?  Or is it so weak as to be utterly useless?

If it is so bad that you don't want to add it, maybe you could just
update the link above to explicitely say so.  I haven't found a single
place talking of this algorithm (except a log of a pluto session from
last year that seemed to accept the proposal, so I thought it could be
available to charon also).

Thank you very much,

François




More information about the Users mailing list