[strongSwan] charon says "DH group MODP_1024 inacceptable, requesting MODP_1536"

Tobias Brunner tobias at strongswan.org
Tue Oct 27 14:20:41 CET 2015


Hi Harald,

> If I got you correctly I would have to move back to DH2, just to make
> the iphone users happy.

Correct, or you use a configuration profile with DiffieHellmanGroup set
to one of the other groups Apple claims to support (I don't know which
of them actually work, though): 2 (Default), 5, 14, 15, 16, 17, or 18.

> Do you know of any commitments from Apple to fix this?

No idea.  I wasn't the one adding that information to the wiki.  But you
could report the bug to Apple to get a rough idea when it is fixed.  In
this case they will close your bug report and mark it as duplicate and
you won't get any direct status updates etc. but you can see whether the
original ticket is still open or not.

Regards,
Tobias



More information about the Users mailing list