[strongSwan] AH Transport AES-128 GMAC

Gyula Kovács gyula.kovacs.kkb.tech at gmail.com
Mon Nov 7 09:47:52 CET 2016


Hi Tobias,

Thank you for the idea, but I'm using version 5.5.1 (see below).
-------------------------------------------------------
root at atm:~# ipsec version
Linux strongSwan U5.5.1/K3.16.0-4-586
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil, Switzerland
See 'ipsec --copyright' for copyright information.
root at atm:~#
-------------------------------------------------------
I compiled it on Debian 8.6 VM, after using the following configuration 
options:
./configure --prefix=/usr --sysconfdir=/etc --enable-openssl 
--enable-gmp --enable-charon --enable-stroke --enable-curl 
--enable-sqlite --enable-agent --enable-gcm

Best regards,
Gyula



On 2016.11.07. 09:35, Tobias Brunner wrote:
> Hi Gyula,
>
>> Anybody have an idea what could be wrong?
> That's due to a recently fixed bug that mapped the aes*gmac keywords
> incorrectly for AH proposals.  You may either update to 5.5.1, which
> includes the fix, or try to apply the patch at [1] (won't apply cleanly
> to any older version as it is based on other changes).
>
> Regards,
> Tobias
>
> [1] https://git.strongswan.org/?p=strongswan.git;a=commitdiff;h=a65a282f
>
>

-- 
Gyula Kovács
KKB-Tech
+36 30 257 9319

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20161107/81d5b99b/attachment.html>


More information about the Users mailing list