[strongSwan] Sudden issues with Windows 10 clients

Jafar Al-Gharaibeh jafar at atcorp.com
Tue May 15 06:38:56 CEST 2018


Tobias,

    My next question then is:

    In the case of  aesgcm algorithms where the integrity is built into 
the encryption algorithm, How does that map to prf algorithms ?  Do yo 
have to explicitly configure prf in that case? or are those mapped too? 
I didn't see such mapping in wiki pages.

Thanks,
Jaafr


On 2018-05-14 04:16, Tobias Brunner wrote:
> Hi Jafar,
> 
>>      Thanks for the correction.   What I meant to say is :
>> 
>>               The PRF algorithm is derived from the integrity 
>> algorithm,
>> but only if a DH group is also configured.
>> 
>>   Correct?
> 
> No, the DH group has nothing to do with the PRF or the integrity
> algorithm.  And for IKE proposals you always have to configure at least
> one DH group.
> 
> Regards,
> Tobias


More information about the Users mailing list