Re: IPsec: remove DES support

2015-12-08 Thread Mike Belopuhov
On 2 December 2015 at 23:36, Christian Weisgerber wrote: > Quoth ipsec.conf(5): > Use of DES as an encryption algorithm is considered to be insecure since > brute force attacks are practical due its short key length. > > The attached patch removes support for DES-CBC encryption in ESP > an

IPsec: remove DES support

2015-12-02 Thread Christian Weisgerber
Quoth ipsec.conf(5): Use of DES as an encryption algorithm is considered to be insecure since brute force attacks are practical due its short key length. The attached patch removes support for DES-CBC encryption in ESP and in IKE main and quick mode from the kernel, iked(8), ipsecctl(8), a