[Openswan Users] DH group 7

Paul Wouters paul at xelerance.com
Thu Jan 26 04:32:20 CET 2006


On Wed, 25 Jan 2006, Marco Berizzi wrote:

> One of our customers has asked me to configure an ipsec tunnel.
> He proposed me the following DH group: 1,2,5 and 7. After a
> short googling I have found that DH group 7 specifies to use
> Elliptic Curve Cryptography (ECC). Will openswan support this
> DH group? Is it stronger than DH group 14, 15, 16, 17, 18?

It is currently not supported or planned. The use of ECC is more that
it is different then the standard factoring that is in use of the
other ciphers, so if someone tackles the factoring problem, then ECC
should be more resilent to that.

It's not that we do not want to support it. It is a matter of resources.

Paul


More information about the Users mailing list