[Openswan Users] Re: DES algorithm doesn't work
utkarsh shah
utkarsh at elitecore.com
Thu Mar 23 13:50:25 CET 2006
Hi,
Thanks....
will try it soon and let u know if i found something...
Regards,
Utkarsh Shah
----- Original Message -----
From: "Paul Wouters" <paul at xelerance.com>
To: "utkarsh shah" <utkarsh at elitecore.com>
Cc: <users at openswan.org>
Sent: Saturday, March 25, 2006 10:56 PM
Subject: Re: DES algorithm doesn't work
>
> On Sat, 25 Mar 2006, utkarsh shah wrote:
>
> > Subject: DES algorithm doesn't work
>
> > please guide me if i have made some mistake
>
> > when i use des algorithm as a phase1 algorithm it doesn't work
>
> > ike="3DES-MD5-modp1536!"
> > esp="3DES-MD5-1536!"
>
> Don't use "!", that is obsolete syntax. I am not sure if all the matches
> are also case insensitive, so do not use capitals.
>
> > other end
>
> > ike="3DES-MD5-modp1536"
> > esp="3DES-MD5-1536!"
>
>
> > ike="DES-MD5-modp1536!"
> > esp="3DES-MD5-1536!"
> >
> > other end
>
> > ike="DES-MD5-modp1536"
> > esp="3DES-MD5-1536!"
>
> I dont understand why you would want DES for IKE and 3DES for esp. In
fact, I
> don'tunderstand why you want DES, it is insecure. To enable 1DES you need
> to edit Makefile.inc and enable USE_WEAKSTUFF and in newer versions you
also
> need to set USE_NOCRYPTO (because 1des is as good as no crypto)
>
> Paul
>
More information about the Users
mailing list