[Openswan Users] Re: DES algorithm doesn't work

utkarsh shah utkarsh at elitecore.com
Thu Mar 23 13:50:25 CET 2006


Hi,

    Thanks....

    will try it soon and let u know if i found something...

Regards,

Utkarsh Shah

----- Original Message ----- 
From: "Paul Wouters" <paul at xelerance.com>
To: "utkarsh shah" <utkarsh at elitecore.com>
Cc: <users at openswan.org>
Sent: Saturday, March 25, 2006 10:56 PM
Subject: Re: DES algorithm doesn't work


>
> On Sat, 25 Mar 2006, utkarsh shah wrote:
>
> > Subject: DES algorithm doesn't work
>
> >     please guide me if i have made some mistake
>
> >   when i use des algorithm as a phase1 algorithm it doesn't work
>
> >           ike="3DES-MD5-modp1536!"
> >           esp="3DES-MD5-1536!"
>
> Don't use "!", that is obsolete syntax. I am not sure if all the matches
> are also case insensitive, so do not use capitals.

>
> >   other end
>
> >           ike="3DES-MD5-modp1536"
> >           esp="3DES-MD5-1536!"
>
>
> >           ike="DES-MD5-modp1536!"
> >           esp="3DES-MD5-1536!"
> >
> >   other end
>
> >           ike="DES-MD5-modp1536"
> >           esp="3DES-MD5-1536!"
>
> I dont understand why you would want DES for IKE and 3DES for esp. In
fact, I
> don'tunderstand why you want DES, it is insecure. To enable 1DES you need
> to edit Makefile.inc and enable USE_WEAKSTUFF and in newer versions you
also
> need to set USE_NOCRYPTO (because 1des is as good as no crypto)
>
> Paul
>




More information about the Users mailing list