[Openswan Users] encryption key

Paul Wouters paul at xelerance.com
Thu Feb 1 12:04:51 EST 2007


On Thu, 1 Feb 2007, pande rambo wrote:

> i would like to change ike and esp to use different key algorithm such as
> twofish, or serpant,
> so i add this line in the /etc/ipsec.conf
> ike="3des-sha1-96"
> esp=twofish128-sha1
>
> but when i start the ipsec service, when i check with ipsec whack --status,
> there connection said that it prosperiated erouted. what does that mean. do
> i have something wrong in my configuration?

Not all kernel supported algorithms are supported in the ipsec protocol, or
in the openswan implementation of it.

I am not sure what the status of twofish is.

Paul
-- 
Building and integrating Virtual Private Networks with Openswan:
http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155


More information about the Users mailing list