summary |
shortlog |
log |
commit | commitdiff |
review |
tree
raw |
patch |
inline | side by side (from parent 1:
cd35ed4)
Type: fix
Anouncing DH group in esp transform proposals will enable PFS which is
not suppored now. This fixes issue during rekey when using strongswan as
responder.
Change-Id: Ib9f586113ae0ab9dc67e6ceadff43f8aac463820
Signed-off-by: Filip Tehlar <ftehlar@cisco.com>
- if (is_ike || ts->dh_type != IKEV2_TRANSFORM_DH_TYPE_NONE)
{
error = 1;
vec_foreach (td, km->supported_transforms)
{
error = 1;
vec_foreach (td, km->supported_transforms)
else
if (unformat
(line_input,
else
if (unformat
(line_input,
- "set %U esp-crypto-alg %U %u esp-integ-alg %U esp-dh %U",
+ "set %U esp-crypto-alg %U %u esp-integ-alg %U",
unformat_token, valid_chars, &name,
unformat_ikev2_transform_encr_type, &crypto_alg, &tmp1,
unformat_token, valid_chars, &name,
unformat_ikev2_transform_encr_type, &crypto_alg, &tmp1,
- unformat_ikev2_transform_integ_type, &integ_alg,
- unformat_ikev2_transform_dh_type, &dh_type))
+ unformat_ikev2_transform_integ_type, &integ_alg))
{
r =
ikev2_set_profile_esp_transforms (vm, name, crypto_alg, integ_alg,
{
r =
ikev2_set_profile_esp_transforms (vm, name, crypto_alg, integ_alg,
+ IKEV2_TRANSFORM_DH_TYPE_NONE,
+ tmp1);
goto done;
}
else if (unformat
(line_input,
goto done;
}
else if (unformat
(line_input,
- "set %U esp-crypto-alg %U %u esp-dh %U",
+ "set %U esp-crypto-alg %U %u",
unformat_token, valid_chars, &name,
unformat_token, valid_chars, &name,
- unformat_ikev2_transform_encr_type, &crypto_alg, &tmp1,
- unformat_ikev2_transform_dh_type, &dh_type))
+ unformat_ikev2_transform_encr_type, &crypto_alg, &tmp1))
{
r =
ikev2_set_profile_esp_transforms (vm, name, crypto_alg, 0,
{
r =
ikev2_set_profile_esp_transforms (vm, name, crypto_alg, 0,
+ IKEV2_TRANSFORM_DH_TYPE_NONE,
+ tmp1);
goto done;
}
else if (unformat (line_input, "set %U sa-lifetime %lu %u %u %lu",
goto done;
}
else if (unformat (line_input, "set %U sa-lifetime %lu %u %u %lu",
"ikev2 profile set <id> responder <interface> <addr>\n"
"ikev2 profile set <id> ike-crypto-alg <crypto alg> <key size> ike-integ-alg <integ alg> ike-dh <dh type>\n"
"ikev2 profile set <id> esp-crypto-alg <crypto alg> <key size> "
"ikev2 profile set <id> responder <interface> <addr>\n"
"ikev2 profile set <id> ike-crypto-alg <crypto alg> <key size> ike-integ-alg <integ alg> ike-dh <dh type>\n"
"ikev2 profile set <id> esp-crypto-alg <crypto alg> <key size> "
- "[esp-integ-alg <integ alg>] esp-dh <dh type>\n"
+ "[esp-integ-alg <integ alg>]\n"
"ikev2 profile set <id> sa-lifetime <seconds> <jitter> <handover> <max bytes>",
.function = ikev2_profile_add_del_command_fn,
};
"ikev2 profile set <id> sa-lifetime <seconds> <jitter> <handover> <max bytes>",
.function = ikev2_profile_add_del_command_fn,
};