|
|||||||||||
|
linux-ipsec: Pluto/IKE policy configuration?
From: Ian Calderbank <ianc(at)uk.uu.net>
Date: Wed Dec 23 1998 - 10:01:08 EST
I ran into a snag when trying to esablish isakmp via pluto to a Cisco IOS router. It would appear from watching this from the router that all the proposals that pluto makes contain 3des for the ike SA , des is not proposed. Is this correct? If so then this causes me a problem, as the router is only single-des enabled, so it refuses all the proposals. Enabling 3des on that cisco router isn't at the present time an option. I would like to persuade pluto to have the option of proposing des for ike if possible, for the purpose of tests. I am aware of the des vs 3des security arguments. >The policy for acceptable characteristics for Security Associations is hardwired into
If I'm on the right lines here - whereabouts in the code is this hardwiring? I'm a network design engineer, not a coder, so a pointer along the lines of "change this line(s) and recompile" would be appreciated. Presumably the design for such a policy database would be intended to include such things as choice of des/3des for ike, along with authentication policies such as certs vs pre-exchanged rsa key vs pre-shared secret etc? > pluto uses shared secrets to authenticate peers with whom it is negotiating. In future
Regards,
-- Ian Calderbank, ianc@uk.uu.net Network Development,UUNET UKReceived on Wed Dec 23 10:56:46 1998 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:09 EDT |
||||||||||
|
|||||||||||