|
|||||||||||
|
Re: linux-ipsec: Pluto/IKE policy configuration?
From: Henry Spencer <henry(at)spsystems.net>
Date: Wed Dec 23 1998 - 11:42:15 EST
At the moment, this is correct. Users really need to have more control over such policy matters, and that is on our to-do list, although it may be a little while before it gets addressed. DHR might possibly be able to suggest a way to fudge it for testing. We are reluctant to provide a default configuration with single-DES enabled, especially for something as crucial as key exchange, since single-DES no longer offers meaningful security. (If your competition is seriously interested in eavesdropping on you, they can and will build a DES-cracker machine -- see doc/des.) > >...Eventually this will be moved into a security policy database with
It's in pluto/spdb.c, but detailed instructions for fudging it should come from DHR rather than me -- I don't remember the details well enough to confidently give precise instructions. > ...Presumably the design for such a policy database would be
Yes, that's the general intention... although do note that when it comes to choice of encryption algorithm, single-DES is such a poor choice that we've had repeated discussions of whether it belongs in our code at all. So far it's still there as an ESP transform, mostly because it is officially mandatory, and we will support it for IKE at such time as IKE becomes properly configurable, for the same reason. However... if IETF ever downgrades DES support to optional (presumably after blessing a stronger replacement), it would not surprise me if we decided to stop shipping it. Our project management feels strongly about giving users real security, not just a crumbly plastic imitation. > I read some discussion of rsa-sig being considered as a next stage - if
Great!
Henry Spencer
henry@spsystems.net
(henry@zoo.toronto.edu)
Received on Wed Dec 23 12:13:21 1998This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:29 EDT |
||||||||||
|
|||||||||||