diff options
author | Jeff Leung <jleung@v10networks.ca> | 2015-12-04 23:49:35 -0500 |
---|---|---|
committer | Jeff Leung <jleung@v10networks.ca> | 2015-12-05 02:23:02 -0500 |
commit | e35a282eef077d8cc91e8e5fd7b7a1dcf91750c4 (patch) | |
tree | 9c5cc628f890e0f6e67e91a8309cb350ca6a2a85 /templates/vpn/ipsec | |
parent | f179c69fcfd84d4889aec93bf87fdb265106f29e (diff) | |
download | vyatta-cfg-vpn-e35a282eef077d8cc91e8e5fd7b7a1dcf91750c4.tar.gz vyatta-cfg-vpn-e35a282eef077d8cc91e8e5fd7b7a1dcf91750c4.zip |
Add ChaCha20 Poly1305 cipher as an available cipher for IKE exchanges.
Starting with strongSwan 5.3.3, chacha20poly1305 is a supported cipher for
IKE and ESP configurations with an IKEv2 configuration.
Diffstat (limited to 'templates/vpn/ipsec')
-rw-r--r-- | templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def | 3 | ||||
-rw-r--r-- | templates/vpn/ipsec/ike-group/node.tag/proposal/node.tag/encryption/node.def | 3 |
2 files changed, 4 insertions, 2 deletions
diff --git a/templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def b/templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def index 1c02803..05aa407 100644 --- a/templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def +++ b/templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def @@ -1,7 +1,8 @@ help: Encryption algorithm type: txt default: "aes128" -syntax:expression: $VAR(@) in "aes128", "aes256", "3des"; "must be aes128, or aes256, or 3des" +syntax:expression: $VAR(@) in "aes128", "aes256", "3des", "chacha20poly1305"; "must be aes128, aes256, 3des, or chacha20poly1305" val_help: aes128; AES-128 encryption (default) val_help: aes256; AES-256 encryption val_help: 3des; 3DES encryption +val_help: chacha20poly1305; ChaCha20-Poly1305 encryption diff --git a/templates/vpn/ipsec/ike-group/node.tag/proposal/node.tag/encryption/node.def b/templates/vpn/ipsec/ike-group/node.tag/proposal/node.tag/encryption/node.def index 1c02803..05aa407 100644 --- a/templates/vpn/ipsec/ike-group/node.tag/proposal/node.tag/encryption/node.def +++ b/templates/vpn/ipsec/ike-group/node.tag/proposal/node.tag/encryption/node.def @@ -1,7 +1,8 @@ help: Encryption algorithm type: txt default: "aes128" -syntax:expression: $VAR(@) in "aes128", "aes256", "3des"; "must be aes128, or aes256, or 3des" +syntax:expression: $VAR(@) in "aes128", "aes256", "3des", "chacha20poly1305"; "must be aes128, aes256, 3des, or chacha20poly1305" val_help: aes128; AES-128 encryption (default) val_help: aes256; AES-256 encryption val_help: 3des; 3DES encryption +val_help: chacha20poly1305; ChaCha20-Poly1305 encryption |