From 941c5adfaca2c7e3318b2ba0e7f36c37acaa53c1 Mon Sep 17 00:00:00 2001 From: Daniil Baturin Date: Mon, 9 Oct 2023 17:30:12 +0100 Subject: openvpn: T5634: Remove support for insecure DES and Blowfish ciphers --- data/templates/openvpn/server.conf.j2 | 9 +-------- 1 file changed, 1 insertion(+), 8 deletions(-) (limited to 'data') diff --git a/data/templates/openvpn/server.conf.j2 b/data/templates/openvpn/server.conf.j2 index 2eb9416fe..746155c37 100644 --- a/data/templates/openvpn/server.conf.j2 +++ b/data/templates/openvpn/server.conf.j2 @@ -205,19 +205,12 @@ tls-server {% if encryption is vyos_defined %} {% if encryption.cipher is vyos_defined %} cipher {{ encryption.cipher | openvpn_cipher }} -{% if encryption.cipher is vyos_defined('bf128') %} -keysize 128 -{% elif encryption.cipher is vyos_defined('bf256') %} -keysize 256 -{% endif %} {% endif %} {% if encryption.ncp_ciphers is vyos_defined %} data-ciphers {{ encryption.ncp_ciphers | openvpn_ncp_ciphers }} {% endif %} {% endif %} -# https://vyos.dev/T5027 -# Required to support BF-CBC (default ciphername when none given) -providers legacy default +providers default {% if hash is vyos_defined %} auth {{ hash }} -- cgit v1.2.3