From 63697214b432b9ad27fa5df1dd830ccb14a4e91f Mon Sep 17 00:00:00 2001 From: hwdsl2 Date: Wed, 18 Jan 2017 21:13:00 -0600 Subject: [PATCH] Improve VPN ciphers - Consolidate VPN ciphers for "ike=" and "phase2alg=" in ipsec.conf. --- docs/ikev2-howto-zh.md | 4 ++-- docs/ikev2-howto.md | 4 ++-- extras/vpnupgrade.sh | 12 +++++++----- extras/vpnupgrade_centos.sh | 12 +++++++----- vpnsetup.sh | 4 ++-- vpnsetup_centos.sh | 4 ++-- 6 files changed, 22 insertions(+), 18 deletions(-) diff --git a/docs/ikev2-howto-zh.md b/docs/ikev2-howto-zh.md index 2848062..c898221 100644 --- a/docs/ikev2-howto-zh.md +++ b/docs/ikev2-howto-zh.md @@ -58,8 +58,8 @@ Libreswan 支持通过使用 RSA 签名算法的 X.509 Machine Certificates 来 ikev2=insist rekey=no fragmentation=yes - ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes256-sha2_512,aes256-sha2_512;modp1024,aes256-sha2_256,aes256-sha2_256;modp1024 - phase2alg=3des-sha1,aes-sha1,aes256-sha2_512,aes256-sha2_256 + ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024 + phase2alg=3des-sha1,aes-sha1,aes-sha2 EOF ``` diff --git a/docs/ikev2-howto.md b/docs/ikev2-howto.md index 0b99e68..eba32ac 100644 --- a/docs/ikev2-howto.md +++ b/docs/ikev2-howto.md @@ -58,8 +58,8 @@ Before continuing, make sure you have successfully