diff --git a/docs/ikev2-howto-zh.md b/docs/ikev2-howto-zh.md index d17f595..9f2c93a 100644 --- a/docs/ikev2-howto-zh.md +++ b/docs/ikev2-howto-zh.md @@ -55,8 +55,8 @@ Libreswan 支持通过使用 RSA 签名算法的 X.509 Machine Certificates 来 ikev2=insist rekey=no fragmentation=yes - ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024 - phase2alg=3des-sha1,aes-sha1,aes-sha2 + ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024,aes256-sha2_512 + phase2alg=3des-sha1,aes-sha1,aes-sha2,aes256-sha2_512 EOF ``` diff --git a/docs/ikev2-howto.md b/docs/ikev2-howto.md index 4e49b7a..17ca30a 100644 --- a/docs/ikev2-howto.md +++ b/docs/ikev2-howto.md @@ -55,8 +55,8 @@ Before continuing, make sure you have successfully /dev/null restorecon /usr/local/libexec/ipsec -Rv 2>/dev/null # Update ipsec.conf for Libreswan 3.19 and newer -IKE_NEW=" ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024" -PHASE2_NEW=" phase2alg=3des-sha1,aes-sha1,aes-sha2" +IKE_NEW=" ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024,aes256-sha2_512" +PHASE2_NEW=" phase2alg=3des-sha1,aes-sha1,aes-sha2,aes256-sha2_512" sed -i".old-$(date +%Y-%m-%d-%H:%M:%S)" \ -e "s/^[[:space:]]\+auth=esp\$/ phase2=esp/" \ -e "s/^[[:space:]]\+forceencaps=yes\$/ encapsulation=yes/" \ diff --git a/vpnsetup.sh b/vpnsetup.sh index e5d60cb..4265158 100755 --- a/vpnsetup.sh +++ b/vpnsetup.sh @@ -228,8 +228,8 @@ conn shared dpddelay=30 dpdtimeout=120 dpdaction=clear - ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024 - phase2alg=3des-sha1,aes-sha1,aes-sha2 + ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024,aes256-sha2_512 + phase2alg=3des-sha1,aes-sha1,aes-sha2,aes256-sha2_512 sha2-truncbug=yes conn l2tp-psk diff --git a/vpnsetup_centos.sh b/vpnsetup_centos.sh index 2e6ee3c..bf6eaad 100755 --- a/vpnsetup_centos.sh +++ b/vpnsetup_centos.sh @@ -212,8 +212,8 @@ conn shared dpddelay=30 dpdtimeout=120 dpdaction=clear - ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024 - phase2alg=3des-sha1,aes-sha1,aes-sha2 + ike=3des-sha1,3des-sha1;modp1024,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024,aes256-sha2_512 + phase2alg=3des-sha1,aes-sha1,aes-sha2,aes256-sha2_512 sha2-truncbug=yes conn l2tp-psk