auth-cfg: Make IKE signature schemes configurable
This also restores the charon.signature_authentication_constraints functionality, that is, if no explicit IKE signature schemes are configured we apply all regular signature constraints as IKE constraints.
This commit is contained in:
+9
-4
@@ -587,18 +587,23 @@ or a key strength definition (for example
|
||||
or
|
||||
.BR rsa-2048-ecdsa-256-sha256-sha384-sha512 ).
|
||||
Unless disabled in
|
||||
.BR strongswan.conf (5)
|
||||
such key types and hash algorithms are also applied as constraints against IKEv2
|
||||
.BR strongswan.conf (5),
|
||||
or explicit IKEv2 signature constraints are configured (see below), such key
|
||||
types and hash algorithms are also applied as constraints against IKEv2
|
||||
signature authentication schemes used by the remote side.
|
||||
|
||||
If both peers support RFC 7427 ("Signature Authentication in IKEv2") specific
|
||||
hash algorithms to be used during IKEv2 authentication may be configured.
|
||||
The syntax is the same as above. For example, with
|
||||
.B pubkey-sha384-sha256
|
||||
The syntax is the same as above, but with ike: prefix. For example, with
|
||||
.B ike:pubkey-sha384-sha256
|
||||
a public key signature scheme with either SHA-384 or SHA-256 would get used for
|
||||
authentication, in that order and depending on the hash algorithms supported by
|
||||
the peer. If no specific hash algorithms are configured, the default is to
|
||||
prefer an algorithm that matches or exceeds the strength of the signature key.
|
||||
If no constraints with ike: prefix are configured any signature scheme
|
||||
constraint (without ike: prefix) will also apply to IKEv2 authentication, unless
|
||||
this is disabled in
|
||||
.BR strongswan.conf (5).
|
||||
|
||||
For
|
||||
.BR eap ,
|
||||
|
||||
Reference in New Issue
Block a user