child-cfg: Optionally use 96-bit truncation for HMAC-SHA-256
The correct truncation is 128-bit but some implementations insist on using 96-bit truncation. With strongSwan this can be negotiated using an algorithm identifier from a private range. But this doesn't work with third-party implementations. This adds an option to use 96-bit truncation even if the official identifier is used.
This commit is contained in:
@@ -307,6 +307,9 @@ enum child_cfg_option_t {
|
||||
|
||||
/** Enable hardware offload, if supported by the IPsec backend */
|
||||
OPT_HW_OFFLOAD = (1<<5),
|
||||
|
||||
/** Force 96-bit truncation for SHA-256 */
|
||||
OPT_SHA256_96 = (1<<6),
|
||||
};
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user