https://wiki.strongswan.org/projects/strongswan/wiki/IKEv1CipherSuites
https://docs.strongswan.org/docs/5.9/config/IKEv2CipherSuites.html
Diffie Hellman Groups
Keyword | DH Group | Modulus | Subgroup | IKE | Deprecated |
---|---|---|---|---|---|
Regular Groups | |||||
modp768 | 1 | 768 bits | m o g | l | |
modp1024 | 2 | 1024 bits | m o g | l | |
modp1536 | 5 | 1536 bits | m o g | l | |
modp2048 | 14 | 2048 bits | m o g | ||
modp3072 | 15 | 3072 bits | m o g | ||
modp4096 | 16 | 4096 bits | m o g | ||
modp6144 | 17 | 6144 bits | m o g | ||
modp8192 | 18 | 8192 bits | m o g | ||
Modulo Prime Groups with Prime Order Subgroup | |||||
modp1024s160 | 22 | 1024 bits | 160 bits | m o g | x |
modp2048s224 | 23 | 2048 bits | 224 bits | m o g | x |
modp2048s256 | 24 | 2048 bits | 256 bits | m o g | x |
NIST Elliptic Curve Groups | |||||
ecp192 | 25 | 192 bits | o | w | |
ecp224 | 26 | 224 bits | o | ||
ecp256 | 19 | 256 bits | o | ||
ecp384 | 20 | 384 bits | o | ||
ecp521 | 21 | 521 bits | o | ||
Brainpool Elliptic Curve Groups | |||||
ecp224bp | 27 | 224 bits | o | ||
ecp256bp | 28 | 256 bits | o | ||
ecp384bp | 29 | 384 bits | o | ||
ecp512bp | 30 | 512 bits | o | ||
Elliptic Curve 25519 - only standardized for IKEv2 but also supported for IKEv1 by strongSwan | |||||
curve25519 or x25519 | 31 | 256 bits | c | ||
IKE support | |||||
c curve25519 plugin m GMP multi-precision library (gmp plugin) o OpenSSL crypto library (openssl plugin) g Gcrypt crypto library (gcrypt plugin) | |||||
Deprecated | |||||
x questionable source of the primes. Potentially trapdoored (https://eprint.iacr.org/2016/961). l broken by LogJam w less than 112 bit security strength |
Post-Quantum Key Exchange using NTRU Encryption
Keyword | DH Group | Strength | IKE |
ntru112 | 1030 | 112 bits | n |
ntru128 | 1031 | 128 bits | n |
ntru192 | 1032 | 192 bits | n |
ntru256 | 1033 | 256 bits | n |
IKE support | |||
n ntru plugin (includes ntru-crypto library) |
Post-Quantum Key Exchange using NewHope
Keyword | DH Group | Strength | IKE |
---|---|---|---|
newhope128 | 1040 | 128 bits | n |
IKE support | |||
n newhope plugin |
推荐本站淘宝优惠价购买喜欢的宝贝:
本文链接:https://www.hqyman.cn/post/8612.html 非本站原创文章欢迎转载,原创文章需保留本站地址!
休息一下~~