27
2024
11
01:00:29

strongswan Diffie-Hellman

https://wiki.strongswan.org/projects/strongswan/wiki/IKEv1CipherSuites


https://docs.strongswan.org/docs/5.9/config/IKEv2CipherSuites.html


Diffie Hellman Groups

KeywordDH GroupModulusSubgroupIKEDeprecated
Regular Groups
modp7681768 bits
m o gl
modp102421024 bits
m o gl
modp153651536 bits
m o gl
modp2048142048 bits
m o g
modp3072153072 bits
m o g
modp4096164096 bits
m o g
modp6144176144 bits
m o g
modp8192188192 bits
m o g
Modulo Prime Groups with Prime Order Subgroup
modp1024s160221024 bits160 bitsm o gx
modp2048s224232048 bits224 bitsm o gx
modp2048s256242048 bits256 bitsm o gx
NIST Elliptic Curve Groups
ecp19225192 bits
ow
ecp22426224 bits
o
ecp25619256 bits
o
ecp38420384 bits
o
ecp52121521 bits
o
Brainpool Elliptic Curve Groups
ecp224bp27224 bits
o
ecp256bp28256 bits
o
ecp384bp29384 bits
o
ecp512bp30512 bits
o
Elliptic Curve 25519 - only standardized for IKEv2 but also supported for IKEv1 by strongSwan
curve25519 or x2551931256 bits
c
IKE support
c curve25519 plugin
m GMP multi-precision library (gmp plugin)
o OpenSSL crypto library (openssl plugin)
g Gcrypt crypto library (gcrypt plugin)
Deprecated
x questionable source of the primes. Potentially trapdoored (https://eprint.iacr.org/2016/961).
l broken by LogJam
w less than 112 bit security strength

Post-Quantum Key Exchange using NTRU Encryption

KeywordDH GroupStrengthIKE
ntru1121030112 bitsn
ntru1281031128 bitsn
ntru1921032192 bitsn
ntru2561033256 bitsn
IKE support
n ntru plugin (includes ntru-crypto library)

Post-Quantum Key Exchange using NewHope

KeywordDH GroupStrengthIKE
newhope1281040128 bitsn
IKE support
n newhope plugin




推荐本站淘宝优惠价购买喜欢的宝贝:

image.png

本文链接:https://www.hqyman.cn/post/8612.html 非本站原创文章欢迎转载,原创文章需保留本站地址!

分享到:
打赏





休息一下~~


« 上一篇 下一篇 »

发表评论:

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。

请先 登录 再评论,若不是会员请先 注册

您的IP地址是: