ike.config(4) needs additional oakley_group numbers
While setting up a new IPsec tunnel, I noticed that the documented oakley_group numbers in ike.config(4) are not the only ones supported. We appear to support some or all of the additional numbers from RFC 5114, section 3.2 (I used 21). The man page should be enhanced to list the additional group numbers that we support.
Updated by Dan McDonald almost 7 years ago
The ikedoor.h file has the values we support: http://src.illumos.org/source/xref/illumos-gate/usr/src/lib/libipsecutil/common/ikedoor.h. Look for IKE_GRP_DESC_*.
Updated by Electric Monk almost 7 years ago
- Status changed from Feedback to Closed
commit 808449d51f6ccd25ce8ca4ff2e7cb4302ad9b574 Author: Eric Sproul <email@example.com> Date: 2015-04-07T16:15:51.000Z 5782 ike.config(4) needs additional oakley_group numbers Reviewed by: Dan McDonald <firstname.lastname@example.org> Reviewed by: Bayard Bell <email@example.com> Approved by: Robert Mustacchi <firstname.lastname@example.org>