fae18fd201
This fixes an interoperability issue with Windows Server 2012 R2 gateways. They insist on using modp1024 for IKE, however, Microsoft's IKEv2 implementation seems only to consider the first 15 DH groups in the proposal. Depending on the loaded plugins modp1024 is now at position 17 or even later, causing the server to reject the proposal. By removing some of the weaker and rarely used DH groups from the default proposal we make sure modp1024 is among the first 15 DH groups. The removed groups may still be used by configuring custom proposals. |
||
---|---|---|
.. | ||
backend.h | ||
backend_manager.c | ||
backend_manager.h | ||
child_cfg.c | ||
child_cfg.h | ||
ike_cfg.c | ||
ike_cfg.h | ||
peer_cfg.c | ||
peer_cfg.h | ||
proposal.c | ||
proposal.h |