From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: Re: [PATCH] Mark recommended ciphers/algorithms Date: Thu, 10 Dec 2015 17:16:13 +0000 Message-ID: <1449767773.31655.108.camel@ipfire.org> In-Reply-To: <5665B543.1040304@web.de> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============8041268247792948327==" List-Id: --===============8041268247792948327== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Hello, this patch was line-wrapped and cannot be merged, but nevertheless, here are my thoughts: On Mon, 2015-12-07 at 17:35 +0100, IT Superhack wrote: > Signed-off-by: Timmothy Wilson > --- > diff --git a/html/cgi-bin/ovpnmain.cgi b/html/cgi-bin/ovpnmain.cgi > index 62af54e..15385f1 100644 > --- a/html/cgi-bin/ovpnmain.cgi > +++ b/html/cgi-bin/ovpnmain.cgi > @@ -1316,7 +1316,7 @@ END > > > > - > + > > > I agree, that it is desirable to use longer keys. However, I am not sure if it is a good idea to go all the way for 4096 bit and not only for e.g. 2048 bit. Why not 8192 even? I would like to read some justification for the values that are picked. Furthermore, I think that we the upper bound should be something that the average IPFire box is able to handle. > @@ -4687,7 +4687,7 @@ if ($cgiparams{'TYPE'} eq 'net') { > > > > - > + > > > I can agree with that since it is already selected by default. This makes it just more explicit. I would have merged this if this was an independent patch in a patch set. > @@ -4702,7 +4702,7 @@ if ($cgiparams{'TYPE'} eq 'net') { > $Lang::tr{'ovpn ha'}: > > - > + > > > Why should IKEv2 be recommended? AFAIK there are no known design issues with IKEv1. Some algorithms might not be available, but this is not an issue for now since AES, SHA2, (AKA the strong ones) are supported. > @@ -2434,7 +2434,7 @@ if(($cgiparams{'ACTION'} eq > $Lang::tr{'advanced'}) || > width="15%">$Lang::tr{'encryption'} > > multiple='multiple' size='6' > style='width: 100%'> > - > + > > > Why are the AES-GCM cipher suites with smaller IVs not recommended? > @@ -2478,7 +2478,7 @@ if(($cgiparams{'ACTION'} eq > $Lang::tr{'advanced'}) || > width="15%">$Lang::tr{'integrity'} > > multiple='multiple' size='6' > style='width: 100%'> > - > + > > > Same again. > diff --git a/langs/de/cgi-bin/de.pl b/langs/de/cgi-bin/de.pl > index 2bca854..b18cace 100644 > --- a/langs/de/cgi-bin/de.pl > +++ b/langs/de/cgi-bin/de.pl > @@ -1914,6 +1914,7 @@ > 'rebooting ipfire' => 'Starte IPFire neu', > 'reconnect' => 'Neu Verbinden', > 'reconnection' => 'Wiederverbindung', > +'recommended' => 'empfohlen', > 'red' => 'Internet', > 'red1' => 'ROT', > 'references' => 'Referenzen', > > The English translation is missing. Best, -Michael --===============8041268247792948327== Content-Type: application/pgp-signature Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="signature.asc" MIME-Version: 1.0 LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KVmVyc2lvbjogR251UEcgdjEKCmlRSWNCQUFC Q2dBR0JRSldhYk5kQUFvSkVJQjU4UDl2a0FrSG5INFAvQWc1dUtQU2ZVbU14SkNjNGZ2ZlZ0bk4K Y3NEUWw4b1JZSXEwQlZJZlNnc3NYSC9KN2ZpWmRIbXZGekxNa1c3dVlBMkZQQjY3bVJUNjk1QXNH WkV6NWREMwpzbHZpeXh3eEs2dGwwbUdrV0NGYkVoM3ZyZmFqck5ldmdkUnFxYmtjdEtWb2hac2E0 YnpUeElhZlIyR2tXcFZNCm53MkE4am1Ia3FGdjByRGEybXl1U2E1TEZHWjlSYkdvaEVJSzdGMWgy SHd1WjJTcXFCNklEVkRUUGRTYytmdmkKdjVnQ2UwR1p6YjBaSkUwcWdsd2NNbVBiZisva3VzQU9a OWpoUXJLUzVxd2tMSmNxNWNGdVRlcUhTQkxJM3hHcgpaN2h0Qk0xZHhzK3ZhekNETlVrSkppVGFN dHRHSlVSNmFKOSsxVHNFZFJ4NVJjbXBka1JSOHo1VWtxUjAvbmVVCk5KYURtZGMvNTNiWkU4OVJh c0N3Q0syd2ZvT2traUNJR2Y4dENFZUZpSWNzWmcvbEY3V2U1TVQ0b3JEQnQyMUEKN2cxeVl3cjNG emkxSUhoeHlNY0hUN2tJaTNGZEk1TVdYRi9nWG9zSGpicXBWNmNwaC82d2V4UTZVRmtPZ3RXUQpK aVpaYUQ3Yzl5Mm92TWVPRkljdmNPbi84c3JwNC9mL1gxU2JKT0lTQnd0SUdIcFlFV0RjZnpENnV2 Wnk3WTlKCkZqREtzaFZheWJlbkE5MG9EaU9UMWxxUWZ4V2p6WFAyV001YzNRYi94c0RIQXJoTWJM c1RJWk9ubFBENE1CM2gKaE9HVUI0L1FjZExkQyswWS82c1JrZktqQk5wWklPQnVtbmU2MnBzWXp2 b2NTWnRqRURFRk05RDkxeGJzMHM0eQpMRlhRQklDM3lFdjJFTjJXYkx3ago9dm9zYQotLS0tLUVO RCBQR1AgU0lHTkFUVVJFLS0tLS0K --===============8041268247792948327==--