From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: Re: [PATCH] OpenVPN: mark CBC ciphers as weak in WebUI Date: Mon, 10 Jun 2019 20:12:54 +0100 Message-ID: <1833CC6E-915A-4C04-AA0A-2F7AF12B147A@ipfire.org> In-Reply-To: <8edaf74e-2912-1d32-9c23-234e1eadf1d2@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============3050080329632758122==" List-Id: --===============3050080329632758122== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi, > On 10 Jun 2019, at 20:08, Peter M=C3=BCller wr= ote: >=20 > Hello Michael, >=20 > thanks for your comments. >=20 >> Hi, >>=20 >> I think I can ACK this although we definitely should change the default. I= have raised that a couple of times before. > Yes. This is true for IPsec as well... Patch is in my pipeline=E2=80=A6 Okay. Can we try to make a patchset out of things like this in the future? That keeps things together and we can coordinate better when we merge this. We have closed the last Core Update technically last week. Now we have some b= ig changes here and I would prefer to not break the update but have it rather= shipped as soon as possible. >>=20 >> I also do not like having a very long list of ciphers that are weak. There= are not too many left which are =E2=80=9Cstrong=E2=80=9D. But yeah, what can= you do? > As far as I am concerned, there is little "strong" cryptography left indeed. > It's basically only TLS >=3D 1.2 with AEAD (e.g. GCM) ciphers and Forward S= ecrecy. >=20 > Speaking about RFC 8446, this is more or less what survived discussions bef= ore > standardizing TLS 1.3 ... :-) Yeah I picked up on that too, but we have to make sure that we ensure compati= bility. OpenVPN is hard to update. People cannot migrate from a cipher to another one= and not all versions support GCM. -Michael >>=20 >> I will wait for Erik to ack this, too. >>=20 >> -Michael > Thanks, and best regards, > Peter M=C3=BCller > --=20 > The road to Hades is easy to travel. > -- Bion of Borysthenes --===============3050080329632758122==--