Page MenuHomeVyOS Platform

openvpn: reject AEAD data-ciphers-fallback with shared-secret-key
Open, NormalPublic

Description

OpenVPN's static key mode only supports CBC ciphers.
With shared-secret-key, an AEAD encryption data-ciphers-fallback (e.g. aes256gcm) commits fine, but the daemon then fails with "Cipher 'AES-256-GCM' mode not supported" and keeps restarting.
Reject it at commit time, as is already done for encryption cipher.

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

ordex triaged this task as Normal priority.
ordex created this object in space S1 VyOS Public.