OpenVPN's static key mode only supports CBC ciphers.
With shared-secret-key, an AEAD encryption data-ciphers-fallback (e.g. aes256gcm) commits fine, but the daemon then fails with "Cipher 'AES-256-GCM' mode not supported" and keeps restarting.
Reject it at commit time, as is already done for encryption cipher.
Description
Description
Details
Details
- Version
- -
- Is it a breaking change?
- Perfectly compatible
- Issue type
- Bug (incorrect behavior)