]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/commitdiff
IPsec: Apple: Enable PFS on client when enabled
authorMichael Tremer <michael.tremer@ipfire.org>
Thu, 5 Mar 2020 13:48:21 +0000 (13:48 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Wed, 5 May 2021 11:27:04 +0000 (11:27 +0000)
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
html/cgi-bin/vpnmain.cgi

index 09acbdaabccd3660731714eb01be8845aafa2442..9ff5f62b08be6d04dae6b22504e8b1e4230e29ce 100644 (file)
@@ -1257,6 +1257,13 @@ END
        print "                                 <key>RemoteAddress</key>\n";
        print "                                 <string>$endpoint</string>\n";
 
+       # PFS
+       my $pfs = $confighash{$key}[28];
+       if ($pfs eq "on") {
+               print "                                 <key>EnablePFS</key>\n";
+               print "                                 <true/>\n";
+       }
+
        # Left ID
        if ($confighash{$key}[9]) {
                print "                                 <key>LocalIdentifier</key>\n";