From: Steffan Karger Date: Mon, 27 Jul 2020 11:09:24 +0000 (+0200) Subject: Gently push users towards --data-ciphers in --show-ciphers output X-Git-Tag: v2.5_beta1~28 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=0a7af784c9a1534b13092c0504df679365a48ddb;p=thirdparty%2Fopenvpn.git Gently push users towards --data-ciphers in --show-ciphers output Also: * fix a typo in the openssl output ("may be use*d*") * mention GCM before CBC (we prefer AEAD modes) Signed-off-by: Steffan Karger Acked-by: Arne Schwabe Message-Id: URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg20608.html Signed-off-by: Gert Doering --- diff --git a/src/openvpn/crypto_mbedtls.c b/src/openvpn/crypto_mbedtls.c index 19a87eb47..fbb1f120c 100644 --- a/src/openvpn/crypto_mbedtls.c +++ b/src/openvpn/crypto_mbedtls.c @@ -149,8 +149,9 @@ show_available_ciphers(void) #ifndef ENABLE_SMALL printf("The following ciphers and cipher modes are available for use\n" "with " PACKAGE_NAME ". Each cipher shown below may be used as a\n" - "parameter to the --cipher option. Using a CBC or GCM mode is\n" - "recommended. In static key mode only CBC mode is allowed.\n\n"); + "parameter to the --data-ciphers (or --cipher) option. Using a\n" + "GCM or CBC mode is recommended. In static key mode only CBC\n" + "mode is allowed.\n\n"); #endif while (*ciphers != 0) diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index c47c2f3ca..c60d4a54a 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -287,11 +287,11 @@ show_available_ciphers(void) size_t num_ciphers = 0; #ifndef ENABLE_SMALL printf("The following ciphers and cipher modes are available for use\n" - "with " PACKAGE_NAME ". Each cipher shown below may be use as a\n" - "parameter to the --cipher option. The default key size is\n" - "shown as well as whether or not it can be changed with the\n" - "--keysize directive. Using a CBC or GCM mode is recommended.\n" - "In static key mode only CBC mode is allowed.\n\n"); + "with " PACKAGE_NAME ". Each cipher shown below may be used as a\n" + "parameter to the --data-ciphers (or --cipher) option. The\n" + "default key size is shown as well as whether or not it can be\n" + "changed with the --keysize directive. Using a GCM or CBC mode\n" + "is recommended. In static key mode only CBC mode is allowed.\n\n"); #endif for (nid = 0; nid < 10000; ++nid)