]> git.ipfire.org Git - thirdparty/openvpn.git/commitdiff
Move deprecation of SWEET32/64bit block size ciphers to 2.7
authorArne Schwabe <arne@rfc2549.org>
Mon, 13 Dec 2021 15:09:50 +0000 (16:09 +0100)
committerGert Doering <gert@greenie.muc.de>
Mon, 13 Dec 2021 19:21:48 +0000 (20:21 +0100)
We originally wanted to deprecated these ciphers (especially BF-CBC) with
2.6 but currently these ciphers are still too widespread to make this
transition for 2.6.

Acked-by: Gert Doering <gert@greenie.muc.de>
Message-Id: <20211213150950.3993881-1-arne@rfc2549.org>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg23402.html

Signed-off-by: Gert Doering <gert@greenie.muc.de>
(cherry picked from commit 7f2d7dbf986fd7233eabb250b35bf7c3112d3e37)

src/openvpn/crypto.c

index 619cd967d825db1d18df1973314917566a753bfd..6945cc0f887663fdf719d7618103ebe646734e14 100644 (file)
@@ -729,7 +729,7 @@ warn_insecure_key_type(const char *ciphername, const cipher_kt_t *cipher)
             " bit (%d bit).  This allows attacks like SWEET32.  Mitigate by "
             "using a --cipher with a larger block size (e.g. AES-256-CBC). "
             "Support for these insecure ciphers will be removed in "
-            "OpenVPN 2.6.",
+            "OpenVPN 2.7.",
             ciphername, cipher_kt_block_size(cipher)*8);
     }
 }