]> git.ipfire.org Git - thirdparty/openvpn.git/commitdiff
crypto: Do not claim we will remove support for BF-CBC in 2.7
authorFrank Lichtenheld <frank@lichtenheld.com>
Tue, 10 Feb 2026 15:20:30 +0000 (16:20 +0100)
committerGert Doering <gert@greenie.muc.de>
Tue, 10 Feb 2026 15:27:50 +0000 (16:27 +0100)
Change-Id: Ie35099b114c510e55292090c34b9d950b1f03947
Signed-off-by: Frank Lichtenheld <frank@lichtenheld.com>
Acked-by: Gert Doering <gert@greenie.muc.de>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1511
Message-Id: <20260210152035.1273-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg35565.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
src/openvpn/crypto.c

index e3d1fa58858b977b2cefa10ae42f6efdfebdf4c2..9a4269cd27036901c7d52b26ee01848dce51824b 100644 (file)
@@ -863,7 +863,7 @@ warn_insecure_key_type(const char *ciphername)
             " bit (%d bit).  This allows attacks like SWEET32.  Mitigate by "
             "using a --cipher with a larger block size (e.g. AES-256-CBC). "
             "Support for these insecure ciphers will be removed in "
-            "OpenVPN 2.7.",
+            "OpenVPN 2.8.",
             ciphername, cipher_kt_block_size(ciphername) * 8);
     }
 }