From: Martin Willi Date: Thu, 7 Jan 2010 15:16:22 +0000 (+0100) Subject: Added NEWS about mutual EAP-only authentication X-Git-Tag: 4.3.6~40 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=aca9f9ab5a8790f2b0656c78b08bec6c7d9abd62;p=thirdparty%2Fstrongswan.git Added NEWS about mutual EAP-only authentication --- diff --git a/NEWS b/NEWS index 64801421f7..3fcb49c2a2 100644 --- a/NEWS +++ b/NEWS @@ -35,6 +35,12 @@ strongswan-4.3.6 "charon.send_vendor_id" option in strongswan.conf to let the remote peer know this is the case. +- Experimental support for draft-eronen-ipsec-ikev2-eap-auth, where the + responder omits public key authentication in favor of a mutual authentication + method. To enable EAP-only authentication, set rightauth=eap on the responder + to rely only on the MSK constructed AUTH payload. This not-yet standardized + extension requires the strongSwan vendor ID introduced above. + - The IKEv1 daemon ignores the Juniper SRX notification type 40001, thus allowing interoperability.