Re: [openstack-dev] [VPNaaS] Support for Stronger hashes and combined mode ciphers

2016-06-14 Thread Mark Fenwick
Hi Paul, On 06/14/16 10:27, Paul Michali wrote: Certainly the ciphers and hashes could be enhanced for VPNaaS. This would require converting the user selections into options for the underlying device driver, modifying the neutron client (OSC) to allow entry of the new selections, updating unit

[openstack-dev] [VPNaaS] Support for Stronger hashes and combined mode ciphers

2016-06-08 Thread Mark Fenwick
Hi, I was wondering if there are any plans to extend support for IPsec and IKE algorithms. Looks like only AES-CBC mode and SHA1 are supported. It would be nice to see: SHA256, SHA384, SHA512 As well as the combined mode ciphers: AES-CCM and AES-GCM StrongSWAN already supports all of