Re: [Openvpn-devel] [PATCH v3] Allow running a default configuration with TLS libraries without BF-CBC

2021-02-16 Thread Gert Doering
Hi, On Mon, Feb 15, 2021 at 03:31:46PM +0100, Arne Schwabe wrote: > Modern TLS libraries might drop Blowfish by default or distributions > might disable Blowfish in OpenSSL/mbed TLS. We still signal OCC > options with BF-CBC compatible strings. To avoid requiring BF-CBC > for this, special this

[Openvpn-devel] [PATCH v3] Allow running a default configuration with TLS libraries without BF-CBC

2021-02-15 Thread Arne Schwabe
Modern TLS libraries might drop Blowfish by default or distributions might disable Blowfish in OpenSSL/mbed TLS. We still signal OCC options with BF-CBC compatible strings. To avoid requiring BF-CBC for this, special this one usage of BF-CBC enough to avoid a hard requirement on Blowfish in the