Re: [Swan-dev] Certificate based authentication failures with libreswan

2024-01-08 Thread Andrew Cagney
On Mon, 8 Jan 2024 at 15:56, Paul Wouters wrote: > > This likely depends on the crypto policies set. > And yes 1024 is probably no longer allowed. > > You can try: update-crypto-policies —set LEGACY Yes. Between 4.6 and 4.7, and as part of the digital signature work, some of the crypto code was

Re: [Swan-dev] Certificate based authentication failures with libreswan

2024-01-08 Thread Paul Wouters
This likely depends on the crypto policies set. And yes 1024 is probably no longer allowed. You can try: update-crypto-policies —set LEGACY but better to generate new stronger keys. Paul Sent using a virtual keyboard on a phone > On Jan 8, 2024, at 12:38, Praveen Chavan wrote: > >  > Hi,

[Swan-dev] Minimum RSA key, was Fwd: Auto-discard notification

2024-01-08 Thread Paul Wouters
Sent using a virtual keyboard on a phoneBegin forwarded message:From: swan-dev-boun...@lists.libreswan.orgDate: January 8, 2024 at 12:38:45 ESTTo: swan-dev-ow...@lists.libreswan.orgSubject: Auto-discard notificationThe attached message has been automatically discarded.--- Begin Message --- Hi, I