Why is GCM unavailable when using a shared key?
-
Why is GCM unavailable when using a shared key?
-
-
That is more of a question for OpenVPN than pfSense. If OpenVPN supported it, pfSense could use it.
IIRC it had something to do with the HMAC being a part of the shared key in that mode, and AEAD ciphers like AES-GCM and CHACHA20-POLY1305 want to do hashing themselves. I could be misremembering that, though.
I'm not sure what will change here but something is going to have to change in OpenVPN since 3.0 hardcodes the ciphers and only uses AES-GCM and CHACHA20-POLY1305. Maybe they find a way to make it work, or maybe they drop shared key mode.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.