Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Why pfSense doesn't support larger DH groups?

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dusan
      last edited by

      Hi,

      Since m0n0wall and now with pfSense, I've been wondering why it doesn't support larger Diffie-Hellman groups as defined by RFC 3526 (http://www.ietf.org/rfc/rfc3526.txt).

      The largest supported group is DH 5 (MODP 1536 bits), which is roughly equivalent to 96-bit symmetric key. I don't think ciphers with longer key such as 3DES, CAST, Blowfish and AES would be any useful without the larger groups.

      ipsec-tools racoon does support larger DH groups in Linux. I don't know if it does so in FreeBSD, would somebody confirm or rebut this? Thanks.

      Table 1. DH keysize and security (equivalent symmetric key size)

      DH    Security  SuitableCipher
      1024  80      Skipjack
      1536  96      –-
      2048  112      3DES
      3072  128      AES128
      4840  160      AES192
      7680  192      AES192

      1 Reply Last reply Reply Quote 0
      • S
        sullrich
        last edited by

        It is my understanding that we support everything that the freebsd kernel + racoon supports.  Feel free to supply diff's in unified format if this is not the case.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.