3 ms·
Apparently some Cisco products might even be using 768-bit DH as default for IPsec! From http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_ikevpn/configurat
by devit 11y ago
Apparently some Cisco products might even be using 768-bit DH as default for IPsec!
From http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_ikevpn/configuration/15-2mt/sec-key-exch-ipsec.html http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_ikevpn/...:
<<
Diffie-Hellman--A public-key cryptography protocol that allows two parties to establish a shared secret over an unsecure communications channel. Diffie-Hellman is used within IKE to establish session keys. It supports ==> 768-bit (the default) <==, 1024-bit, 1536-bit, 2048-bit, 3072-bit, and 4096-bit DH groups. It also supports a 2048-bit DH group with a 256-bit subgroup, and 256-bit and 384-bit elliptic curve DH (ECDH). Cisco recommends using 2048-bit or larger DH key exchange, or ECDH key exchange.
>>
Malice or incompetence? (or crappy hardware that needs help to not be slow?)
The recommendation is correct so...