From 91b91d8cd4571c28e86fc4e7303cedecf4b07f67 Mon Sep 17 00:00:00 2001 From: Loginbug Date: Mon, 30 Mar 2020 12:31:57 +0200 Subject: [PATCH] Update vpnsetup.sh Updated libreswan version up to 3.31 Removed modp1024 from config file because it's now deprecated Tested on Debian 10 Buster --- vpnsetup.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/vpnsetup.sh b/vpnsetup.sh index 6c95f7d..52ca1cd 100755 --- a/vpnsetup.sh +++ b/vpnsetup.sh @@ -172,7 +172,7 @@ apt-get -yq install fail2ban || exiterr2 bigecho "Compiling and installing Libreswan..." -SWAN_VER=3.29 +SWAN_VER=3.31 swan_file="libreswan-$SWAN_VER.tar.gz" swan_url1="https://github.com/libreswan/libreswan/archive/v$SWAN_VER.tar.gz" swan_url2="https://download.libreswan.org/$swan_file" @@ -239,7 +239,7 @@ conn shared dpdtimeout=120 dpdaction=clear ikev2=never - ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2;modp1024,aes128-sha1;modp1024 + ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2 phase2alg=aes_gcm-null,aes128-sha1,aes256-sha1,aes256-sha2_512,aes128-sha2,aes256-sha2 sha2-truncbug=no