===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/68.html,v
retrieving revision 1.37
retrieving revision 1.38
diff -u -r1.37 -r1.38
--- www/68.html 2020/10/04 17:14:09 1.37
+++ www/68.html 2020/10/04 19:13:46 1.38
@@ -386,6 +386,7 @@
- Fixed an iked(8) policy lookup edge case for simultaneous transport and tunnel mode SAs.
- Added AES-GCM mode ciphers for IKEv2, configurable in iked.conf(5) with the new "ikesa enc" options aes-128-gcm, aes-256-gcm, aes-128-gcm-12 and aes-256-gcm-12.
+
- Added AES-GCM ciphers to the default proposals for IKE and Child SAs resulting in considerable performance improvements with hardware acceleration support.
- Fixed iked(8) public key authentication interoperability with *swan and other IKEv2 implementations by making CERT and CERTREQ payloads optional.
- Prioritized incoming certificate requests by the order of CERTEQ payloads in the received message in iked(8).
- Added optional iked(8) time-stamp validation for OCSP.