VPN fails silently if peer uses 1DES

Bug #1190886 reported by Daniël van Eeden
16
This bug affects 3 people
Affects Status Importance Assigned to Milestone
network-manager-vpnc (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

I needed to connect to a Cisco VPN. I imported a pcf file, but after that the VPN failed. After testing with the vpnc commandline client it seems that the VPN concentrator is configured for 1DES and that vpnc disables that by default (which is good).

The error from vpnc
------------------------------------------------
vpnc: peer selected (single) DES as "encryption" method.
This algorithm is considered too weak today
If your vpn concentrator admin still insists on using DES
use the "--enable-1des" option
------------------------------------------------

The setting as described in the manpage.
------------------------------------------------
       --enable-1des
              enables weak single DES encryption
       conf-variable: Enable Single DES
------------------------------------------------

After setting the option to enable single DES the VPN worked.

Then I went to the network manager settings: VPN->Advanced->Encryption Method and I changed it to 'Weak'. Then it VPN worked.

What I expect if I connect to a 1DES Cisco VPN with the default settings is:
- NetworkManager detects that the encryption method doesn't match and gives an error like "Encryption method mismatch: Local=Strong Remote=Weak, Go to advanced settings to change it" (Or a warning like "Remote VPN is configured for weak encryption: Continue or Abort?")

Revision history for this message
Daniël van Eeden (dveeden) wrote :

Versions:
network-manager-vpnc 0.9.6.0-0ubuntu2
network-manager 0.9.8.0-0ubuntu6
Ubuntu 13.04

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in network-manager-vpnc (Ubuntu):
status: New → Confirmed
Revision history for this message
ariel cornejo (arielco) wrote :

Indeed, it even shows the usual "VPN connection has been successfully established" notification followed by another that says "The VPN connection 'x' failed". I can't find a relevant message in syslog.

summary: - VPN fails if remote uses DES
+ VPN fails silently if peer uses 1DES
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.