@@ -183,17 +183,6 @@ configured in a compatible way between both the local and remote side.
``--tls-auth`` and ``--secret`` options. Useful when using inline files
(See section on inline files).
---keysize n
- **DEPRECATED** This option will be removed in OpenVPN 2.6.
-
- Size of cipher key in bits (optional). If unspecified, defaults to
- cipher-specific default. The ``--show-ciphers`` option (see below) shows
- all available OpenSSL ciphers, their default key sizes, and whether the
- key size can be changed. Use care in changing a cipher's default key
- size. Many ciphers have not been extensively cryptanalyzed with
- non-standard key lengths, and a larger key may offer no real guarantee
- of greater security, or may even reduce security.
-
--data-ciphers cipher-list
Restrict the allowed ciphers to be negotiated to the ciphers in
``cipher-list``. ``cipher-list`` is a colon-separated list of ciphers,
@@ -1626,12 +1626,9 @@ get_random(void)
void
print_cipher(const cipher_kt_t *cipher)
{
- const char *var_key_size = cipher_kt_var_key_size(cipher) ?
- " by default" : "";
-
- printf("%s (%d bit key%s, ",
+ printf("%s (%d bit key, ",
cipher_kt_name(cipher),
- cipher_kt_key_size(cipher) * 8, var_key_size);
+ cipher_kt_key_size(cipher) * 8);
if (cipher_kt_block_size(cipher) == 1)
{
@@ -149,10 +149,4 @@ mbed_log_func_line_lite(unsigned int flags, int errval,
#define mbed_ok(errval) \
mbed_log_func_line_lite(D_CRYPT_ERRORS, errval, __func__, __LINE__)
-static inline bool
-cipher_kt_var_key_size(const cipher_kt_t *cipher)
-{
- return cipher->flags & MBEDTLS_CIPHER_VARIABLE_KEY_LEN;
-}
-
#endif /* CRYPTO_MBEDTLS_H_ */
@@ -114,12 +114,6 @@ void crypto_print_openssl_errors(const unsigned int flags);
msg((flags), __VA_ARGS__); \
} while (false)
-static inline bool
-cipher_kt_var_key_size(const cipher_kt_t *cipher)
-{
- return EVP_CIPHER_flags(cipher) & EVP_CIPH_VARIABLE_LENGTH;
-}
-
/**
* Load a key file from an engine
*
Remove --keysize from the manual page and also remove mentioning variable key size in output of ciphers as there is no longer a way to change the keysize. Signed-off-by: Arne Schwabe <arne@rfc2549.org> --- doc/man-sections/protocol-options.rst | 11 ----------- src/openvpn/crypto.c | 7 ++----- src/openvpn/crypto_mbedtls.h | 6 ------ src/openvpn/crypto_openssl.h | 6 ------ 4 files changed, 2 insertions(+), 28 deletions(-)