[Openvpn-devel,v1] crypto: Do not claim we will remove support for BF-CBC in 2.7

Message ID 20260210152035.1273-1-gert@greenie.muc.de
State New
Headers show
Series [Openvpn-devel,v1] crypto: Do not claim we will remove support for BF-CBC in 2.7 | expand

Commit Message

Gert Doering Feb. 10, 2026, 3:20 p.m. UTC
From: Frank Lichtenheld <frank@lichtenheld.com>

Change-Id: Ie35099b114c510e55292090c34b9d950b1f03947
Signed-off-by: Frank Lichtenheld <frank@lichtenheld.com>
Acked-by: Gert Doering <gert@greenie.muc.de>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1511
---

This change was reviewed on Gerrit and approved by at least one
developer. I request to merge it to master.

Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1511
This mail reflects revision 1 of this Change.

Acked-by according to Gerrit (reflected above):
Gert Doering <gert@greenie.muc.de>

Comments

Gert Doering Feb. 10, 2026, 3:28 p.m. UTC | #1
Arguably we didn't... so this makes sense, and it makes sense to have it
in 2.7.0.  The change is 1 digit in a string, so the risk of introducing
breakage is very low.

Your patch has been applied to the master branch.

commit f6004dc45e686fd2f0d9b5f9ffd342dfa85543f9
Author: Frank Lichtenheld
Date:   Tue Feb 10 16:20:30 2026 +0100

     crypto: Do not claim we will remove support for BF-CBC in 2.7

     Signed-off-by: Frank Lichtenheld <frank@lichtenheld.com>
     Acked-by: Gert Doering <gert@greenie.muc.de>
     Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1511
     Message-Id: <20260210152035.1273-1-gert@greenie.muc.de>
     URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg35565.html
     Signed-off-by: Gert Doering <gert@greenie.muc.de>


--
kind regards,

Gert Doering

Patch

diff --git a/src/openvpn/crypto.c b/src/openvpn/crypto.c
index e3d1fa5..9a4269c 100644
--- a/src/openvpn/crypto.c
+++ b/src/openvpn/crypto.c
@@ -863,7 +863,7 @@ 
             " bit (%d bit).  This allows attacks like SWEET32.  Mitigate by "
             "using a --cipher with a larger block size (e.g. AES-256-CBC). "
             "Support for these insecure ciphers will be removed in "
-            "OpenVPN 2.7.",
+            "OpenVPN 2.8.",
             ciphername, cipher_kt_block_size(ciphername) * 8);
     }
 }