1
0
mirror of https://git.dn42.dev/wiki/wiki synced 2025-03-14 19:43:32 +00:00

Updated IPsec with PublicKeys (markdown)

This commit is contained in:
Anonymous 2015-01-15 14:12:59 +00:00
parent 20235ad1b9
commit 38b4fb6602

View File

@ -1,6 +1,7 @@
# IPsec with public key authentication
## Stop using pre-shared keys!
### Pre-shared keys suck, because _reasons_
* __The key must be kept secret__, which means it must be shared only over a secure channel e.g. PGP, face-to-face
* Most implementations will accept insecure (too short, too simple) keys
* The [insecure][1] [IKE][2] [aggressive mode][3] must be used to support distinct PSKs for multiple dynamic peers, or