id,summary,reporter,owner,description,type,status,priority,milestone,component,version,severity,resolution,keywords,cc 762,want [AEAD] notice in log,Gert Döring,Gert Döring,"This client refuses to do NCP... {{{ Nov 7 11:35:34 fbsd93 openvpn[93232]: OpenVPN 2.4_alpha2 amd64-portbld-freebsd9.3 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [IPv6] built on Nov 6 2016 Nov 7 11:35:34 fbsd93 openvpn[93232]: library versions: OpenSSL 0.9.8zh-freebsd 3 Dec 2015, LZO 2.09 }}} and unless one *knows* that this openssl version is old enough to not have the needed bits for AEAD, it's a bit tricky to debug why it ends up with {{{ Nov 7 11:35:36 fbsd93 openvpn[93233]: WARNING: INSECURE cipher with block size less than 128 bit (64 bit). This allows attacks like SWEET32. Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC). }}} feature wanted!",Feature Wish,closed,major,release 2.4,Generic / unclassified,OpenVPN 2.4_alpha2 (Community Ed),"Not set (select this one, unless your'e a OpenVPN developer)",fixed,,