ipsec: add PQ key exchange algorithms
feature
**Important notices**
Our forum is located at https://forum.opnsense.org , please consider joining discussions there instead of using GitHub for these matters.
Before you ask a new question, we ask you kindly to acknowledge the following:
- [x] I have read the contributing guidelines at https://github.com/opnsense/core/blob/master/CONTRIBUTING.md
- [x] I am convinced that my issue is new after having checked both open and closed issues at https://github.com/opnsense/core/issues?q=is%3Aissue
- [ ] AI tools were used to create at least part of the text submitted herewith.
https://docs.strongswan.org/docs/latest/config/proposals.html#_post_quantum_key_exchange_methods
For reference ML-DSA is pending: https://lists.freebsd.org/archives/freebsd-ports-bugs/2026-April/094877.html
Not sure if this is still relevant to fix or all done since 6.0.x hit:
> Support for multiple IKEv2 key exchanges (RFC 9370) has been added, which allows to use up to seven additional key exchanges (classic or post-quantum) to establish key material when negotiating IKE and/or Child SAs.
7 条评论