Elliptic Curve Digital Signature Algorithm (ECDSA)

As of LCOS 10.30, IKEv2 now supports Elliptic Curve Digital Signature Algorithm (ECDSA) as per RFC 4754 in addition to the authentication methods RSA Signature and Digital Signature.

ECDSA signatures are generally smaller than RSA signatures with comparable cryptographic strength. ECDSA keys and certificates also have significantly smaller file sizes than RSA-based keys and certificates. Furthermore, ECDSA operations are generally faster on most devices. The following methods are supported in IKEv2:

Note:

When using OpenSSL to generate certificates, the following predefined curves must be used as parameters for ECDSA in IKEv2:

Note: The following restrictions apply when using ECDSA:

In LANconfig under VPN > IKEv2/IPSec > Authentication, you can now select these methods for both Local authentication and Remote authentication.





www.lancom-systems.com

LANCOM Systems GmbH | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E-Mail info@lancom.de

LANCOM Logo