Does FreeS/WAN support single DES encryption?
No, single DES is not used either at the IKE level for negotiating connections or at the IPSEC level for actually building them. Single DES is insecure. But isn’t DES support part of the IPSEC standard? Yes, but DES is insecure. As we see it, it is more important to deliver real security than to comply with a standard which has been subverted into allowing use of inadequate methods. I have to talk to …. which offers only DES. How do I do this? Ask the device vendor for the triple DES upgrade. These exist for many IPSEC devices. If no cipher stronger than DES is available, we recommend you not use that IPSEC implementation.
No, single DES is not used either at the IKE level for negotiating connections or at the IPsec level for actually building them. Single DES is insecure. As we see it, it is more important to deliver real security than to comply with a standard which has been subverted into allowing use of inadequate methods. See this discussion . If you want to interoperate with an IPsec implementation which offers only DES, see our interoperation document.