#
# When fips is enabled (fips=1 kernel parameter), only certified openssl
# and kernel crypto API (af-alg) algorithms are supported.
# The strongswan-hmac package is supposed to be used/installed when fips
# is enabled and provides this blacklist disabling other plugins
# providing further and/or alternative algorithm implementations.
gcrypt {
load = no
}
blowfish {
random {
des {
aes {
rc2 {
ctr {
cmac {
xcbc {
md4 {
md5 {
sha1 {
sha2 {
ccm {