Public bug reported: Actually it is a kernel bug, but since it affects (only) setkey users, posting here.
The following ipsec-tools.conf: #!/usr/sbin/setkey -f flush; add 1.1.1.1 1.1.1.2 esp 1000 -E aes-ctr 0x11111111111111111111111111111111111111111111111111111111111111111111111; .....results is error: line 3: Not supported at [0x11111111111111111111111111111111111111111111111111111111111111111111111] parse failed, line 3. Any key length I try results in the same error message. With 3.2 kernel it worked well. ipsec-tools version: 0.8.0 ** Affects: ipsec-tools (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ipsec-tools in Ubuntu. https://bugs.launchpad.net/bugs/1199358 Title: 3.9.3 kernel supports none AES-CTR key lengths To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ipsec-tools/+bug/1199358/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs