summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--regress/sbin/ipsecctl/ike1.ok4
-rw-r--r--regress/sbin/ipsecctl/ike10.ok4
-rw-r--r--regress/sbin/ipsecctl/ike11.ok8
-rw-r--r--regress/sbin/ipsecctl/ike12.ok12
-rw-r--r--regress/sbin/ipsecctl/ike13.ok12
-rw-r--r--regress/sbin/ipsecctl/ike14.ok36
-rw-r--r--regress/sbin/ipsecctl/ike15.ok4
-rw-r--r--regress/sbin/ipsecctl/ike17.ok8
-rw-r--r--regress/sbin/ipsecctl/ike18.ok8
-rw-r--r--regress/sbin/ipsecctl/ike19.ok4
-rw-r--r--regress/sbin/ipsecctl/ike2.ok4
-rw-r--r--regress/sbin/ipsecctl/ike20.ok8
-rw-r--r--regress/sbin/ipsecctl/ike21.ok4
-rw-r--r--regress/sbin/ipsecctl/ike22.ok4
-rw-r--r--regress/sbin/ipsecctl/ike23.ok4
-rw-r--r--regress/sbin/ipsecctl/ike29.ok4
-rw-r--r--regress/sbin/ipsecctl/ike3.ok4
-rw-r--r--regress/sbin/ipsecctl/ike30.ok4
-rw-r--r--regress/sbin/ipsecctl/ike31.ok4
-rw-r--r--regress/sbin/ipsecctl/ike32.ok4
-rw-r--r--regress/sbin/ipsecctl/ike33.ok4
-rw-r--r--regress/sbin/ipsecctl/ike34.ok4
-rw-r--r--regress/sbin/ipsecctl/ike35.ok4
-rw-r--r--regress/sbin/ipsecctl/ike36.ok4
-rw-r--r--regress/sbin/ipsecctl/ike37.ok4
-rw-r--r--regress/sbin/ipsecctl/ike39.ok8
-rw-r--r--regress/sbin/ipsecctl/ike4.ok4
-rw-r--r--regress/sbin/ipsecctl/ike40.ok8
-rw-r--r--regress/sbin/ipsecctl/ike41.ok4
-rw-r--r--regress/sbin/ipsecctl/ike42.ok4
-rw-r--r--regress/sbin/ipsecctl/ike43.ok4
-rw-r--r--regress/sbin/ipsecctl/ike46.ok8
-rw-r--r--regress/sbin/ipsecctl/ike6.ok8
-rw-r--r--regress/sbin/ipsecctl/ike7.ok8
-rw-r--r--regress/sbin/ipsecctl/ike8.ok4
-rw-r--r--regress/sbin/ipsecctl/ike9.ok4
36 files changed, 114 insertions, 114 deletions
diff --git a/regress/sbin/ipsecctl/ike1.ok b/regress/sbin/ipsecctl/ike1.ok
index b6e3e1f937b..d0477799084 100644
--- a/regress/sbin/ipsecctl/ike1.ok
+++ b/regress/sbin/ipsecctl/ike1.ok
@@ -3,14 +3,14 @@ C set [peer-131.188.33.29]:Phase=1 force
C set [peer-131.188.33.29]:Address=131.188.33.29 force
C set [peer-131.188.33.29]:Configuration=mm-131.188.33.29 force
C set [mm-131.188.33.29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-131.188.33.51-131.188.33.29]:Phase=2 force
C set [IPsec-131.188.33.51-131.188.33.29]:ISAKMP-peer=peer-131.188.33.29 force
C set [IPsec-131.188.33.51-131.188.33.29]:Configuration=qm-131.188.33.51-131.188.33.29 force
C set [IPsec-131.188.33.51-131.188.33.29]:Local-ID=lid-131.188.33.51 force
C set [IPsec-131.188.33.51-131.188.33.29]:Remote-ID=rid-131.188.33.29 force
C set [qm-131.188.33.51-131.188.33.29]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-131.188.33.51-131.188.33.29]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-131.188.33.51-131.188.33.29]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-131.188.33.51]:ID-type=IPV4_ADDR force
C set [lid-131.188.33.51]:Address=131.188.33.51 force
C set [rid-131.188.33.29]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike10.ok b/regress/sbin/ipsecctl/ike10.ok
index a5489fcb0d2..6e0f43e75df 100644
--- a/regress/sbin/ipsecctl/ike10.ok
+++ b/regress/sbin/ipsecctl/ike10.ok
@@ -3,14 +3,14 @@ C set [peer-192.168.200.1]:Phase=1 force
C set [peer-192.168.200.1]:Address=192.168.200.1 force
C set [peer-192.168.200.1]:Configuration=mm-192.168.200.1 force
C set [mm-192.168.200.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-192.168.200.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-192.168.200.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-192.168.100.1-192.168.200.1]:Phase=2 force
C set [IPsec-192.168.100.1-192.168.200.1]:ISAKMP-peer=peer-192.168.200.1 force
C set [IPsec-192.168.100.1-192.168.200.1]:Configuration=qm-192.168.100.1-192.168.200.1 force
C set [IPsec-192.168.100.1-192.168.200.1]:Local-ID=lid-192.168.100.1 force
C set [IPsec-192.168.100.1-192.168.200.1]:Remote-ID=rid-192.168.200.1 force
C set [qm-192.168.100.1-192.168.200.1]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-192.168.100.1-192.168.200.1]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-192.168.100.1-192.168.200.1]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-192.168.100.1]:ID-type=IPV4_ADDR force
C set [lid-192.168.100.1]:Address=192.168.100.1 force
C set [rid-192.168.200.1]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike11.ok b/regress/sbin/ipsecctl/ike11.ok
index 960af35a974..efb364da6c9 100644
--- a/regress/sbin/ipsecctl/ike11.ok
+++ b/regress/sbin/ipsecctl/ike11.ok
@@ -4,14 +4,14 @@ C set [peer-192.168.3.1]:Address=192.168.3.1 force
C set [peer-192.168.3.1]:Local-address=192.168.3.2 force
C set [peer-192.168.3.1]:Configuration=mm-192.168.3.1 force
C set [mm-192.168.3.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-192.168.3.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-192.168.3.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Phase=2 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:ISAKMP-peer=peer-192.168.3.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Configuration=qm-1.1.1.1-0.0.0.0/0 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Remote-ID=rid-0.0.0.0/0 force
C set [qm-1.1.1.1-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
@@ -24,14 +24,14 @@ C set [peer-192.168.3.1]:Address=192.168.3.1 force
C set [peer-192.168.3.1]:Local-address=192.168.3.2 force
C set [peer-192.168.3.1]:Configuration=mm-192.168.3.1 force
C set [mm-192.168.3.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-192.168.3.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-192.168.3.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Phase=2 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:ISAKMP-peer=peer-192.168.3.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Configuration=qm-1.1.1.1-0.0.0.0/0 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Remote-ID=rid-0.0.0.0/0 force
C set [qm-1.1.1.1-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
diff --git a/regress/sbin/ipsecctl/ike12.ok b/regress/sbin/ipsecctl/ike12.ok
index bf10271002e..2d582593515 100644
--- a/regress/sbin/ipsecctl/ike12.ok
+++ b/regress/sbin/ipsecctl/ike12.ok
@@ -4,14 +4,14 @@ C set [peer-5.5.5.5]:Phase=1 force
C set [peer-5.5.5.5]:Address=5.5.5.5 force
C set [peer-5.5.5.5]:Configuration=mm-5.5.5.5 force
C set [mm-5.5.5.5]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-5.5.5.5]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-5.5.5.5]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.0/24]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.0/24]:ISAKMP-peer=peer-5.5.5.5 force
C set [IPsec-1.1.1.1-2.2.2.0/24]:Configuration=qm-1.1.1.1-2.2.2.0/24 force
C set [IPsec-1.1.1.1-2.2.2.0/24]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.0/24]:Remote-ID=rid-2.2.2.0/24 force
C set [qm-1.1.1.1-2.2.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
@@ -23,14 +23,14 @@ C set [peer-5.5.5.5]:Phase=1 force
C set [peer-5.5.5.5]:Address=5.5.5.5 force
C set [peer-5.5.5.5]:Configuration=mm-5.5.5.5 force
C set [mm-5.5.5.5]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-5.5.5.5]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-5.5.5.5]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-3.3.3.0/24]:Phase=2 force
C set [IPsec-1.1.1.1-3.3.3.0/24]:ISAKMP-peer=peer-5.5.5.5 force
C set [IPsec-1.1.1.1-3.3.3.0/24]:Configuration=qm-1.1.1.1-3.3.3.0/24 force
C set [IPsec-1.1.1.1-3.3.3.0/24]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-3.3.3.0/24]:Remote-ID=rid-3.3.3.0/24 force
C set [qm-1.1.1.1-3.3.3.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-3.3.3.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-3.3.3.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force
@@ -42,14 +42,14 @@ C set [peer-5.5.5.5]:Phase=1 force
C set [peer-5.5.5.5]:Address=5.5.5.5 force
C set [peer-5.5.5.5]:Configuration=mm-5.5.5.5 force
C set [mm-5.5.5.5]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-5.5.5.5]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-5.5.5.5]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-4.4.4.0/24]:Phase=2 force
C set [IPsec-1.1.1.1-4.4.4.0/24]:ISAKMP-peer=peer-5.5.5.5 force
C set [IPsec-1.1.1.1-4.4.4.0/24]:Configuration=qm-1.1.1.1-4.4.4.0/24 force
C set [IPsec-1.1.1.1-4.4.4.0/24]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-4.4.4.0/24]:Remote-ID=rid-4.4.4.0/24 force
C set [qm-1.1.1.1-4.4.4.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-4.4.4.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-4.4.4.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-4.4.4.0/24]:ID-type=IPV4_ADDR_SUBNET force
diff --git a/regress/sbin/ipsecctl/ike13.ok b/regress/sbin/ipsecctl/ike13.ok
index 94f00d1693b..309be6371ca 100644
--- a/regress/sbin/ipsecctl/ike13.ok
+++ b/regress/sbin/ipsecctl/ike13.ok
@@ -4,14 +4,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-2.2.2.0/24-1.1.1.1]:Phase=2 force
C set [IPsec-2.2.2.0/24-1.1.1.1]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-2.2.2.0/24-1.1.1.1]:Configuration=qm-2.2.2.0/24-1.1.1.1 force
C set [IPsec-2.2.2.0/24-1.1.1.1]:Local-ID=lid-2.2.2.0/24 force
C set [IPsec-2.2.2.0/24-1.1.1.1]:Remote-ID=rid-1.1.1.1 force
C set [qm-2.2.2.0/24-1.1.1.1]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-2.2.2.0/24-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-2.2.2.0/24-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-2.2.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-2.2.2.0/24]:Network=2.2.2.0 force
C set [lid-2.2.2.0/24]:Netmask=255.255.255.0 force
@@ -23,14 +23,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3.3.3.0/24-1.1.1.1]:Phase=2 force
C set [IPsec-3.3.3.0/24-1.1.1.1]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-3.3.3.0/24-1.1.1.1]:Configuration=qm-3.3.3.0/24-1.1.1.1 force
C set [IPsec-3.3.3.0/24-1.1.1.1]:Local-ID=lid-3.3.3.0/24 force
C set [IPsec-3.3.3.0/24-1.1.1.1]:Remote-ID=rid-1.1.1.1 force
C set [qm-3.3.3.0/24-1.1.1.1]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3.3.3.0/24-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3.3.3.0/24-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-3.3.3.0/24]:Network=3.3.3.0 force
C set [lid-3.3.3.0/24]:Netmask=255.255.255.0 force
@@ -42,14 +42,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-4.4.4.0/24-1.1.1.1]:Phase=2 force
C set [IPsec-4.4.4.0/24-1.1.1.1]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-4.4.4.0/24-1.1.1.1]:Configuration=qm-4.4.4.0/24-1.1.1.1 force
C set [IPsec-4.4.4.0/24-1.1.1.1]:Local-ID=lid-4.4.4.0/24 force
C set [IPsec-4.4.4.0/24-1.1.1.1]:Remote-ID=rid-1.1.1.1 force
C set [qm-4.4.4.0/24-1.1.1.1]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-4.4.4.0/24-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-4.4.4.0/24-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-4.4.4.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-4.4.4.0/24]:Network=4.4.4.0 force
C set [lid-4.4.4.0/24]:Netmask=255.255.255.0 force
diff --git a/regress/sbin/ipsecctl/ike14.ok b/regress/sbin/ipsecctl/ike14.ok
index f62f4841952..6e95f4da0b6 100644
--- a/regress/sbin/ipsecctl/ike14.ok
+++ b/regress/sbin/ipsecctl/ike14.ok
@@ -5,14 +5,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-2.2.2.0/24-5.5.5.0/24]:Phase=2 force
C set [IPsec-2.2.2.0/24-5.5.5.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-2.2.2.0/24-5.5.5.0/24]:Configuration=qm-2.2.2.0/24-5.5.5.0/24 force
C set [IPsec-2.2.2.0/24-5.5.5.0/24]:Local-ID=lid-2.2.2.0/24 force
C set [IPsec-2.2.2.0/24-5.5.5.0/24]:Remote-ID=rid-5.5.5.0/24 force
C set [qm-2.2.2.0/24-5.5.5.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-2.2.2.0/24-5.5.5.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-2.2.2.0/24-5.5.5.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-2.2.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-2.2.2.0/24]:Network=2.2.2.0 force
C set [lid-2.2.2.0/24]:Netmask=255.255.255.0 force
@@ -25,14 +25,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-2.2.2.0/24-6.6.6.0/24]:Phase=2 force
C set [IPsec-2.2.2.0/24-6.6.6.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-2.2.2.0/24-6.6.6.0/24]:Configuration=qm-2.2.2.0/24-6.6.6.0/24 force
C set [IPsec-2.2.2.0/24-6.6.6.0/24]:Local-ID=lid-2.2.2.0/24 force
C set [IPsec-2.2.2.0/24-6.6.6.0/24]:Remote-ID=rid-6.6.6.0/24 force
C set [qm-2.2.2.0/24-6.6.6.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-2.2.2.0/24-6.6.6.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-2.2.2.0/24-6.6.6.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-2.2.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-2.2.2.0/24]:Network=2.2.2.0 force
C set [lid-2.2.2.0/24]:Netmask=255.255.255.0 force
@@ -45,14 +45,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-2.2.2.0/24-7.7.7.0/24]:Phase=2 force
C set [IPsec-2.2.2.0/24-7.7.7.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-2.2.2.0/24-7.7.7.0/24]:Configuration=qm-2.2.2.0/24-7.7.7.0/24 force
C set [IPsec-2.2.2.0/24-7.7.7.0/24]:Local-ID=lid-2.2.2.0/24 force
C set [IPsec-2.2.2.0/24-7.7.7.0/24]:Remote-ID=rid-7.7.7.0/24 force
C set [qm-2.2.2.0/24-7.7.7.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-2.2.2.0/24-7.7.7.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-2.2.2.0/24-7.7.7.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-2.2.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-2.2.2.0/24]:Network=2.2.2.0 force
C set [lid-2.2.2.0/24]:Netmask=255.255.255.0 force
@@ -65,14 +65,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3.3.3.0/24-5.5.5.0/24]:Phase=2 force
C set [IPsec-3.3.3.0/24-5.5.5.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-3.3.3.0/24-5.5.5.0/24]:Configuration=qm-3.3.3.0/24-5.5.5.0/24 force
C set [IPsec-3.3.3.0/24-5.5.5.0/24]:Local-ID=lid-3.3.3.0/24 force
C set [IPsec-3.3.3.0/24-5.5.5.0/24]:Remote-ID=rid-5.5.5.0/24 force
C set [qm-3.3.3.0/24-5.5.5.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3.3.3.0/24-5.5.5.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3.3.3.0/24-5.5.5.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-3.3.3.0/24]:Network=3.3.3.0 force
C set [lid-3.3.3.0/24]:Netmask=255.255.255.0 force
@@ -85,14 +85,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3.3.3.0/24-6.6.6.0/24]:Phase=2 force
C set [IPsec-3.3.3.0/24-6.6.6.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-3.3.3.0/24-6.6.6.0/24]:Configuration=qm-3.3.3.0/24-6.6.6.0/24 force
C set [IPsec-3.3.3.0/24-6.6.6.0/24]:Local-ID=lid-3.3.3.0/24 force
C set [IPsec-3.3.3.0/24-6.6.6.0/24]:Remote-ID=rid-6.6.6.0/24 force
C set [qm-3.3.3.0/24-6.6.6.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3.3.3.0/24-6.6.6.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3.3.3.0/24-6.6.6.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-3.3.3.0/24]:Network=3.3.3.0 force
C set [lid-3.3.3.0/24]:Netmask=255.255.255.0 force
@@ -105,14 +105,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3.3.3.0/24-7.7.7.0/24]:Phase=2 force
C set [IPsec-3.3.3.0/24-7.7.7.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-3.3.3.0/24-7.7.7.0/24]:Configuration=qm-3.3.3.0/24-7.7.7.0/24 force
C set [IPsec-3.3.3.0/24-7.7.7.0/24]:Local-ID=lid-3.3.3.0/24 force
C set [IPsec-3.3.3.0/24-7.7.7.0/24]:Remote-ID=rid-7.7.7.0/24 force
C set [qm-3.3.3.0/24-7.7.7.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3.3.3.0/24-7.7.7.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3.3.3.0/24-7.7.7.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-3.3.3.0/24]:Network=3.3.3.0 force
C set [lid-3.3.3.0/24]:Netmask=255.255.255.0 force
@@ -125,14 +125,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-4.4.4.0/24-5.5.5.0/24]:Phase=2 force
C set [IPsec-4.4.4.0/24-5.5.5.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-4.4.4.0/24-5.5.5.0/24]:Configuration=qm-4.4.4.0/24-5.5.5.0/24 force
C set [IPsec-4.4.4.0/24-5.5.5.0/24]:Local-ID=lid-4.4.4.0/24 force
C set [IPsec-4.4.4.0/24-5.5.5.0/24]:Remote-ID=rid-5.5.5.0/24 force
C set [qm-4.4.4.0/24-5.5.5.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-4.4.4.0/24-5.5.5.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-4.4.4.0/24-5.5.5.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-4.4.4.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-4.4.4.0/24]:Network=4.4.4.0 force
C set [lid-4.4.4.0/24]:Netmask=255.255.255.0 force
@@ -145,14 +145,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-4.4.4.0/24-6.6.6.0/24]:Phase=2 force
C set [IPsec-4.4.4.0/24-6.6.6.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-4.4.4.0/24-6.6.6.0/24]:Configuration=qm-4.4.4.0/24-6.6.6.0/24 force
C set [IPsec-4.4.4.0/24-6.6.6.0/24]:Local-ID=lid-4.4.4.0/24 force
C set [IPsec-4.4.4.0/24-6.6.6.0/24]:Remote-ID=rid-6.6.6.0/24 force
C set [qm-4.4.4.0/24-6.6.6.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-4.4.4.0/24-6.6.6.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-4.4.4.0/24-6.6.6.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-4.4.4.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-4.4.4.0/24]:Network=4.4.4.0 force
C set [lid-4.4.4.0/24]:Netmask=255.255.255.0 force
@@ -165,14 +165,14 @@ C set [peer-1.1.1.1]:Phase=1 force
C set [peer-1.1.1.1]:Address=1.1.1.1 force
C set [peer-1.1.1.1]:Configuration=mm-1.1.1.1 force
C set [mm-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.1.1.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-4.4.4.0/24-7.7.7.0/24]:Phase=2 force
C set [IPsec-4.4.4.0/24-7.7.7.0/24]:ISAKMP-peer=peer-1.1.1.1 force
C set [IPsec-4.4.4.0/24-7.7.7.0/24]:Configuration=qm-4.4.4.0/24-7.7.7.0/24 force
C set [IPsec-4.4.4.0/24-7.7.7.0/24]:Local-ID=lid-4.4.4.0/24 force
C set [IPsec-4.4.4.0/24-7.7.7.0/24]:Remote-ID=rid-7.7.7.0/24 force
C set [qm-4.4.4.0/24-7.7.7.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-4.4.4.0/24-7.7.7.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-4.4.4.0/24-7.7.7.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-4.4.4.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-4.4.4.0/24]:Network=4.4.4.0 force
C set [lid-4.4.4.0/24]:Netmask=255.255.255.0 force
diff --git a/regress/sbin/ipsecctl/ike15.ok b/regress/sbin/ipsecctl/ike15.ok
index 28d95040cd3..778ea1f594b 100644
--- a/regress/sbin/ipsecctl/ike15.ok
+++ b/regress/sbin/ipsecctl/ike15.ok
@@ -3,7 +3,7 @@ C set [peer-3ffe::1]:Phase=1 force
C set [peer-3ffe::1]:Address=3ffe::1 force
C set [peer-3ffe::1]:Configuration=mm-3ffe::1 force
C set [mm-3ffe::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::1]:Transforms=AES-SHA-RSA_SIG force
C set [peer-3ffe::1]:ID=sharleena.as10.net-ID force
C set [sharleena.as10.net-ID]:ID-type=FQDN force
C set [sharleena.as10.net-ID]:Name=sharleena.as10.net force
@@ -16,7 +16,7 @@ C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Configuration=qm-10.1.1.0/24-10.1.2.0/24 f
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Local-ID=lid-10.1.1.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Remote-ID=rid-10.1.2.0/24 force
C set [qm-10.1.1.0/24-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.1.0/24]:Network=10.1.1.0 force
C set [lid-10.1.1.0/24]:Netmask=255.255.255.0 force
diff --git a/regress/sbin/ipsecctl/ike17.ok b/regress/sbin/ipsecctl/ike17.ok
index 242622d29d1..765f90222e7 100644
--- a/regress/sbin/ipsecctl/ike17.ok
+++ b/regress/sbin/ipsecctl/ike17.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::29]:Phase=1 force
C set [peer-3ffe::29]:Address=3ffe::29 force
C set [peer-3ffe::29]:Configuration=mm-3ffe::29 force
C set [mm-3ffe::29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Phase=2 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:ISAKMP-peer=peer-3ffe::29 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Configuration=qm-10.1.1.0/24-10.1.2.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Local-ID=lid-10.1.1.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Remote-ID=rid-10.1.2.0/24 force
C set [qm-10.1.1.0/24-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.1.0/24]:Network=10.1.1.0 force
C set [lid-10.1.1.0/24]:Netmask=255.255.255.0 force
@@ -23,14 +23,14 @@ C set [peer-3ffe::29]:Phase=1 force
C set [peer-3ffe::29]:Address=3ffe::29 force
C set [peer-3ffe::29]:Configuration=mm-3ffe::29 force
C set [mm-3ffe::29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::51-3ffe::29]:Phase=2 force
C set [IPsec-3ffe::51-3ffe::29]:ISAKMP-peer=peer-3ffe::29 force
C set [IPsec-3ffe::51-3ffe::29]:Configuration=qm-3ffe::51-3ffe::29 force
C set [IPsec-3ffe::51-3ffe::29]:Local-ID=lid-3ffe::51 force
C set [IPsec-3ffe::51-3ffe::29]:Remote-ID=rid-3ffe::29 force
C set [qm-3ffe::51-3ffe::29]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::51-3ffe::29]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::51-3ffe::29]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::51]:ID-type=IPV6_ADDR force
C set [lid-3ffe::51]:Address=3ffe::51 force
C set [rid-3ffe::29]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike18.ok b/regress/sbin/ipsecctl/ike18.ok
index 0b7e7200e43..36bd8a67ac0 100644
--- a/regress/sbin/ipsecctl/ike18.ok
+++ b/regress/sbin/ipsecctl/ike18.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::51]:Phase=1 force
C set [peer-3ffe::51]:Address=3ffe::51 force
C set [peer-3ffe::51]:Configuration=mm-3ffe::51 force
C set [mm-3ffe::51]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::51]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::51]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Phase=2 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:ISAKMP-peer=peer-3ffe::51 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Configuration=qm-10.1.2.0/24-10.1.1.0/24 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Local-ID=lid-10.1.2.0/24 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Remote-ID=rid-10.1.1.0/24 force
C set [qm-10.1.2.0/24-10.1.1.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.2.0/24-10.1.1.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.2.0/24-10.1.1.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.2.0/24]:Network=10.1.2.0 force
C set [lid-10.1.2.0/24]:Netmask=255.255.255.0 force
@@ -23,14 +23,14 @@ C set [peer-3ffe::51]:Phase=1 force
C set [peer-3ffe::51]:Address=3ffe::51 force
C set [peer-3ffe::51]:Configuration=mm-3ffe::51 force
C set [mm-3ffe::51]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::51]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::51]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::29-3ffe::51]:Phase=2 force
C set [IPsec-3ffe::29-3ffe::51]:ISAKMP-peer=peer-3ffe::51 force
C set [IPsec-3ffe::29-3ffe::51]:Configuration=qm-3ffe::29-3ffe::51 force
C set [IPsec-3ffe::29-3ffe::51]:Local-ID=lid-3ffe::29 force
C set [IPsec-3ffe::29-3ffe::51]:Remote-ID=rid-3ffe::51 force
C set [qm-3ffe::29-3ffe::51]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::29-3ffe::51]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::29-3ffe::51]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::29]:ID-type=IPV6_ADDR force
C set [lid-3ffe::29]:Address=3ffe::29 force
C set [rid-3ffe::51]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike19.ok b/regress/sbin/ipsecctl/ike19.ok
index 854aa89d9b9..d440bbc0629 100644
--- a/regress/sbin/ipsecctl/ike19.ok
+++ b/regress/sbin/ipsecctl/ike19.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::1]:Phase=1 force
C set [peer-3ffe::1]:Address=3ffe::1 force
C set [peer-3ffe::1]:Configuration=mm-3ffe::1 force
C set [mm-3ffe::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Phase=2 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:ISAKMP-peer=peer-3ffe::1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Configuration=qm-1.1.1.1-0.0.0.0/0 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Remote-ID=rid-0.0.0.0/0 force
C set [qm-1.1.1.1-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
diff --git a/regress/sbin/ipsecctl/ike2.ok b/regress/sbin/ipsecctl/ike2.ok
index f4917d5d394..11112ea8e12 100644
--- a/regress/sbin/ipsecctl/ike2.ok
+++ b/regress/sbin/ipsecctl/ike2.ok
@@ -3,14 +3,14 @@ C set [peer-131.188.33.29]:Phase=1 force
C set [peer-131.188.33.29]:Address=131.188.33.29 force
C set [peer-131.188.33.29]:Configuration=mm-131.188.33.29 force
C set [mm-131.188.33.29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Phase=2 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:ISAKMP-peer=peer-131.188.33.29 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Configuration=qm-10.1.1.0/24-10.1.2.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Local-ID=lid-10.1.1.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Remote-ID=rid-10.1.2.0/24 force
C set [qm-10.1.1.0/24-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.1.0/24]:Network=10.1.1.0 force
C set [lid-10.1.1.0/24]:Netmask=255.255.255.0 force
diff --git a/regress/sbin/ipsecctl/ike20.ok b/regress/sbin/ipsecctl/ike20.ok
index 960af35a974..efb364da6c9 100644
--- a/regress/sbin/ipsecctl/ike20.ok
+++ b/regress/sbin/ipsecctl/ike20.ok
@@ -4,14 +4,14 @@ C set [peer-192.168.3.1]:Address=192.168.3.1 force
C set [peer-192.168.3.1]:Local-address=192.168.3.2 force
C set [peer-192.168.3.1]:Configuration=mm-192.168.3.1 force
C set [mm-192.168.3.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-192.168.3.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-192.168.3.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Phase=2 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:ISAKMP-peer=peer-192.168.3.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Configuration=qm-1.1.1.1-0.0.0.0/0 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Remote-ID=rid-0.0.0.0/0 force
C set [qm-1.1.1.1-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
@@ -24,14 +24,14 @@ C set [peer-192.168.3.1]:Address=192.168.3.1 force
C set [peer-192.168.3.1]:Local-address=192.168.3.2 force
C set [peer-192.168.3.1]:Configuration=mm-192.168.3.1 force
C set [mm-192.168.3.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-192.168.3.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-192.168.3.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Phase=2 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:ISAKMP-peer=peer-192.168.3.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Configuration=qm-1.1.1.1-0.0.0.0/0 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Remote-ID=rid-0.0.0.0/0 force
C set [qm-1.1.1.1-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
diff --git a/regress/sbin/ipsecctl/ike21.ok b/regress/sbin/ipsecctl/ike21.ok
index 37519a126aa..14dd3a6ee16 100644
--- a/regress/sbin/ipsecctl/ike21.ok
+++ b/regress/sbin/ipsecctl/ike21.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::2]:Phase=1 force
C set [peer-3ffe::2]:Address=3ffe::2 force
C set [peer-3ffe::2]:Configuration=mm-3ffe::2 force
C set [mm-3ffe::2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::1-3ffe::2]:Phase=2 force
C set [IPsec-3ffe::1-3ffe::2]:ISAKMP-peer=peer-3ffe::2 force
C set [IPsec-3ffe::1-3ffe::2]:Configuration=qm-3ffe::1-3ffe::2 force
C set [IPsec-3ffe::1-3ffe::2]:Local-ID=lid-3ffe::1 force
C set [IPsec-3ffe::1-3ffe::2]:Remote-ID=rid-3ffe::2 force
C set [qm-3ffe::1-3ffe::2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::1-3ffe::2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::1-3ffe::2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::1]:ID-type=IPV6_ADDR force
C set [lid-3ffe::1]:Address=3ffe::1 force
C set [rid-3ffe::2]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike22.ok b/regress/sbin/ipsecctl/ike22.ok
index bd769d1ac59..92465e7b950 100644
--- a/regress/sbin/ipsecctl/ike22.ok
+++ b/regress/sbin/ipsecctl/ike22.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::1]:Phase=1 force
C set [peer-3ffe::1]:Address=3ffe::1 force
C set [peer-3ffe::1]:Configuration=mm-3ffe::1 force
C set [mm-3ffe::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Phase=2 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:ISAKMP-peer=peer-3ffe::1 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Configuration=qm-10.1.1.0/24-10.1.2.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Local-ID=lid-10.1.1.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Remote-ID=rid-10.1.2.0/24 force
C set [qm-10.1.1.0/24-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.1.0/24]:Network=10.1.1.0 force
C set [lid-10.1.1.0/24]:Netmask=255.255.255.0 force
diff --git a/regress/sbin/ipsecctl/ike23.ok b/regress/sbin/ipsecctl/ike23.ok
index 4d8807b8f1f..93a411fff95 100644
--- a/regress/sbin/ipsecctl/ike23.ok
+++ b/regress/sbin/ipsecctl/ike23.ok
@@ -3,7 +3,7 @@ C set [peer-3ffe::29]:Phase=1 force
C set [peer-3ffe::29]:Address=3ffe::29 force
C set [peer-3ffe::29]:Configuration=mm-3ffe::29 force
C set [mm-3ffe::29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::29]:Transforms=AES-SHA-RSA_SIG force
C set [peer-3ffe::29]:ID=sharleena.as10.net-ID force
C set [sharleena.as10.net-ID]:ID-type=FQDN force
C set [sharleena.as10.net-ID]:Name=sharleena.as10.net force
@@ -16,7 +16,7 @@ C set [IPsec-3ffe::51-3ffe::29]:Configuration=qm-3ffe::51-3ffe::29 force
C set [IPsec-3ffe::51-3ffe::29]:Local-ID=lid-3ffe::51 force
C set [IPsec-3ffe::51-3ffe::29]:Remote-ID=rid-3ffe::29 force
C set [qm-3ffe::51-3ffe::29]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::51-3ffe::29]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::51-3ffe::29]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::51]:ID-type=IPV6_ADDR force
C set [lid-3ffe::51]:Address=3ffe::51 force
C set [rid-3ffe::29]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike29.ok b/regress/sbin/ipsecctl/ike29.ok
index baaf19f2a1c..4675d4f4f9f 100644
--- a/regress/sbin/ipsecctl/ike29.ok
+++ b/regress/sbin/ipsecctl/ike29.ok
@@ -5,7 +5,7 @@ C set [peer-3ffe:2::1]:Phase=1 force
C set [peer-3ffe:2::1]:Address=3ffe:2::1 force
C set [peer-3ffe:2::1]:Configuration=mm-3ffe:2::1 force
C set [mm-3ffe:2::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe:2::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe:2::1]:Transforms=AES-SHA-RSA_SIG force
C set [peer-3ffe:2::1]:ID=noname.my.domain-ID force
C set [noname.my.domain-ID]:ID-type=FQDN force
C set [noname.my.domain-ID]:Name=noname.my.domain force
@@ -15,7 +15,7 @@ C set [IPsec-3ffe:3::/64-3ffe:4::/64]:Configuration=qm-3ffe:3::/64-3ffe:4::/64 f
C set [IPsec-3ffe:3::/64-3ffe:4::/64]:Local-ID=lid-3ffe:3::/64 force
C set [IPsec-3ffe:3::/64-3ffe:4::/64]:Remote-ID=rid-3ffe:4::/64 force
C set [qm-3ffe:3::/64-3ffe:4::/64]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe:3::/64-3ffe:4::/64]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe:3::/64-3ffe:4::/64]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe:3::/64]:ID-type=IPV6_ADDR_SUBNET force
C set [lid-3ffe:3::/64]:Network=3ffe:3:: force
C set [lid-3ffe:3::/64]:Netmask=ffff:ffff:ffff:ffff:: force
diff --git a/regress/sbin/ipsecctl/ike3.ok b/regress/sbin/ipsecctl/ike3.ok
index 39fccfa8b74..fc7c3916764 100644
--- a/regress/sbin/ipsecctl/ike3.ok
+++ b/regress/sbin/ipsecctl/ike3.ok
@@ -3,7 +3,7 @@ C set [peer-131.188.33.29]:Phase=1 force
C set [peer-131.188.33.29]:Address=131.188.33.29 force
C set [peer-131.188.33.29]:Configuration=mm-131.188.33.29 force
C set [mm-131.188.33.29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.29]:Transforms=AES-SHA-RSA_SIG force
C set [peer-131.188.33.29]:ID=sharleena.as10.net-ID force
C set [sharleena.as10.net-ID]:ID-type=FQDN force
C set [sharleena.as10.net-ID]:Name=sharleena.as10.net force
@@ -16,7 +16,7 @@ C set [IPsec-131.188.33.51-131.188.33.29]:Configuration=qm-131.188.33.51-131.188
C set [IPsec-131.188.33.51-131.188.33.29]:Local-ID=lid-131.188.33.51 force
C set [IPsec-131.188.33.51-131.188.33.29]:Remote-ID=rid-131.188.33.29 force
C set [qm-131.188.33.51-131.188.33.29]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-131.188.33.51-131.188.33.29]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-131.188.33.51-131.188.33.29]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-131.188.33.51]:ID-type=IPV4_ADDR force
C set [lid-131.188.33.51]:Address=131.188.33.51 force
C set [rid-131.188.33.29]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike30.ok b/regress/sbin/ipsecctl/ike30.ok
index 4e31e8b6fdc..f1df19d02d7 100644
--- a/regress/sbin/ipsecctl/ike30.ok
+++ b/regress/sbin/ipsecctl/ike30.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::2]:Phase=1 force
C set [peer-3ffe::2]:Address=3ffe::2 force
C set [peer-3ffe::2]:Configuration=mm-3ffe::2 force
C set [mm-3ffe::2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::1-3ffe::2]:Phase=2 force
C set [IPsec-3ffe::1-3ffe::2]:ISAKMP-peer=peer-3ffe::2 force
C set [IPsec-3ffe::1-3ffe::2]:Configuration=qm-3ffe::1-3ffe::2 force
C set [IPsec-3ffe::1-3ffe::2]:Local-ID=lid-3ffe::1 force
C set [IPsec-3ffe::1-3ffe::2]:Remote-ID=rid-3ffe::2 force
C set [qm-3ffe::1-3ffe::2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::1-3ffe::2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::1-3ffe::2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::1]:ID-type=IPV6_ADDR force
C set [lid-3ffe::1]:Address=3ffe::1 force
C set [rid-3ffe::2]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike31.ok b/regress/sbin/ipsecctl/ike31.ok
index 2a7506aee76..4a35e8c65c1 100644
--- a/regress/sbin/ipsecctl/ike31.ok
+++ b/regress/sbin/ipsecctl/ike31.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::1]:Phase=1 force
C set [peer-3ffe::1]:Address=3ffe::1 force
C set [peer-3ffe::1]:Configuration=mm-3ffe::1 force
C set [mm-3ffe::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe:2::1-::/0]:Phase=2 force
C set [IPsec-3ffe:2::1-::/0]:ISAKMP-peer=peer-3ffe::1 force
C set [IPsec-3ffe:2::1-::/0]:Configuration=qm-3ffe:2::1-::/0 force
C set [IPsec-3ffe:2::1-::/0]:Local-ID=lid-3ffe:2::1 force
C set [IPsec-3ffe:2::1-::/0]:Remote-ID=rid-::/0 force
C set [qm-3ffe:2::1-::/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe:2::1-::/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe:2::1-::/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe:2::1]:ID-type=IPV6_ADDR force
C set [lid-3ffe:2::1]:Address=3ffe:2::1 force
C set [rid-::/0]:ID-type=IPV6_ADDR_SUBNET force
diff --git a/regress/sbin/ipsecctl/ike32.ok b/regress/sbin/ipsecctl/ike32.ok
index 338d7adcb76..97f4022303e 100644
--- a/regress/sbin/ipsecctl/ike32.ok
+++ b/regress/sbin/ipsecctl/ike32.ok
@@ -4,14 +4,14 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.2]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Configuration=qm-1.1.1.1-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.2]:Remote-ID=rid-2.2.2.2 force
C set [qm-1.1.1.1-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.2]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike33.ok b/regress/sbin/ipsecctl/ike33.ok
index 188d7080c32..e11446041fb 100644
--- a/regress/sbin/ipsecctl/ike33.ok
+++ b/regress/sbin/ipsecctl/ike33.ok
@@ -4,14 +4,14 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.2]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Configuration=qm-1.1.1.1-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.2]:Remote-ID=rid-2.2.2.2 force
C set [qm-1.1.1.1-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.2]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike34.ok b/regress/sbin/ipsecctl/ike34.ok
index 1158ef6245a..cb7d9897b06 100644
--- a/regress/sbin/ipsecctl/ike34.ok
+++ b/regress/sbin/ipsecctl/ike34.ok
@@ -3,14 +3,14 @@ C set [peer-1.2.3.4]:Phase=1 force
C set [peer-1.2.3.4]:Address=1.2.3.4 force
C set [peer-1.2.3.4]:Configuration=mm-1.2.3.4 force
C set [mm-1.2.3.4]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.2.3.4]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.2.3.4]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::1/24-3ffe:2::/24]:Phase=2 force
C set [IPsec-3ffe::1/24-3ffe:2::/24]:ISAKMP-peer=peer-1.2.3.4 force
C set [IPsec-3ffe::1/24-3ffe:2::/24]:Configuration=qm-3ffe::1/24-3ffe:2::/24 force
C set [IPsec-3ffe::1/24-3ffe:2::/24]:Local-ID=lid-3ffe::1/24 force
C set [IPsec-3ffe::1/24-3ffe:2::/24]:Remote-ID=rid-3ffe:2::/24 force
C set [qm-3ffe::1/24-3ffe:2::/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::1/24-3ffe:2::/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::1/24-3ffe:2::/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::1/24]:ID-type=IPV6_ADDR_SUBNET force
C set [lid-3ffe::1/24]:Network=3ffe::1 force
C set [lid-3ffe::1/24]:Netmask=ffff:ff00:: force
diff --git a/regress/sbin/ipsecctl/ike35.ok b/regress/sbin/ipsecctl/ike35.ok
index 7339a2d7701..92d2fc9a4bd 100644
--- a/regress/sbin/ipsecctl/ike35.ok
+++ b/regress/sbin/ipsecctl/ike35.ok
@@ -3,14 +3,14 @@ C set [peer-1.2.3.4]:Phase=1 force
C set [peer-1.2.3.4]:Address=1.2.3.4 force
C set [peer-1.2.3.4]:Configuration=mm-1.2.3.4 force
C set [mm-1.2.3.4]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-1.2.3.4]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-1.2.3.4]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe:2::/24-3ffe::1/24]:Phase=2 force
C set [IPsec-3ffe:2::/24-3ffe::1/24]:ISAKMP-peer=peer-1.2.3.4 force
C set [IPsec-3ffe:2::/24-3ffe::1/24]:Configuration=qm-3ffe:2::/24-3ffe::1/24 force
C set [IPsec-3ffe:2::/24-3ffe::1/24]:Local-ID=lid-3ffe:2::/24 force
C set [IPsec-3ffe:2::/24-3ffe::1/24]:Remote-ID=rid-3ffe::1/24 force
C set [qm-3ffe:2::/24-3ffe::1/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe:2::/24-3ffe::1/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe:2::/24-3ffe::1/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe:2::/24]:ID-type=IPV6_ADDR_SUBNET force
C set [lid-3ffe:2::/24]:Network=3ffe:2:: force
C set [lid-3ffe:2::/24]:Netmask=ffff:ff00:: force
diff --git a/regress/sbin/ipsecctl/ike36.ok b/regress/sbin/ipsecctl/ike36.ok
index 1336ed16326..69e3b7b4d6d 100644
--- a/regress/sbin/ipsecctl/ike36.ok
+++ b/regress/sbin/ipsecctl/ike36.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::1]:Phase=1 force
C set [peer-3ffe::1]:Address=3ffe::1 force
C set [peer-3ffe::1]:Configuration=mm-3ffe::1 force
C set [mm-3ffe::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::3-3ffe::4]:Phase=2 force
C set [IPsec-3ffe::3-3ffe::4]:ISAKMP-peer=peer-3ffe::1 force
C set [IPsec-3ffe::3-3ffe::4]:Configuration=qm-3ffe::3-3ffe::4 force
C set [IPsec-3ffe::3-3ffe::4]:Local-ID=lid-3ffe::3 force
C set [IPsec-3ffe::3-3ffe::4]:Remote-ID=rid-3ffe::4 force
C set [qm-3ffe::3-3ffe::4]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::3-3ffe::4]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::3-3ffe::4]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::3]:ID-type=IPV6_ADDR force
C set [lid-3ffe::3]:Address=3ffe::3 force
C set [rid-3ffe::4]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike37.ok b/regress/sbin/ipsecctl/ike37.ok
index 9d735efe24b..c6fdb02dc42 100644
--- a/regress/sbin/ipsecctl/ike37.ok
+++ b/regress/sbin/ipsecctl/ike37.ok
@@ -3,7 +3,7 @@ C set [peer-3ffe::1]:Phase=1 force
C set [peer-3ffe::1]:Address=3ffe::1 force
C set [peer-3ffe::1]:Configuration=mm-3ffe::1 force
C set [mm-3ffe::1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::1]:Transforms=AES-SHA-RSA_SIG force
C set [peer-3ffe::1]:ID=sharleena.as10.net-ID force
C set [sharleena.as10.net-ID]:ID-type=FQDN force
C set [sharleena.as10.net-ID]:Name=sharleena.as10.net force
@@ -16,7 +16,7 @@ C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Configuration=qm-3ffe:1::/64-3ffe:2::/64 f
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Local-ID=lid-3ffe:1::/64 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Remote-ID=rid-3ffe:2::/64 force
C set [qm-3ffe:1::/64-3ffe:2::/64]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe:1::/64-3ffe:2::/64]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe:1::/64-3ffe:2::/64]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe:1::/64]:ID-type=IPV6_ADDR_SUBNET force
C set [lid-3ffe:1::/64]:Network=3ffe:1:: force
C set [lid-3ffe:1::/64]:Netmask=ffff:ffff:ffff:ffff:: force
diff --git a/regress/sbin/ipsecctl/ike39.ok b/regress/sbin/ipsecctl/ike39.ok
index d11254f52e2..0dc8d0f5093 100644
--- a/regress/sbin/ipsecctl/ike39.ok
+++ b/regress/sbin/ipsecctl/ike39.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::29]:Phase=1 force
C set [peer-3ffe::29]:Address=3ffe::29 force
C set [peer-3ffe::29]:Configuration=mm-3ffe::29 force
C set [mm-3ffe::29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Phase=2 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:ISAKMP-peer=peer-3ffe::29 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Configuration=qm-3ffe:1::/64-3ffe:2::/64 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Local-ID=lid-3ffe:1::/64 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Remote-ID=rid-3ffe:2::/64 force
C set [qm-3ffe:1::/64-3ffe:2::/64]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe:1::/64-3ffe:2::/64]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe:1::/64-3ffe:2::/64]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe:1::/64]:ID-type=IPV6_ADDR_SUBNET force
C set [lid-3ffe:1::/64]:Network=3ffe:1:: force
C set [lid-3ffe:1::/64]:Netmask=ffff:ffff:ffff:ffff:: force
@@ -23,14 +23,14 @@ C set [peer-3ffe::29]:Phase=1 force
C set [peer-3ffe::29]:Address=3ffe::29 force
C set [peer-3ffe::29]:Configuration=mm-3ffe::29 force
C set [mm-3ffe::29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::51-3ffe::29]:Phase=2 force
C set [IPsec-3ffe::51-3ffe::29]:ISAKMP-peer=peer-3ffe::29 force
C set [IPsec-3ffe::51-3ffe::29]:Configuration=qm-3ffe::51-3ffe::29 force
C set [IPsec-3ffe::51-3ffe::29]:Local-ID=lid-3ffe::51 force
C set [IPsec-3ffe::51-3ffe::29]:Remote-ID=rid-3ffe::29 force
C set [qm-3ffe::51-3ffe::29]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::51-3ffe::29]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::51-3ffe::29]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::51]:ID-type=IPV6_ADDR force
C set [lid-3ffe::51]:Address=3ffe::51 force
C set [rid-3ffe::29]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike4.ok b/regress/sbin/ipsecctl/ike4.ok
index e2e2aa46923..a3e698ce51a 100644
--- a/regress/sbin/ipsecctl/ike4.ok
+++ b/regress/sbin/ipsecctl/ike4.ok
@@ -3,7 +3,7 @@ C set [peer-131.188.33.29]:Phase=1 force
C set [peer-131.188.33.29]:Address=131.188.33.29 force
C set [peer-131.188.33.29]:Configuration=mm-131.188.33.29 force
C set [mm-131.188.33.29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.29]:Transforms=AES-SHA-RSA_SIG force
C set [peer-131.188.33.29]:ID=sharleena.as10.net-ID force
C set [sharleena.as10.net-ID]:ID-type=FQDN force
C set [sharleena.as10.net-ID]:Name=sharleena.as10.net force
@@ -16,7 +16,7 @@ C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Configuration=qm-10.1.1.0/24-10.1.2.0/24 f
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Local-ID=lid-10.1.1.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Remote-ID=rid-10.1.2.0/24 force
C set [qm-10.1.1.0/24-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.1.0/24]:Network=10.1.1.0 force
C set [lid-10.1.1.0/24]:Netmask=255.255.255.0 force
diff --git a/regress/sbin/ipsecctl/ike40.ok b/regress/sbin/ipsecctl/ike40.ok
index 9761d98b353..62389eaea1e 100644
--- a/regress/sbin/ipsecctl/ike40.ok
+++ b/regress/sbin/ipsecctl/ike40.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::51]:Phase=1 force
C set [peer-3ffe::51]:Address=3ffe::51 force
C set [peer-3ffe::51]:Configuration=mm-3ffe::51 force
C set [mm-3ffe::51]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::51]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::51]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Phase=2 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:ISAKMP-peer=peer-3ffe::51 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Configuration=qm-3ffe:1::/64-3ffe:2::/64 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Local-ID=lid-3ffe:1::/64 force
C set [IPsec-3ffe:1::/64-3ffe:2::/64]:Remote-ID=rid-3ffe:2::/64 force
C set [qm-3ffe:1::/64-3ffe:2::/64]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe:1::/64-3ffe:2::/64]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe:1::/64-3ffe:2::/64]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe:1::/64]:ID-type=IPV6_ADDR_SUBNET force
C set [lid-3ffe:1::/64]:Network=3ffe:1:: force
C set [lid-3ffe:1::/64]:Netmask=ffff:ffff:ffff:ffff:: force
@@ -23,14 +23,14 @@ C set [peer-3ffe::51]:Phase=1 force
C set [peer-3ffe::51]:Address=3ffe::51 force
C set [peer-3ffe::51]:Configuration=mm-3ffe::51 force
C set [mm-3ffe::51]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::51]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::51]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::29-3ffe::51]:Phase=2 force
C set [IPsec-3ffe::29-3ffe::51]:ISAKMP-peer=peer-3ffe::51 force
C set [IPsec-3ffe::29-3ffe::51]:Configuration=qm-3ffe::29-3ffe::51 force
C set [IPsec-3ffe::29-3ffe::51]:Local-ID=lid-3ffe::29 force
C set [IPsec-3ffe::29-3ffe::51]:Remote-ID=rid-3ffe::51 force
C set [qm-3ffe::29-3ffe::51]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::29-3ffe::51]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::29-3ffe::51]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::29]:ID-type=IPV6_ADDR force
C set [lid-3ffe::29]:Address=3ffe::29 force
C set [rid-3ffe::51]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike41.ok b/regress/sbin/ipsecctl/ike41.ok
index 6da54ba009c..9816d8e4097 100644
--- a/regress/sbin/ipsecctl/ike41.ok
+++ b/regress/sbin/ipsecctl/ike41.ok
@@ -5,14 +5,14 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.2]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Configuration=qm-1.1.1.1-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.2]:Remote-ID=rid-2.2.2.2 force
C set [qm-1.1.1.1-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.2]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike42.ok b/regress/sbin/ipsecctl/ike42.ok
index c58bdffbb3c..323637044c6 100644
--- a/regress/sbin/ipsecctl/ike42.ok
+++ b/regress/sbin/ipsecctl/ike42.ok
@@ -3,14 +3,14 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.2]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Configuration=qm-1.1.1.1-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.2]:Remote-ID=rid-2.2.2.2 force
C set [qm-1.1.1.1-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.2]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike43.ok b/regress/sbin/ipsecctl/ike43.ok
index ac456989b93..e745d5310bf 100644
--- a/regress/sbin/ipsecctl/ike43.ok
+++ b/regress/sbin/ipsecctl/ike43.ok
@@ -3,14 +3,14 @@ C set [peer-3ffe::2]:Phase=1 force
C set [peer-3ffe::2]:Address=3ffe::2 force
C set [peer-3ffe::2]:Configuration=mm-3ffe::2 force
C set [mm-3ffe::2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-3ffe::2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-3ffe::2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-3ffe::1-3ffe::2]:Phase=2 force
C set [IPsec-3ffe::1-3ffe::2]:ISAKMP-peer=peer-3ffe::2 force
C set [IPsec-3ffe::1-3ffe::2]:Configuration=qm-3ffe::1-3ffe::2 force
C set [IPsec-3ffe::1-3ffe::2]:Local-ID=lid-3ffe::1 force
C set [IPsec-3ffe::1-3ffe::2]:Remote-ID=rid-3ffe::2 force
C set [qm-3ffe::1-3ffe::2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3ffe::1-3ffe::2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3ffe::1-3ffe::2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3ffe::1]:ID-type=IPV6_ADDR force
C set [lid-3ffe::1]:Address=3ffe::1 force
C set [rid-3ffe::2]:ID-type=IPV6_ADDR force
diff --git a/regress/sbin/ipsecctl/ike46.ok b/regress/sbin/ipsecctl/ike46.ok
index aab90ab162d..b122e11231d 100644
--- a/regress/sbin/ipsecctl/ike46.ok
+++ b/regress/sbin/ipsecctl/ike46.ok
@@ -3,14 +3,14 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.2]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Configuration=qm-1.1.1.1-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.2]:Remote-ID=rid-2.2.2.2 force
C set [qm-1.1.1.1-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.2]:ID-type=IPV4_ADDR force
@@ -21,14 +21,14 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-2.2.2.2]:Phase=2 force
C set [IPsec-1.1.1.1-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Configuration=qm-1.1.1.1-2.2.2.2 force
C set [IPsec-1.1.1.1-2.2.2.2]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-2.2.2.2]:Remote-ID=rid-2.2.2.2 force
C set [qm-1.1.1.1-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-TRP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-2.2.2.2]:Suites=QM-ESP-TRP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-2.2.2.2]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike6.ok b/regress/sbin/ipsecctl/ike6.ok
index b13282f49f7..80006b1a5d3 100644
--- a/regress/sbin/ipsecctl/ike6.ok
+++ b/regress/sbin/ipsecctl/ike6.ok
@@ -3,14 +3,14 @@ C set [peer-131.188.33.29]:Phase=1 force
C set [peer-131.188.33.29]:Address=131.188.33.29 force
C set [peer-131.188.33.29]:Configuration=mm-131.188.33.29 force
C set [mm-131.188.33.29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Phase=2 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:ISAKMP-peer=peer-131.188.33.29 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Configuration=qm-10.1.1.0/24-10.1.2.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Local-ID=lid-10.1.1.0/24 force
C set [IPsec-10.1.1.0/24-10.1.2.0/24]:Remote-ID=rid-10.1.2.0/24 force
C set [qm-10.1.1.0/24-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.1.0/24-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.1.0/24]:Network=10.1.1.0 force
C set [lid-10.1.1.0/24]:Netmask=255.255.255.0 force
@@ -23,14 +23,14 @@ C set [peer-131.188.33.29]:Phase=1 force
C set [peer-131.188.33.29]:Address=131.188.33.29 force
C set [peer-131.188.33.29]:Configuration=mm-131.188.33.29 force
C set [mm-131.188.33.29]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.29]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.29]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-131.188.33.51-131.188.33.29]:Phase=2 force
C set [IPsec-131.188.33.51-131.188.33.29]:ISAKMP-peer=peer-131.188.33.29 force
C set [IPsec-131.188.33.51-131.188.33.29]:Configuration=qm-131.188.33.51-131.188.33.29 force
C set [IPsec-131.188.33.51-131.188.33.29]:Local-ID=lid-131.188.33.51 force
C set [IPsec-131.188.33.51-131.188.33.29]:Remote-ID=rid-131.188.33.29 force
C set [qm-131.188.33.51-131.188.33.29]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-131.188.33.51-131.188.33.29]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-131.188.33.51-131.188.33.29]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-131.188.33.51]:ID-type=IPV4_ADDR force
C set [lid-131.188.33.51]:Address=131.188.33.51 force
C set [rid-131.188.33.29]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike7.ok b/regress/sbin/ipsecctl/ike7.ok
index 0c4cf7ac7b3..4fd969cbee4 100644
--- a/regress/sbin/ipsecctl/ike7.ok
+++ b/regress/sbin/ipsecctl/ike7.ok
@@ -3,14 +3,14 @@ C set [peer-131.188.33.51]:Phase=1 force
C set [peer-131.188.33.51]:Address=131.188.33.51 force
C set [peer-131.188.33.51]:Configuration=mm-131.188.33.51 force
C set [mm-131.188.33.51]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.51]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.51]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Phase=2 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:ISAKMP-peer=peer-131.188.33.51 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Configuration=qm-10.1.2.0/24-10.1.1.0/24 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Local-ID=lid-10.1.2.0/24 force
C set [IPsec-10.1.2.0/24-10.1.1.0/24]:Remote-ID=rid-10.1.1.0/24 force
C set [qm-10.1.2.0/24-10.1.1.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-10.1.2.0/24-10.1.1.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-10.1.2.0/24-10.1.1.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-10.1.2.0/24]:Network=10.1.2.0 force
C set [lid-10.1.2.0/24]:Netmask=255.255.255.0 force
@@ -23,14 +23,14 @@ C set [peer-131.188.33.51]:Phase=1 force
C set [peer-131.188.33.51]:Address=131.188.33.51 force
C set [peer-131.188.33.51]:Configuration=mm-131.188.33.51 force
C set [mm-131.188.33.51]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-131.188.33.51]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-131.188.33.51]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-131.188.33.29-131.188.33.51]:Phase=2 force
C set [IPsec-131.188.33.29-131.188.33.51]:ISAKMP-peer=peer-131.188.33.51 force
C set [IPsec-131.188.33.29-131.188.33.51]:Configuration=qm-131.188.33.29-131.188.33.51 force
C set [IPsec-131.188.33.29-131.188.33.51]:Local-ID=lid-131.188.33.29 force
C set [IPsec-131.188.33.29-131.188.33.51]:Remote-ID=rid-131.188.33.51 force
C set [qm-131.188.33.29-131.188.33.51]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-131.188.33.29-131.188.33.51]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-131.188.33.29-131.188.33.51]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-131.188.33.29]:ID-type=IPV4_ADDR force
C set [lid-131.188.33.29]:Address=131.188.33.29 force
C set [rid-131.188.33.51]:ID-type=IPV4_ADDR force
diff --git a/regress/sbin/ipsecctl/ike8.ok b/regress/sbin/ipsecctl/ike8.ok
index 68717f64d10..44c91e112b2 100644
--- a/regress/sbin/ipsecctl/ike8.ok
+++ b/regress/sbin/ipsecctl/ike8.ok
@@ -3,14 +3,14 @@ C set [peer-192.168.3.1]:Phase=1 force
C set [peer-192.168.3.1]:Address=192.168.3.1 force
C set [peer-192.168.3.1]:Configuration=mm-192.168.3.1 force
C set [mm-192.168.3.1]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-192.168.3.1]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-192.168.3.1]:Transforms=AES-SHA-RSA_SIG force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Phase=2 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:ISAKMP-peer=peer-192.168.3.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Configuration=qm-1.1.1.1-0.0.0.0/0 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Local-ID=lid-1.1.1.1 force
C set [IPsec-1.1.1.1-0.0.0.0/0]:Remote-ID=rid-0.0.0.0/0 force
C set [qm-1.1.1.1-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-1.1.1.1-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-1.1.1.1]:ID-type=IPV4_ADDR force
C set [lid-1.1.1.1]:Address=1.1.1.1 force
C set [rid-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
diff --git a/regress/sbin/ipsecctl/ike9.ok b/regress/sbin/ipsecctl/ike9.ok
index fe36268a619..71a038dae5b 100644
--- a/regress/sbin/ipsecctl/ike9.ok
+++ b/regress/sbin/ipsecctl/ike9.ok
@@ -5,7 +5,7 @@ C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=mm-2.2.2.2 force
C set [mm-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
-C add [mm-2.2.2.2]:Transforms=AES-SHA-GRP15-RSA_SIG force
+C add [mm-2.2.2.2]:Transforms=AES-SHA-RSA_SIG force
C set [peer-2.2.2.2]:ID=noname.my.domain-ID force
C set [noname.my.domain-ID]:ID-type=FQDN force
C set [noname.my.domain-ID]:Name=noname.my.domain force
@@ -15,7 +15,7 @@ C set [IPsec-3.3.3.0/24-4.4.4.0/24]:Configuration=qm-3.3.3.0/24-4.4.4.0/24 force
C set [IPsec-3.3.3.0/24-4.4.4.0/24]:Local-ID=lid-3.3.3.0/24 force
C set [IPsec-3.3.3.0/24-4.4.4.0/24]:Remote-ID=rid-4.4.4.0/24 force
C set [qm-3.3.3.0/24-4.4.4.0/24]:EXCHANGE_TYPE=QUICK_MODE force
-C set [qm-3.3.3.0/24-4.4.4.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-GRP15-SUITE force
+C set [qm-3.3.3.0/24-4.4.4.0/24]:Suites=QM-ESP-AES-SHA2-256-SUITE force
C set [lid-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force
C set [lid-3.3.3.0/24]:Network=3.3.3.0 force
C set [lid-3.3.3.0/24]:Netmask=255.255.255.0 force