- added separate implementation for connection_store, credential_store, policy_store

- added folder structure to config
- credentials are fetched solely on IDs now
This commit is contained in:
Martin Willi
2006-04-25 10:06:30 +00:00
parent a8c09d8cc0
commit 13e4a62f5c
36 changed files with 1240 additions and 641 deletions
+10 -11
View File
@@ -4,18 +4,17 @@
echo 1 > /proc/sys/net/ipv4/ip_forward
# add connection to alice
MY_ADDR=192.168.0.2 # Address of local peer, also used as ID
OTHER_ADDR=192.168.0.1 # Address of remote peer, also used as ID
MY_CERT=bob.der # own certificate
OTHER_CERT=alice.der # certificate for remote peer
MY_NET=10.2.0.0 # protected local subnet
OTHER_NET=10.1.0.0 # protected remote subnet
MY_BITS=16 # size of subnet
OTHER_BITS=16 # size of subnet
CONN_NAME=to-alice # connection name
MY_ADDR=192.168.0.2 # Address of local peer
OTHER_ADDR=192.168.0.1 # Address of remote peer
MY_ID="C=CH, O=Linux strongSwan, CN=bob" # ID of local peer
OTHER_ID="C=CH, O=Linux strongSwan, CN=alice" # ID of remote peer
MY_NET=10.2.0.0 # protected local subnet
OTHER_NET=10.1.0.0 # protected remote subnet
MY_BITS=16 # size of subnet
OTHER_BITS=16 # size of subnet
CONN_NAME=to-alice # connection name
bin/stroke add $CONN_NAME $MY_ADDR $OTHER_ADDR $MY_CERT $OTHER_CERT \
$MY_ADDR $OTHER_ADDR $MY_NET $OTHER_NET $MY_BITS $OTHER_BITS
bin/stroke add $CONN_NAME "$MY_ID" "$OTHER_ID" $MY_ADDR $OTHER_ADDR $MY_NET $OTHER_NET $MY_BITS $OTHER_BITS
# initiate
i=0
+20 -12
View File
@@ -4,16 +4,24 @@
echo 1 > /proc/sys/net/ipv4/ip_forward
# add connection to bob
MY_ADDR=192.168.0.1 # Address of local peer, also used as ID
OTHER_ADDR=192.168.0.2 # Address of remote peer, also used as ID
MY_CERT=alice.der # own certificate
OTHER_CERT=bob.der # certificate for remote peer
MY_NET=10.1.0.0 # protected local subnet
OTHER_NET=10.2.0.0 # protected remote subnet
MY_BITS=16 # size of subnet
OTHER_BITS=16 # size of subnet
CONN_NAME=to-bob # connection name
MY_ADDR=192.168.0.1 # Address of local peer
OTHER_ADDR=192.168.0.2 # Address of remote peer
MY_ID="C=CH, O=Linux strongSwan, CN=alice" # ID of local peer
OTHER_ID="C=CH, O=Linux strongSwan, CN=bob" # ID of remote peer
MY_NET=10.1.0.0 # protected local subnet
OTHER_NET=10.2.0.0 # protected remote subnet
MY_BITS=16 # size of subnet
OTHER_BITS=16 # size of subnet
CONN_NAME=to-bob # connection name
bin/stroke add $CONN_NAME $MY_ADDR $OTHER_ADDR $MY_CERT $OTHER_CERT \
$MY_ADDR $OTHER_ADDR $MY_NET $OTHER_NET $MY_BITS $OTHER_BITS
bin/stroke add $CONN_NAME "$MY_ID" "$OTHER_ID" $MY_ADDR $OTHER_ADDR $MY_NET $OTHER_NET $MY_BITS $OTHER_BITS
# initiate
i=0
LIMIT=0
while [ "$i" -lt "$LIMIT" ]
do
bin/stroke up $CONN_NAME
let "i += 1"
done