testing: Use TLS 1.3 in TNC PT-TLS tests

This commit is contained in:
Andreas Steffen
2021-02-21 09:48:34 +01:00
parent 9f55246018
commit 20c47af319
11 changed files with 24 additions and 11 deletions
@@ -1,7 +1,7 @@
The PT-TLS (RFC 6876) clients <b>carol</b> and <b>dave</b> set up a connection each to the policy decision
point (PDP) <b>alice</b>. Endpoint <b>carol</b> uses password-based SASL PLAIN client authentication during the
<b>PT-TLS negotiation phase</b> whereas endpoint <b>dave</b> uses certificate-based TLS client authentication
during the <b>TLS setup phase</b>.
during the <b>TLS setup phase</b>. In both connections TLS 1.3 is used.
<p/>
During the ensuing <b>PT-TLS data transport phase</b> the <b>OS</b> and <b>SWIMA</b> IMC/IMV pairs
loaded by the PT-TLS clients and PDP, respectively, exchange PA-TNC (RFC 5792) messages
@@ -24,7 +24,9 @@ charon-systemd {
}
libtls {
suites = TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
suites = TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384, TLS_CHACHA20_POLY1305_SHA256
ke_group = curve25519, curve448
version_max = 1.3
}
libimcv {
@@ -1,7 +1,9 @@
# /etc/strongswan.conf - strongSwan configuration file
libtls {
suites = TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
suites = TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384
ke_group = curve25519, curve448
version_max = 1.3
}
libimcv {
@@ -12,7 +12,9 @@ libimcv {
}
libtls {
suites = TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
suites = TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384
ke_group = curve25519, curve448
version_max = 1.3
}
pt-tls-client {