ikev2: Only request reauth during IKE_AUTH if active reauth is not possible

If we can initiate the reauthentication ourselves, there is no reason to
explicitly request the peer to do so (at basically the same time).
This commit is contained in:
Tobias Brunner
2021-08-24 14:31:55 +02:00
parent 0d373e25e0
commit 23e46ea5ab
12 changed files with 62 additions and 39 deletions
@@ -1,7 +1,8 @@
This scenario tests <b>repeated authentication</b> according to RFC 4478.
The initiator <b>carol</b> sets a large <b>reauth_time=60m</b> but the responder
<b>moon</b> defining a much shorter <b>reauth_time=30s</b> proposes this
value via an AUTH_LIFETIME notification to the initiator. Thus the
value via an AUTH_LIFETIME notification to the initiator as it can't initiate
the reauthentication itself due to the EAP authentication. Thus the
IKE reauthentication takes places after less than 30s. A ping from
<b>carol</b> to client <b>alice</b> hiding in the subnet behind <b>moon</b>
tests if the CHILD_SA has been recreated under the new IKE_SA.