diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/tnc_config deleted file mode 100644 index a9509a716..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMV configuration file for TNC@FHH-TNC-Server - -IMV "Dummy" /usr/local/lib/libdummyimv.so.0.7.0 diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/tnc_config deleted file mode 100644 index a5a9a68f3..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/tnc/dummyimc.file deleted file mode 100644 index 621e94f0e..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -none diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/tnc_config deleted file mode 100644 index a5a9a68f3..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/tnc/dummyimc.file deleted file mode 100644 index f5da834c0..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -allow diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/tnc_config deleted file mode 100644 index a5a9a68f3..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/tnc/dummyimc.file deleted file mode 100644 index 621e94f0e..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -none diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/tnc_config deleted file mode 100644 index a5a9a68f3..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/tnc/dummyimv.policy b/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/tnc/dummyimv.policy deleted file mode 100644 index 573541ac9..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/tnc/dummyimv.policy +++ /dev/null @@ -1 +0,0 @@ -0 diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/tnc_config deleted file mode 100644 index ac436a344..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMV configuration file for strongSwan server - -IMV "Dummy" /usr/local/lib/libdummyimv.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc/dummyimc.file deleted file mode 100644 index f5da834c0..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -allow diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/tnc/dummyimc.file deleted file mode 100644 index f5da834c0..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -allow diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/tnc_config deleted file mode 100644 index a5a9a68f3..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/tnc/dummyimc.file deleted file mode 100644 index c20b5e57f..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -isolate \ No newline at end of file diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/tnc_config deleted file mode 100644 index a5a9a68f3..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/tnc/dummyimv.policy b/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/tnc/dummyimv.policy deleted file mode 100644 index 573541ac9..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/tnc/dummyimv.policy +++ /dev/null @@ -1 +0,0 @@ -0 diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/tnc_config deleted file mode 100644 index ac436a344..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/tnc_config +++ /dev/null @@ -1,3 +0,0 @@ -#IMV configuration file for strongSwan server - -IMV "Dummy" /usr/local/lib/libdummyimv.so diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/tnc/dummyimc.file deleted file mode 100644 index f5da834c0..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -allow diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/tnc_config deleted file mode 100644 index d2fabe109..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/tnc_config +++ /dev/null @@ -1,4 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so -#IMC "HostScanner" /usr/local/lib/libhostscannerimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/strongswan.conf b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/strongswan.conf deleted file mode 100644 index b2aa2806a..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/strongswan.conf +++ /dev/null @@ -1,11 +0,0 @@ -# /etc/strongswan.conf - strongSwan configuration file - -charon { - load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-20 updown - multiple_authentication=no - plugins { - eap-tnc { - protocol = tnccs-2.0 - } - } -} diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/tnc/dummyimc.file b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/tnc/dummyimc.file deleted file mode 100644 index 33945dc1e..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/tnc/dummyimc.file +++ /dev/null @@ -1 +0,0 @@ -isolate diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/tnc_config deleted file mode 100644 index d2fabe109..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/tnc_config +++ /dev/null @@ -1,4 +0,0 @@ -#IMC configuration file for strongSwan client - -IMC "Dummy" /usr/local/lib/libdummyimc.so -#IMC "HostScanner" /usr/local/lib/libhostscannerimc.so diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/tnc/dummyimv.policy b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/tnc/dummyimv.policy deleted file mode 100644 index d00491fd7..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/tnc/dummyimv.policy +++ /dev/null @@ -1 +0,0 @@ -1 diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/tnc_config b/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/tnc_config deleted file mode 100644 index 140caa98f..000000000 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/tnc_config +++ /dev/null @@ -1,4 +0,0 @@ -#IMV configuration file for strongSwan server - -IMV "Dummy" /usr/local/lib/libdummyimv.so -#IMV "HostScanner" /usr/local/lib/libhostscannerimv.so diff --git a/testing/tests/tnc/tnccs-11-fhh/description.txt b/testing/tests/tnc/tnccs-11-fhh/description.txt new file mode 100644 index 000000000..2b7545f59 --- /dev/null +++ b/testing/tests/tnc/tnccs-11-fhh/description.txt @@ -0,0 +1,11 @@ +The roadwarriors carol and dave set up a connection each to gateway moon +using EAP-TTLS authentication only with the gateway presenting a server certificate and +the clients doing EAP-MD5 password-based authentication. +In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the +health of carol and dave via the IF-TNCCS 1.1 client-server interface. +The Dummy IMC and IMV from the TNC@FHH project are used which communicate over a proprietary protocol. +
+carol passes the health test and dave fails. Based on these measurements the +clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, +respectively. + diff --git a/testing/tests/ikev2/rw-eap-tnc-11/evaltest.dat b/testing/tests/tnc/tnccs-11-fhh/evaltest.dat similarity index 78% rename from testing/tests/ikev2/rw-eap-tnc-11/evaltest.dat rename to testing/tests/tnc/tnccs-11-fhh/evaltest.dat index f7d78d1ca..a02755148 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11/evaltest.dat +++ b/testing/tests/tnc/tnccs-11-fhh/evaltest.dat @@ -6,11 +6,9 @@ dave::cat /var/log/daemon.log::TNCCS-Recommendation.*isolate::YES dave::cat /var/log/daemon.log::EAP method EAP_TTLS succeeded, MSK established ::YES dave::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with EAP successful::YES dave::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.200/32 === 10.1.0.16/28::YES -moon::cat /var/log/auth.log::policy enforced on peer 'carol@strongswan.org' is 'allow'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'allow'::YES +moon::cat /var/log/daemon.log::added group membership 'allow'::YES moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES -moon::cat /var/log/auth.log::policy enforced on peer 'dave@strongswan.org' is 'isolate'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'isolate'::YES +moon::cat /var/log/daemon.log::added group membership 'isolate'::YES moon::cat /var/log/daemon.log::authentication of 'dave@strongswan.org' with EAP successful::YES moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/ipsec.conf index c19192dae..ca55d84a2 100755 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/tnc/dummyimc.file b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/tnc/dummyimc.file similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/tnc/dummyimc.file rename to testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/tnc/dummyimc.file diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/tnc/log4cxx.properties diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/tnc_config rename to testing/tests/tnc/tnccs-11-fhh/hosts/carol/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/ipsec.conf index 7d5ea8b83..93807bb66 100755 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/tnc/dummyimc.file b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/tnc/dummyimc.file similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/tnc/dummyimc.file rename to testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/tnc/dummyimc.file diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/tnc/log4cxx.properties diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/tnc_config rename to testing/tests/tnc/tnccs-11-fhh/hosts/dave/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/ipsec.conf similarity index 95% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/ipsec.conf index 50514c99f..32c3357a3 100755 --- a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/ipsec.conf @@ -3,7 +3,7 @@ config setup strictcrlpolicy=no plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc/dummyimv.policy b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc/dummyimv.policy similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc/dummyimv.policy rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc/dummyimv.policy diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc/hostscannerimv.policy b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc/hostscannerimv.policy similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc/hostscannerimv.policy rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc/hostscannerimv.policy diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc/log4cxx.properties diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/moon/etc/tnc_config rename to testing/tests/tnc/tnccs-11-fhh/hosts/moon/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-11/posttest.dat b/testing/tests/tnc/tnccs-11-fhh/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/posttest.dat rename to testing/tests/tnc/tnccs-11-fhh/posttest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-11/pretest.dat b/testing/tests/tnc/tnccs-11-fhh/pretest.dat similarity index 55% rename from testing/tests/ikev2/rw-eap-tnc-11/pretest.dat rename to testing/tests/tnc/tnccs-11-fhh/pretest.dat index 9896b1e4a..c7a30ee7c 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11/pretest.dat +++ b/testing/tests/tnc/tnccs-11-fhh/pretest.dat @@ -6,9 +6,9 @@ carol::cat /etc/tnc_config dave::cat /etc/tnc_config carol::cat /etc/tnc/dummyimc.file dave::cat /etc/tnc/dummyimc.file -moon::LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties ipsec start -carol::LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties ipsec start -dave::LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties ipsec start +moon::LEAK_DETECTIVE_DISABLE=1 LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties ipsec start +carol::LEAK_DETECTIVE_DISABLE=1 LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties ipsec start +dave::LEAK_DETECTIVE_DISABLE=1 LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties ipsec start carol::sleep 1 carol::ipsec up home dave::ipsec up home diff --git a/testing/tests/ikev2/rw-eap-tnc-11/test.conf b/testing/tests/tnc/tnccs-11-fhh/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/test.conf rename to testing/tests/tnc/tnccs-11-fhh/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/description.txt b/testing/tests/tnc/tnccs-11-radius-block/description.txt similarity index 90% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/description.txt rename to testing/tests/tnc/tnccs-11-radius-block/description.txt index 350aefc60..10640649c 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/description.txt +++ b/testing/tests/tnc/tnccs-11-radius-block/description.txt @@ -6,6 +6,8 @@ the FreeRADIUS server alice authenticated by an X.509 AAA certificate. The strong EAP-TTLS tunnel protects the ensuing weak client authentication based on EAP-MD5. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 1.1 client-server interface. +The IMC and IMV communicate using the IF-M protocol defined by RFC 5792 PA-TNC. +
carol passes the health test and dave fails. Based on these measurements carol is authenticated successfully and is granted access to the subnet behind moon whereas dave fails the layered EAP authentication and is rejected. diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/evaltest.dat b/testing/tests/tnc/tnccs-11-radius-block/evaltest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/evaltest.dat rename to testing/tests/tnc/tnccs-11-radius-block/evaltest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/clients.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/clients.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/clients.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/clients.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/dictionary b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/dictionary similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/dictionary rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/dictionary diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/dictionary.tnc b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/dictionary.tnc similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/dictionary.tnc rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/dictionary.tnc diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/eap.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/eap.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/eap.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/eap.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/proxy.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/proxy.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/proxy.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/proxy.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/radiusd.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/radiusd.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/radiusd.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/radiusd.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/sites-available/default b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/sites-available/default similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/sites-available/default rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/sites-available/default diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel-second b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel-second similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel-second rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/sites-available/inner-tunnel-second diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/users b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/users similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/alice/etc/raddb/users rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/raddb/users diff --git a/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/strongswan.conf new file mode 100644 index 000000000..62bcbffa6 --- /dev/null +++ b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/strongswan.conf @@ -0,0 +1,5 @@ +# /etc/strongswan.conf - strongSwan configuration file + +libimcv { + debug_level = 3 +} diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/tnc/log4cxx.properties diff --git a/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/tnc_config b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/tnc_config new file mode 100644 index 000000000..5028bc8c9 --- /dev/null +++ b/testing/tests/tnc/tnccs-11-radius-block/hosts/alice/etc/tnc_config @@ -0,0 +1,3 @@ +#IMV configuration file for strongSwan client + +IMV "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imv-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/carol/etc/tnc_config rename to testing/tests/tnc/tnccs-11-radius-block/hosts/carol/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/tnc_config rename to testing/tests/tnc/tnccs-11-radius-block/hosts/dave/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/init.d/iptables b/testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/init.d/iptables similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/init.d/iptables rename to testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/init.d/iptables diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius-block/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/posttest.dat b/testing/tests/tnc/tnccs-11-radius-block/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/posttest.dat rename to testing/tests/tnc/tnccs-11-radius-block/posttest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/pretest.dat b/testing/tests/tnc/tnccs-11-radius-block/pretest.dat similarity index 68% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/pretest.dat rename to testing/tests/tnc/tnccs-11-radius-block/pretest.dat index dc7d5934e..49cc2e2de 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/pretest.dat +++ b/testing/tests/tnc/tnccs-11-radius-block/pretest.dat @@ -3,12 +3,10 @@ carol::/etc/init.d/iptables start 2> /dev/null dave::/etc/init.d/iptables start 2> /dev/null alice::ln -s /etc/raddb/sites-available/inner-tunnel-second /etc/raddb/sites-enabled/inner-tunnel-second alice::cat /etc/raddb/sites-enabled/inner-tunnel-second -alice::/etc/init.d/radiusd start -carol::cat /etc/tnc/dummyimc.file -dave::cat /etc/tnc/dummyimc.file +alice::LEAK_DETECTIVE_DISABLE=1 LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.properties radiusd moon::ipsec start -carol::ipsec start -dave::ipsec start +carol::LEAK_DETECTIVE_DISABLE=1 ipsec start +dave::LEAK_DETECTIVE_DISABLE=1 ipsec start carol::sleep 1 carol::ipsec up home dave::ipsec up home diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/test.conf b/testing/tests/tnc/tnccs-11-radius-block/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/test.conf rename to testing/tests/tnc/tnccs-11-radius-block/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/description.txt b/testing/tests/tnc/tnccs-11-radius/description.txt similarity index 76% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/description.txt rename to testing/tests/tnc/tnccs-11-radius/description.txt index 69ed1601d..2d66d3e3e 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius/description.txt +++ b/testing/tests/tnc/tnccs-11-radius/description.txt @@ -6,6 +6,7 @@ the FreeRADIUS server alice authenticated by an X.509 AAA certificate. The strong EAP-TTLS tunnel protects the ensuing weak client authentication based on EAP-MD5. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 1.1 client-server interface. -carol passes the health test and dave fails. Based on these measurements exchanged -via the IF-M (RFC 5792 PA-TNC) protocol, the clients are connected by gateway moon -to the "rw-allow" and "rw-isolate" subnets, respectively. +The IMC and IMV communicate using the IF-M protocol defined by RFC 5792 PA-TNC. +
+carol passes the health test and dave fails. Based on these measurements the clients +are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, respectively. diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/evaltest.dat b/testing/tests/tnc/tnccs-11-radius/evaltest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/evaltest.dat rename to testing/tests/tnc/tnccs-11-radius/evaltest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/clients.conf b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/clients.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/clients.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/clients.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/dictionary b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/dictionary similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/dictionary rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/dictionary diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/dictionary.tnc b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/dictionary.tnc similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/dictionary.tnc rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/dictionary.tnc diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/eap.conf b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/eap.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/eap.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/eap.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/proxy.conf b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/proxy.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/proxy.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/proxy.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/radiusd.conf b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/radiusd.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/radiusd.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/radiusd.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/sites-available/default b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/sites-available/default similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/sites-available/default rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/sites-available/default diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel-second b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel-second similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel-second rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/sites-available/inner-tunnel-second diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/users b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/users similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/raddb/users rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/raddb/users diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/strongswan.conf diff --git a/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/tnc/log4cxx.properties new file mode 100644 index 000000000..2bdc6e4de --- /dev/null +++ b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/tnc/log4cxx.properties @@ -0,0 +1,15 @@ +# Set root logger level to DEBUG and its appenders to A1 and A2. +log4j.rootLogger=DEBUG, A1, A2 + +# A1 is set to be a ConsoleAppender. +log4j.appender.A1=org.apache.log4j.ConsoleAppender +log4j.appender.A1.layout=org.apache.log4j.PatternLayout +log4j.appender.A1.layout.ConversionPattern=[FHH] %m%n + +# A2 is set to be a SyslogAppender +log4j.appender.A2=org.apache.log4j.net.SyslogAppender +log4j.appender.A2.Facility=DAEMON +log4j.appender.A2.SyslogHost=localhost +log4j.appender.A2.Threshold=DEBUG +log4j.appender.A2.layout=org.apache.log4j.PatternLayout +log4j.appender.A2.layout.ConversionPattern=[FHH] %m%n diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/tnc_config b/testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/alice/etc/tnc_config rename to testing/tests/tnc/tnccs-11-radius/hosts/alice/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/ipsec.conf index 9cf2b43c4..a639b0426 100755 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/carol/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/strongswan.conf similarity index 85% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/strongswan.conf index 6a12318db..f6dc2dcbc 100644 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/strongswan.conf @@ -3,9 +3,12 @@ charon { load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-11 updown multiple_authentication=no +} + +libimcv { plugins { - eap-tnc { - protocol = tnccs-1.1 + imc-test { + command = allow } } } diff --git a/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-11-radius/hosts/carol/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/ipsec.conf index 998e6c2e5..5da78b4ab 100755 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/hosts/dave/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/strongswan.conf diff --git a/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-11-radius/hosts/dave/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/init.d/iptables b/testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/init.d/iptables similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/init.d/iptables rename to testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/init.d/iptables diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11-radius/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/posttest.dat b/testing/tests/tnc/tnccs-11-radius/posttest.dat similarity index 88% rename from testing/tests/ikev2/rw-eap-tnc-11-radius-block/posttest.dat rename to testing/tests/tnc/tnccs-11-radius/posttest.dat index 132752119..86bd89dea 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius-block/posttest.dat +++ b/testing/tests/tnc/tnccs-11-radius/posttest.dat @@ -1,7 +1,7 @@ moon::ipsec stop carol::ipsec stop dave::ipsec stop -alice::/etc/init.d/radiusd stop +alice::killall radiusd alice::rm /etc/raddb/sites-enabled/inner-tunnel-second moon::/etc/init.d/iptables stop 2> /dev/null carol::/etc/init.d/iptables stop 2> /dev/null diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/pretest.dat b/testing/tests/tnc/tnccs-11-radius/pretest.dat similarity index 90% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/pretest.dat rename to testing/tests/tnc/tnccs-11-radius/pretest.dat index b663661e3..b5d284278 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11-radius/pretest.dat +++ b/testing/tests/tnc/tnccs-11-radius/pretest.dat @@ -7,8 +7,6 @@ alice::LEAK_DETECTIVE_DISABLE=1 LOG4CXX_CONFIGURATION=/etc/tnc/log4cxx.propertie alice::cat /etc/tnc_config carol::cat /etc/tnc_config dave::cat /etc/tnc_config -carol::cat /etc/tnc/dummyimc.file -dave::cat /etc/tnc/dummyimc.file moon::ipsec start carol::LEAK_DETECTIVE_DISABLE=1 ipsec start dave::LEAK_DETECTIVE_DISABLE=1 ipsec start diff --git a/testing/tests/ikev2/rw-eap-tnc-11-radius/test.conf b/testing/tests/tnc/tnccs-11-radius/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11-radius/test.conf rename to testing/tests/tnc/tnccs-11-radius/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11/description.txt b/testing/tests/tnc/tnccs-11/description.txt similarity index 86% rename from testing/tests/ikev2/rw-eap-tnc-11/description.txt rename to testing/tests/tnc/tnccs-11/description.txt index 4b4808c94..d6a3ba283 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11/description.txt +++ b/testing/tests/tnc/tnccs-11/description.txt @@ -3,6 +3,8 @@ using EAP-TTLS authentication only with the gateway presenting a server certific the clients doing EAP-MD5 password-based authentication. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 1.1 client-server interface. +The IMC and IMV communicate using the IF-M protocol defined by RFC 5792 PA-TNC. +
carol passes the health test and dave fails. Based on these measurements the clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, respectively. diff --git a/testing/tests/tnc/tnccs-11/evaltest.dat b/testing/tests/tnc/tnccs-11/evaltest.dat new file mode 100644 index 000000000..a02755148 --- /dev/null +++ b/testing/tests/tnc/tnccs-11/evaltest.dat @@ -0,0 +1,19 @@ +carol::cat /var/log/daemon.log::TNCCS-Recommendation.*allow::YES +carol::cat /var/log/daemon.log::EAP method EAP_TTLS succeeded, MSK established ::YES +carol::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with EAP successful::YES +carol::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.100/32 === 10.1.0.0/28::YES +dave::cat /var/log/daemon.log::TNCCS-Recommendation.*isolate::YES +dave::cat /var/log/daemon.log::EAP method EAP_TTLS succeeded, MSK established ::YES +dave::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with EAP successful::YES +dave::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.200/32 === 10.1.0.16/28::YES +moon::cat /var/log/daemon.log::added group membership 'allow'::YES +moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES +moon::cat /var/log/daemon.log::added group membership 'isolate'::YES +moon::cat /var/log/daemon.log::authentication of 'dave@strongswan.org' with EAP successful::YES +moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES +moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES +carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES +carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO +dave::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES +dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_VENUS: icmp_seq=1::NO + diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-11/hosts/carol/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11/hosts/carol/etc/ipsec.conf index c19192dae..105fcbec6 100755 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11/hosts/carol/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-11/hosts/carol/etc/strongswan.conf similarity index 79% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11/hosts/carol/etc/strongswan.conf index c12143cb1..f6dc2dcbc 100644 --- a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-11/hosts/carol/etc/strongswan.conf @@ -4,3 +4,11 @@ charon { load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-11 updown multiple_authentication=no } + +libimcv { + plugins { + imc-test { + command = allow + } + } +} diff --git a/testing/tests/tnc/tnccs-11/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-11/hosts/carol/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-11/hosts/carol/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-11/hosts/dave/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11/hosts/dave/etc/ipsec.conf index 7d5ea8b83..97f322c28 100755 --- a/testing/tests/ikev2/rw-eap-tnc-11/hosts/dave/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11/hosts/dave/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-11/hosts/dave/etc/strongswan.conf similarity index 69% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-11/hosts/dave/etc/strongswan.conf index b2aa2806a..0a132cae3 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-11/hosts/dave/etc/strongswan.conf @@ -1,11 +1,14 @@ # /etc/strongswan.conf - strongSwan configuration file charon { - load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-20 updown + load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-11 updown multiple_authentication=no +} + +libimcv { plugins { - eap-tnc { - protocol = tnccs-2.0 + imc-test { + command = isolate } } } diff --git a/testing/tests/tnc/tnccs-11/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-11/hosts/dave/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-11/hosts/dave/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-11/hosts/moon/etc/ipsec.conf similarity index 95% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-11/hosts/moon/etc/ipsec.conf index 50514c99f..997db0df7 100755 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-11/hosts/moon/etc/ipsec.conf @@ -3,7 +3,7 @@ config setup strictcrlpolicy=no plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imv 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-11/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-11/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/tnc/tnccs-11/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-11/hosts/moon/etc/strongswan.conf new file mode 100644 index 000000000..4565c2d01 --- /dev/null +++ b/testing/tests/tnc/tnccs-11/hosts/moon/etc/strongswan.conf @@ -0,0 +1,21 @@ +# /etc/strongswan.conf - strongSwan configuration file + +charon { + load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-ttls eap-md5 eap-tnc tnccs-11 tnc-imv updown + multiple_authentication=no + plugins { + eap-ttls { + phase2_method = md5 + phase2_piggyback = yes + phase2_tnc = yes + } + } +} + +libimcv { + plugins { + imv-test { + rounds = 1 + } + } +} diff --git a/testing/tests/tnc/tnccs-11/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-11/hosts/moon/etc/tnc_config new file mode 100644 index 000000000..5028bc8c9 --- /dev/null +++ b/testing/tests/tnc/tnccs-11/hosts/moon/etc/tnc_config @@ -0,0 +1,3 @@ +#IMV configuration file for strongSwan client + +IMV "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imv-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/posttest.dat b/testing/tests/tnc/tnccs-11/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/posttest.dat rename to testing/tests/tnc/tnccs-11/posttest.dat diff --git a/testing/tests/tnc/tnccs-11/pretest.dat b/testing/tests/tnc/tnccs-11/pretest.dat new file mode 100644 index 000000000..dd729cb0b --- /dev/null +++ b/testing/tests/tnc/tnccs-11/pretest.dat @@ -0,0 +1,13 @@ +moon::/etc/init.d/iptables start 2> /dev/null +carol::/etc/init.d/iptables start 2> /dev/null +dave::/etc/init.d/iptables start 2> /dev/null +moon::cat /etc/tnc_config +carol::cat /etc/tnc_config +dave::cat /etc/tnc_config +moon::LEAK_DETECTIVE_DISABLE=1 ipsec start +carol::LEAK_DETECTIVE_DISABLE=1 ipsec start +dave::LEAK_DETECTIVE_DISABLE=1 ipsec start +carol::sleep 1 +carol::ipsec up home +dave::ipsec up home +dave::sleep 1 diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/test.conf b/testing/tests/tnc/tnccs-11/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/test.conf rename to testing/tests/tnc/tnccs-11/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/description.txt b/testing/tests/tnc/tnccs-20-block/description.txt similarity index 83% rename from testing/tests/ikev2/rw-eap-tnc-20-block/description.txt rename to testing/tests/tnc/tnccs-20-block/description.txt index c7422aa46..d240d5749 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/description.txt +++ b/testing/tests/tnc/tnccs-20-block/description.txt @@ -3,7 +3,8 @@ using EAP-TTLS authentication only with the gateway presenting a server certific the clients doing EAP-MD5 password-based authentication. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 2.0 client-server interface -compliant with RFC 5793 PB-TNC. +compliant with RFC 5793 PB-TNC. The IMC and IMV communicate using the IF-M +protocol defined by RFC 5792 PA-TNC.
carol passes the health test and dave fails. Based on these measurements carol is authenticated successfully and is granted access to the subnet behind diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/evaltest.dat b/testing/tests/tnc/tnccs-20-block/evaltest.dat similarity index 75% rename from testing/tests/ikev2/rw-eap-tnc-20-block/evaltest.dat rename to testing/tests/tnc/tnccs-20-block/evaltest.dat index e3c482441..f1753c208 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/evaltest.dat +++ b/testing/tests/tnc/tnccs-20-block/evaltest.dat @@ -5,10 +5,8 @@ carol::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.100/3 dave::cat /var/log/daemon.log::PB-TNC access recommendation is 'Access Denied'::YES dave::cat /var/log/daemon.log::received EAP_FAILURE, EAP authentication failed::YES dave::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.200/32 === 10.1.0.0/16::NO -moon::cat /var/log/auth.log::policy enforced on peer 'carol@strongswan.org' is 'allow'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'allow'::YES -moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES -moon::cat /var/log/auth.log::policy enforced on peer 'dave@strongswan.org' is 'no access'::YES +moon::cat /var/log/daemon.log::added group membership 'allow'::YES +moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES moon::cat /var/log/daemon.log::EAP method EAP_TTLS failed for peer dave@strongswan.org::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_VENUS: icmp_seq=1::NO diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-block/hosts/carol/etc/ipsec.conf index c19192dae..105fcbec6 100755 --- a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-block/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/strongswan.conf similarity index 84% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-block/hosts/carol/etc/strongswan.conf index 1a39b8c57..c25ff96b0 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/carol/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/strongswan.conf @@ -12,3 +12,11 @@ charon { } } } + +libimcv { + plugins { + imc-test { + command = allow + } + } +} diff --git a/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-20-block/hosts/carol/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-block/hosts/dave/etc/ipsec.conf index 7d5ea8b83..97f322c28 100755 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imc 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-block/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-block/hosts/dave/etc/strongswan.conf diff --git a/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-20-block/hosts/dave/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-block/hosts/moon/etc/ipsec.conf index 6747b4a4a..106cde446 100755 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/ipsec.conf @@ -3,7 +3,7 @@ config setup strictcrlpolicy=no plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 3, imv 3" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-block/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-block/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-block/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/tnc_config new file mode 100644 index 000000000..5028bc8c9 --- /dev/null +++ b/testing/tests/tnc/tnccs-20-block/hosts/moon/etc/tnc_config @@ -0,0 +1,3 @@ +#IMV configuration file for strongSwan client + +IMV "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imv-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/posttest.dat b/testing/tests/tnc/tnccs-20-block/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/posttest.dat rename to testing/tests/tnc/tnccs-20-block/posttest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/pretest.dat b/testing/tests/tnc/tnccs-20-block/pretest.dat similarity index 83% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/pretest.dat rename to testing/tests/tnc/tnccs-20-block/pretest.dat index ce897d181..c332f131b 100644 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/pretest.dat +++ b/testing/tests/tnc/tnccs-20-block/pretest.dat @@ -4,8 +4,6 @@ dave::/etc/init.d/iptables start 2> /dev/null moon::cat /etc/tnc_config carol::cat /etc/tnc_config dave::cat /etc/tnc_config -carol::cat /etc/tnc/dummyimc.file -dave::cat /etc/tnc/dummyimc.file moon::ipsec start carol::ipsec start dave::ipsec start diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/test.conf b/testing/tests/tnc/tnccs-20-block/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/test.conf rename to testing/tests/tnc/tnccs-20-block/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/description.txt b/testing/tests/tnc/tnccs-20-fhh/description.txt similarity index 81% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/description.txt rename to testing/tests/tnc/tnccs-20-fhh/description.txt index 796b8d27e..798ba0034 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-fhh/description.txt +++ b/testing/tests/tnc/tnccs-20-fhh/description.txt @@ -3,8 +3,8 @@ using EAP-TTLS authentication only with the gateway presenting a server certific the clients doing EAP-MD5 password-based authentication. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the TNCCS 2.0 client-server interface -compliant with RFC 5793 PB-TNC. Th Dummy IMC and IMV from the TNC@FHH project is -used which communicate with a proprietary protocol. +compliant with RFC 5793 PB-TNC. The Dummy IMC and IMV from the TNC@FHH project are +used which communicate over a proprietary protocol.
carol passes the health test and dave fails. Based on these measurements the clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/evaltest.dat b/testing/tests/tnc/tnccs-20-fhh/evaltest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/evaltest.dat rename to testing/tests/tnc/tnccs-20-fhh/evaltest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/tnc/dummyimc.file b/testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/tnc/dummyimc.file similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-11/hosts/carol/etc/tnc/dummyimc.file rename to testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/tnc/dummyimc.file diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/tnc/log4cxx.properties diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/carol/etc/tnc_config rename to testing/tests/tnc/tnccs-20-fhh/hosts/carol/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/tnc/dummyimc.file b/testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/tnc/dummyimc.file similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/tnc/dummyimc.file rename to testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/tnc/dummyimc.file diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/tnc/log4cxx.properties diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/dave/etc/tnc_config rename to testing/tests/tnc/tnccs-20-fhh/hosts/dave/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc/dummyimv.policy b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc/dummyimv.policy similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc/dummyimv.policy rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc/dummyimv.policy diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc/hostscannerimv.policy b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc/hostscannerimv.policy similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc/hostscannerimv.policy rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc/hostscannerimv.policy diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc/log4cxx.properties b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc/log4cxx.properties similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc/log4cxx.properties rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc/log4cxx.properties diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/hosts/moon/etc/tnc_config rename to testing/tests/tnc/tnccs-20-fhh/hosts/moon/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/posttest.dat b/testing/tests/tnc/tnccs-20-fhh/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/posttest.dat rename to testing/tests/tnc/tnccs-20-fhh/posttest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-20-fhh/pretest.dat b/testing/tests/tnc/tnccs-20-fhh/pretest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-fhh/pretest.dat rename to testing/tests/tnc/tnccs-20-fhh/pretest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/test.conf b/testing/tests/tnc/tnccs-20-fhh/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/test.conf rename to testing/tests/tnc/tnccs-20-fhh/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/description.txt b/testing/tests/tnc/tnccs-20-tls/description.txt similarity index 80% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/description.txt rename to testing/tests/tnc/tnccs-20-tls/description.txt index 54590a951..a520b40d2 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/description.txt +++ b/testing/tests/tnc/tnccs-20-tls/description.txt @@ -2,7 +2,8 @@ The roadwarriors carol and dave set up a connection each to gatewa both ends doing certificate-based EAP-TLS authentication only. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 2.0 client-server interface -compliant with RFC 5793 PB-TNC. +compliant with RFC 5793 PB-TNC. The IMC and IMV communicate using the IF-M +protocol defined by RFC 5792 PA-TNC.
carol passes the health test and dave fails. Based on these measurements the clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/evaltest.dat b/testing/tests/tnc/tnccs-20-tls/evaltest.dat similarity index 76% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/evaltest.dat rename to testing/tests/tnc/tnccs-20-tls/evaltest.dat index c871bb6da..bbc0603b6 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/evaltest.dat +++ b/testing/tests/tnc/tnccs-20-tls/evaltest.dat @@ -6,11 +6,9 @@ dave::cat /var/log/daemon.log::PB-TNC access recommendation is 'Quarantined'::YE dave::cat /var/log/daemon.log::EAP method EAP_TTLS succeeded, MSK established ::YES dave::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with EAP successful::YES dave::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.200/32 === 10.1.0.16/28::YES -moon::cat /var/log/auth.log::policy enforced on peer 'carol@strongswan.org' is 'allow'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'allow'::YES -moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES -moon::cat /var/log/auth.log::policy enforced on peer 'dave@strongswan.org' is 'isolate'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'isolate'::YES +moon::cat /var/log/daemon.log::added group membership 'allow'::YES +moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES +moon::cat /var/log/daemon.log::added group membership 'isolate'::YES moon::cat /var/log/daemon.log::authentication of 'dave@strongswan.org' with EAP successful::YES moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/ipsec.conf index 1b6274215..fe26aaede 100755 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/carol/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 2, imc 2" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/strongswan.conf similarity index 83% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/strongswan.conf index 79f166da8..c001e47e5 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/strongswan.conf @@ -10,6 +10,10 @@ charon { } } -imc-test { - command = isolate +libimcv { + plugins { + imc-test { + command = allow + } + } } diff --git a/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-20-tls/hosts/carol/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/ipsec.conf similarity index 93% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/ipsec.conf index 54c06b12e..e1cfd14bb 100755 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/ipsec.conf @@ -2,7 +2,7 @@ config setup plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 2, imc 2" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/strongswan.conf similarity index 82% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/strongswan.conf index b2aa2806a..ef052cefa 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/dave/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/strongswan.conf @@ -9,3 +9,11 @@ charon { } } } + +libimcv { + plugins { + imc-test { + command = isolate + } + } +} diff --git a/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-20-tls/hosts/dave/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/ipsec.conf similarity index 95% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/ipsec.conf index 50514c99f..80bcb5a5a 100755 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/ipsec.conf +++ b/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/ipsec.conf @@ -3,7 +3,7 @@ config setup strictcrlpolicy=no plutostart=no - charondebug="tls 2, tnc 3" + charondebug="tnc 2, imv 2" conn %default ikelifetime=60m diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/tnc_config new file mode 100644 index 000000000..5028bc8c9 --- /dev/null +++ b/testing/tests/tnc/tnccs-20-tls/hosts/moon/etc/tnc_config @@ -0,0 +1,3 @@ +#IMV configuration file for strongSwan client + +IMV "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imv-test.so diff --git a/testing/tests/ikev2/rw-eap-tnc-20/posttest.dat b/testing/tests/tnc/tnccs-20-tls/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/posttest.dat rename to testing/tests/tnc/tnccs-20-tls/posttest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-20-tls/pretest.dat b/testing/tests/tnc/tnccs-20-tls/pretest.dat similarity index 83% rename from testing/tests/ikev2/rw-eap-tnc-20-tls/pretest.dat rename to testing/tests/tnc/tnccs-20-tls/pretest.dat index ce897d181..c332f131b 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-tls/pretest.dat +++ b/testing/tests/tnc/tnccs-20-tls/pretest.dat @@ -4,8 +4,6 @@ dave::/etc/init.d/iptables start 2> /dev/null moon::cat /etc/tnc_config carol::cat /etc/tnc_config dave::cat /etc/tnc_config -carol::cat /etc/tnc/dummyimc.file -dave::cat /etc/tnc/dummyimc.file moon::ipsec start carol::ipsec start dave::ipsec start diff --git a/testing/tests/ikev2/rw-eap-tnc-20/test.conf b/testing/tests/tnc/tnccs-20-tls/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/test.conf rename to testing/tests/tnc/tnccs-20-tls/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-20/description.txt b/testing/tests/tnc/tnccs-20/description.txt similarity index 90% rename from testing/tests/ikev2/rw-eap-tnc-20/description.txt rename to testing/tests/tnc/tnccs-20/description.txt index 410ccca84..00c88eaa6 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20/description.txt +++ b/testing/tests/tnc/tnccs-20/description.txt @@ -3,8 +3,8 @@ using EAP-TTLS authentication only with the gateway presenting a server certific the clients doing EAP-MD5 password-based authentication. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the TNCCS 2.0 client-server interface -compliant with RFC 5793 PB-TNC. The IMC and IMV communicate using the RFC 5792 PA-TNC -protocol. +compliant with RFC 5793 PB-TNC. The IMC and IMV communicate using the IF-M +protocol defined by RFC 5792 PA-TNC.
carol passes the health test and dave fails. Based on these measurements the clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, diff --git a/testing/tests/ikev2/rw-eap-tnc-20/evaltest.dat b/testing/tests/tnc/tnccs-20/evaltest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/evaltest.dat rename to testing/tests/tnc/tnccs-20/evaltest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-20/hosts/carol/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20/hosts/carol/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20/hosts/carol/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/carol/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20/hosts/carol/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-20/hosts/carol/etc/strongswan.conf similarity index 83% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20/hosts/carol/etc/strongswan.conf index 7ee4cbc05..c001e47e5 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-20/hosts/carol/etc/strongswan.conf @@ -10,6 +10,10 @@ charon { } } -imc-test { - command = allow +libimcv { + plugins { + imc-test { + command = allow + } + } } diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-20/hosts/carol/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/carol/etc/tnc_config rename to testing/tests/tnc/tnccs-20/hosts/carol/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-20/hosts/dave/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20/hosts/dave/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20/hosts/dave/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/dave/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20/hosts/dave/etc/ipsec.secrets diff --git a/testing/tests/tnc/tnccs-20/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-20/hosts/dave/etc/strongswan.conf new file mode 100644 index 000000000..ef052cefa --- /dev/null +++ b/testing/tests/tnc/tnccs-20/hosts/dave/etc/strongswan.conf @@ -0,0 +1,19 @@ +# /etc/strongswan.conf - strongSwan configuration file + +charon { + load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-20 updown + multiple_authentication=no + plugins { + eap-tnc { + protocol = tnccs-2.0 + } + } +} + +libimcv { + plugins { + imc-test { + command = isolate + } + } +} diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-20/hosts/dave/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/dave/etc/tnc_config rename to testing/tests/tnc/tnccs-20/hosts/dave/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-20/hosts/moon/etc/ipsec.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/ipsec.conf rename to testing/tests/tnc/tnccs-20/hosts/moon/etc/ipsec.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-20/hosts/moon/etc/ipsec.secrets similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/ipsec.secrets rename to testing/tests/tnc/tnccs-20/hosts/moon/etc/ipsec.secrets diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-20/hosts/moon/etc/strongswan.conf similarity index 87% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-20/hosts/moon/etc/strongswan.conf index 2bc6bec54..eb615ff23 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/strongswan.conf +++ b/testing/tests/tnc/tnccs-20/hosts/moon/etc/strongswan.conf @@ -15,6 +15,10 @@ charon { } } -imv-test { - rounds = 1 +libimcv { + plugins { + imv-test { + rounds = 1 + } + } } diff --git a/testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-20/hosts/moon/etc/tnc_config similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/hosts/moon/etc/tnc_config rename to testing/tests/tnc/tnccs-20/hosts/moon/etc/tnc_config diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/posttest.dat b/testing/tests/tnc/tnccs-20/posttest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/posttest.dat rename to testing/tests/tnc/tnccs-20/posttest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-20/pretest.dat b/testing/tests/tnc/tnccs-20/pretest.dat similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-20/pretest.dat rename to testing/tests/tnc/tnccs-20/pretest.dat diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/test.conf b/testing/tests/tnc/tnccs-20/test.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/test.conf rename to testing/tests/tnc/tnccs-20/test.conf diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/description.txt b/testing/tests/tnc/tnccs-dynamic/description.txt similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/description.txt rename to testing/tests/tnc/tnccs-dynamic/description.txt diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/evaltest.dat b/testing/tests/tnc/tnccs-dynamic/evaltest.dat similarity index 84% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/evaltest.dat rename to testing/tests/tnc/tnccs-dynamic/evaltest.dat index 593ac4505..5cc395ef8 100644 --- a/testing/tests/ikev2/rw-eap-tnc-dynamic/evaltest.dat +++ b/testing/tests/tnc/tnccs-dynamic/evaltest.dat @@ -9,15 +9,13 @@ dave::cat /var/log/daemon.log::CHILD_SA home{1} established.*TS 192.168.0.200/32 moon::cat /var/log/daemon.log::TNCCS 1.1 protocol detected dynamically::YES moon::cat /var/log/daemon.log::assigned TNCCS Connection ID 1::YES moon::cat /var/log/daemon.log::final recommendation is 'allow' and evaluation is 'compliant'::YES -moon::cat /var/log/auth.log::policy enforced on peer 'carol@strongswan.org' is 'allow'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'allow'::YES +moon::cat /var/log/daemon.log::added group membership 'allow'::YES moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES moon::cat /var/log/daemon.log::removed TNCCS Connection ID 1::YES moon::cat /var/log/daemon.log::TNCCS 2.0 protocol detected dynamically::YES moon::cat /var/log/daemon.log::assigned TNCCS Connection ID 2::YES moon::cat /var/log/daemon.log::final recommendation is 'isolate' and evaluation is 'non-compliant minor'::YES -moon::cat /var/log/auth.log::policy enforced on peer 'dave@strongswan.org' is 'isolate'::YES -moon::cat /var/log/daemon.log::policy enforcement point added group membership 'isolate'::YES +moon::cat /var/log/daemon.log::added group membership 'isolate'::YES moon::cat /var/log/daemon.log::authentication of 'dave@strongswan.org' with EAP successful::YES moon::cat /var/log/daemon.log::removed TNCCS Connection ID 2::YES moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/ipsec.conf b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/ipsec.conf new file mode 100755 index 000000000..105fcbec6 --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/ipsec.conf @@ -0,0 +1,23 @@ +# /etc/ipsec.conf - strongSwan IPsec configuration file + +config setup + plutostart=no + charondebug="tnc 3, imc 3" + +conn %default + ikelifetime=60m + keylife=20m + rekeymargin=3m + keyingtries=1 + keyexchange=ikev2 + +conn home + left=PH_IP_CAROL + leftid=carol@strongswan.org + leftauth=eap + leftfirewall=yes + right=PH_IP_MOON + rightid=@moon.strongswan.org + rightsendcert=never + rightsubnet=10.1.0.0/16 + auto=add diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/ipsec.secrets b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/ipsec.secrets new file mode 100644 index 000000000..74942afda --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/ipsec.secrets @@ -0,0 +1,3 @@ +# /etc/ipsec.secrets - strongSwan IPsec secrets file + +carol@strongswan.org : EAP "Ar3etTnp" diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/strongswan.conf b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/strongswan.conf new file mode 100644 index 000000000..6ef71ce6a --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/strongswan.conf @@ -0,0 +1,19 @@ +# /etc/strongswan.conf - strongSwan configuration file + +charon { + load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-11 updown + multiple_authentication=no + plugins { + eap-tnc { + protocol = tnccs-1.1 + } + } +} + +libimcv { + plugins { + imc-test { + command = allow + } + } +} diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/tnc_config b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/carol/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/ipsec.conf b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/ipsec.conf new file mode 100755 index 000000000..97f322c28 --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/ipsec.conf @@ -0,0 +1,23 @@ +# /etc/ipsec.conf - strongSwan IPsec configuration file + +config setup + plutostart=no + charondebug="tnc 3, imc 3" + +conn %default + ikelifetime=60m + keylife=20m + rekeymargin=3m + keyingtries=1 + keyexchange=ikev2 + +conn home + left=PH_IP_DAVE + leftid=dave@strongswan.org + leftauth=eap + leftfirewall=yes + right=PH_IP_MOON + rightid=@moon.strongswan.org + rightsendcert=never + rightsubnet=10.1.0.0/16 + auto=add diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/ipsec.secrets b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/ipsec.secrets new file mode 100644 index 000000000..5496df7ad --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/ipsec.secrets @@ -0,0 +1,3 @@ +# /etc/ipsec.secrets - strongSwan IPsec secrets file + +dave@strongswan.org : EAP "W7R0g3do" diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/strongswan.conf b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/strongswan.conf new file mode 100644 index 000000000..ef052cefa --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/strongswan.conf @@ -0,0 +1,19 @@ +# /etc/strongswan.conf - strongSwan configuration file + +charon { + load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnccs-20 updown + multiple_authentication=no + plugins { + eap-tnc { + protocol = tnccs-2.0 + } + } +} + +libimcv { + plugins { + imc-test { + command = isolate + } + } +} diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/tnc_config b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/tnc_config new file mode 100644 index 000000000..a39922ddb --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/dave/etc/tnc_config @@ -0,0 +1,3 @@ +#IMC configuration file for strongSwan client + +IMC "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imc-test.so diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/ipsec.conf b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/ipsec.conf new file mode 100755 index 000000000..997db0df7 --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/ipsec.conf @@ -0,0 +1,36 @@ +# /etc/ipsec.conf - strongSwan IPsec configuration file + +config setup + strictcrlpolicy=no + plutostart=no + charondebug="tnc 3, imv 3" + +conn %default + ikelifetime=60m + keylife=20m + rekeymargin=3m + keyingtries=1 + keyexchange=ikev2 + +conn rw-allow + rightgroups=allow + leftsubnet=10.1.0.0/28 + also=rw-eap + auto=add + +conn rw-isolate + rightgroups=isolate + leftsubnet=10.1.0.16/28 + also=rw-eap + auto=add + +conn rw-eap + left=PH_IP_MOON + leftcert=moonCert.pem + leftid=@moon.strongswan.org + leftauth=eap-ttls + leftfirewall=yes + rightauth=eap-ttls + rightid=*@strongswan.org + rightsendcert=never + right=%any diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/ipsec.secrets b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/ipsec.secrets new file mode 100644 index 000000000..2e277ccb0 --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/ipsec.secrets @@ -0,0 +1,6 @@ +# /etc/ipsec.secrets - strongSwan IPsec secrets file + +: RSA moonKey.pem + +carol@strongswan.org : EAP "Ar3etTnp" +dave@strongswan.org : EAP "W7R0g3do" diff --git a/testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/strongswan.conf b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/strongswan.conf similarity index 100% rename from testing/tests/ikev2/rw-eap-tnc-dynamic/hosts/moon/etc/strongswan.conf rename to testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/strongswan.conf diff --git a/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/tnc_config b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/tnc_config new file mode 100644 index 000000000..5028bc8c9 --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/hosts/moon/etc/tnc_config @@ -0,0 +1,3 @@ +#IMV configuration file for strongSwan client + +IMV "Test" /usr/local/libexec/ipsec/plugins/libstrongswan-imv-test.so diff --git a/testing/tests/tnc/tnccs-dynamic/posttest.dat b/testing/tests/tnc/tnccs-dynamic/posttest.dat new file mode 100644 index 000000000..7cebd7f25 --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/posttest.dat @@ -0,0 +1,6 @@ +moon::ipsec stop +carol::ipsec stop +dave::ipsec stop +moon::/etc/init.d/iptables stop 2> /dev/null +carol::/etc/init.d/iptables stop 2> /dev/null +dave::/etc/init.d/iptables stop 2> /dev/null diff --git a/testing/tests/ikev2/rw-eap-tnc-20-block/pretest.dat b/testing/tests/tnc/tnccs-dynamic/pretest.dat similarity index 74% rename from testing/tests/ikev2/rw-eap-tnc-20-block/pretest.dat rename to testing/tests/tnc/tnccs-dynamic/pretest.dat index ce897d181..a7a3bf412 100644 --- a/testing/tests/ikev2/rw-eap-tnc-20-block/pretest.dat +++ b/testing/tests/tnc/tnccs-dynamic/pretest.dat @@ -4,10 +4,8 @@ dave::/etc/init.d/iptables start 2> /dev/null moon::cat /etc/tnc_config carol::cat /etc/tnc_config dave::cat /etc/tnc_config -carol::cat /etc/tnc/dummyimc.file -dave::cat /etc/tnc/dummyimc.file -moon::ipsec start -carol::ipsec start +moon::LEAK_DETECTIVE_DISABLE=1 ipsec start +carol::LEAK_DETECTIVE_DISABLE=1 ipsec start dave::ipsec start carol::sleep 1 carol::ipsec up home diff --git a/testing/tests/tnc/tnccs-dynamic/test.conf b/testing/tests/tnc/tnccs-dynamic/test.conf new file mode 100644 index 000000000..e28b8259b --- /dev/null +++ b/testing/tests/tnc/tnccs-dynamic/test.conf @@ -0,0 +1,26 @@ +#!/bin/bash +# +# This configuration file provides information on the +# UML instances used for this test + +# All UML instances that are required for this test +# +UMLHOSTS="alice venus moon carol winnetou dave" + +# Corresponding block diagram +# +DIAGRAM="a-v-m-c-w-d.png" + +# UML instances on which tcpdump is to be started +# +TCPDUMPHOSTS="moon" + +# UML instances on which IPsec is started +# Used for IPsec logging purposes +# +IPSECHOSTS="moon carol dave" + +# UML instances on which FreeRadius is started +# +RADIUSHOSTS= +