This commit is contained in:
Andreas Steffen
2007-03-14 14:02:39 +00:00
parent ae21d486c9
commit 3f2cc77ac1
8 changed files with 118 additions and 0 deletions
@@ -0,0 +1,8 @@
By setting <b>strictcrlpolicy=yes</b>, a <b>strict</b> CRL policy is enforced on
both roadwarrior <b>carol</b> and gateway <b>moon</b>. The online certificate status
is checked via the OCSP server <b>winnetou</b> which uses the <b>strongSwan CA</b>'s
private key to sign OCSP responses. A <b>strongswan ca</b> section in ipsec.conf
defines an <b>OCSP URI</b> pointing to <b>winnetou</b>.
<p>
<b>carol</b> can successfully initiate an IPsec connection to <b>moon</b> since
the status of both certificates is <b>good</b>.
@@ -0,0 +1,6 @@
moon::cat /var/log/daemon.log::received valid http response::YES
carol::cat /var/log/daemon.log::received valid http response::YES
moon::cat /var/log/daemon.log::certificate is good::YES
carol::cat /var/log/daemon.log::certificate is good::YES
moon::ipsec status::rw.*ESTABLISHED::YES
carol::ipsec status::home.*ESTABLISHED::YES
@@ -0,0 +1,28 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
config setup
crlcheckinterval=180
strictcrlpolicy=yes
plutostart=no
ca strongswan
cacert=strongswanCert.pem
ocspuri=http://ocsp.strongswan.org:8880
auto=add
conn %default
keyexchange=ikev2
ikelifetime=60m
keylife=20m
rekeymargin=3m
keyingtries=1
conn home
left=PH_IP_CAROL
leftnexthop=%direct
leftcert=carolCert.pem
[email protected]
right=PH_IP_MOON
rightsubnet=10.1.0.0/16
[email protected]
auto=add
@@ -0,0 +1,27 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
config setup
crlcheckinterval=180
strictcrlpolicy=yes
plutostart=no
ca strongswan-ca
cacert=strongswanCert.pem
ocspuri=http://ocsp.strongswan.org:8880
auto=add
conn %default
keyexchange=ikev2
ikelifetime=60m
keylife=20m
rekeymargin=3m
keyingtries=1
conn rw
left=PH_IP_MOON
leftnexthop=%direct
leftcert=moonCert.pem
[email protected]
leftsubnet=10.1.0.0/16
right=%any
auto=add
@@ -0,0 +1,20 @@
#! /bin/sh
# start an OpenSSL-based OCSP server
#
# Copyright (C) 2004 Andreas Steffen
# Zuercher Hochschule Winterthur
#
# This program is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation; either version 2 of the License, or (at your
# option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
#
# This program is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
# for more details.
#
# RCSID $Id: start-ocsp,v 1.3 2005/01/01 18:12:14 as Exp $
cd /etc/openssl
openssl ocsp -index index.txt -CA strongswanCert.pem -port 8880 -rkey strongswanKey.pem -rsigner strongswanCert.pem -resp_no_certs -nmin 5 < /dev/null > /dev/null 2>&1 &
@@ -0,0 +1,3 @@
moon::ipsec stop
carol::ipsec stop
winnetou::killall openssl
@@ -0,0 +1,5 @@
winnetou::/etc/openssl/start-ocsp
moon::ipsec start
carol::ipsec start
carol::sleep 2
carol::ipsec up home
@@ -0,0 +1,21 @@
#!/bin/bash
#
# This configuration file provides information on the
# UML instances used for this test
# All UML instances that are required for this test
#
UMLHOSTS="moon carol winnetou"
# Corresponding block diagram
#
DIAGRAM="m-c-w.png"
# UML instances on which tcpdump is to be started
#
TCPDUMPHOSTS=""
# UML instances on which IPsec is started
# Used for IPsec logging purposes
#
IPSECHOSTS="moon carol"