testing: Distributed openssl-ikev2 scenarios
This commit is contained in:
committed by
Tobias Brunner
parent
f766a7ed49
commit
4df94b56c0
@@ -356,7 +356,7 @@ openssl pkcs12 -export -inkey ${HOST_KEY} -in ${HOST_CERT} -name "sun" \
|
||||
-certpbe aes-128-cbc -macalg sha256 -passout "pass:IxjQVCF3JGI+MoPi" > ${SUN_PKCS12}
|
||||
|
||||
# Put a PKCS#12 copy into the botan/net2net-pkcs12 scenario
|
||||
for t in botan/net2net-pkcs12 openssl-ikev2/net2net-pkcs12
|
||||
for t in botan/net2net-pkcs12
|
||||
do
|
||||
TEST="${TEST_DIR}/${t}"
|
||||
mkdir -p ${TEST}/hosts/moon/${SWANCTL_DIR}/pkcs12
|
||||
@@ -762,13 +762,6 @@ pki --issue --cakey ${CA_KEY} --cacert ${CA_CERT} --crl ${CA_CDP} --type rsa \
|
||||
--outform pem > ${TEST_CERT}
|
||||
cp ${TEST_CERT} ${CA_DIR}/certs/${SERIAL}.pem
|
||||
|
||||
# Put a copy in the openssl-ikev2/critical extension scenario
|
||||
TEST="${TEST_DIR}/openssl-ikev2/critical-extension"
|
||||
mkdir -p ${TEST}/hosts/moon/${SWANCTL_DIR}/rsa
|
||||
mkdir -p ${TEST}/hosts/moon/${SWANCTL_DIR}/x509
|
||||
cp ${TEST_KEY} ${TEST}/hosts/moon/${SWANCTL_DIR}/rsa
|
||||
cp ${TEST_CERT} ${TEST}/hosts/moon/${SWANCTL_DIR}/x509
|
||||
|
||||
# Generate sun certificate with an unsupported critical X.509 extension
|
||||
TEST="${TEST_DIR}/ikev2/critical-extension"
|
||||
TEST_KEY="${TEST}/hosts/sun/${SWANCTL_DIR}/rsa/sunKey.pem"
|
||||
@@ -785,13 +778,6 @@ pki --issue --cakey ${CA_KEY} --cacert ${CA_CERT} --crl ${CA_CDP} --type rsa \
|
||||
--outform pem > ${TEST_CERT}
|
||||
cp ${TEST_CERT} ${CA_DIR}/certs/${SERIAL}.pem
|
||||
|
||||
# Put a copy in the openssl-ikev2/critical extension scenario
|
||||
TEST="${TEST_DIR}/openssl-ikev2/critical-extension"
|
||||
mkdir -p ${TEST}/hosts/sun/${SWANCTL_DIR}/rsa
|
||||
mkdir -p ${TEST}/hosts/sun/${SWANCTL_DIR}/x509
|
||||
cp ${TEST_KEY} ${TEST}/hosts/sun/${SWANCTL_DIR}/rsa
|
||||
cp ${TEST_CERT} ${TEST}/hosts/sun/${SWANCTL_DIR}/x509
|
||||
|
||||
# Generate winnetou server certificate
|
||||
HOST_KEY="${CA_DIR}/winnetouKey.pem"
|
||||
HOST_CERT="${CA_DIR}/winnetouCert.pem"
|
||||
@@ -1153,10 +1139,10 @@ pki --self --type ecdsa --in ${ECDSA_KEY} \
|
||||
--dn "C=CH, O=${PROJECT}, CN=strongSwan EC Root CA" \
|
||||
--outform pem > ${ECDSA_CERT}
|
||||
|
||||
# Put a copy in the openssl-ikev2/ecdsa-certs scenario
|
||||
# Put a copy in the ikev2/ecdsa-certs scenario
|
||||
for t in ecdsa-certs ecdsa-pkcs8
|
||||
do
|
||||
TEST="${TEST_DIR}/openssl-ikev2/${t}"
|
||||
TEST="${TEST_DIR}/ikev2/${t}"
|
||||
for h in moon carol dave
|
||||
do
|
||||
mkdir -p ${TEST}/hosts/${h}/${SWANCTL_DIR}/x509ca
|
||||
@@ -1165,7 +1151,7 @@ do
|
||||
done
|
||||
|
||||
# Generate a moon ECDSA 521 bit certificate
|
||||
TEST="${TEST_DIR}/openssl-ikev2/ecdsa-certs"
|
||||
TEST="${TEST_DIR}/ikev2/ecdsa-certs"
|
||||
MOON_KEY="${TEST}/hosts/moon/${SWANCTL_DIR}/ecdsa/moonKey.pem"
|
||||
MOON_CERT="${TEST}/hosts/moon/${SWANCTL_DIR}/x509/moonCert.pem"
|
||||
CN="moon.strongswan.org"
|
||||
@@ -1207,8 +1193,8 @@ pki --issue --cakey ${ECDSA_KEY} --cacert ${ECDSA_CERT} --type ecdsa \
|
||||
--crl ${ECDSA_CDP} --outform pem > ${DAVE_CERT}
|
||||
cp ${DAVE_CERT} ${ECDSA_DIR}/certs/${SERIAL}.pem
|
||||
|
||||
# Put CA and EE certificate copies in the openssl-ikev2/ecdsa-pkcs8 scenario
|
||||
TEST="${TEST_DIR}/openssl-ikev2/ecdsa-pkcs8"
|
||||
# Put CA and EE certificate copies in the ikev2/ecdsa-pkcs8 scenario
|
||||
TEST="${TEST_DIR}/ikev2/ecdsa-pkcs8"
|
||||
mkdir -p ${TEST}/hosts/moon/${SWANCTL_DIR}/x509
|
||||
mkdir -p ${TEST}/hosts/carol/${SWANCTL_DIR}/x509
|
||||
mkdir -p ${TEST}/hosts/dave/${SWANCTL_DIR}/x509
|
||||
@@ -1419,8 +1405,8 @@ pki --issue --cakey ${SHA3_RSA_KEY} --cacert ${SHA3_RSA_CERT} --type rsa \
|
||||
--crl ${SHA3_RSA_CDP} --digest sha3_256 --outform pem > ${MOON_CERT}
|
||||
cp ${MOON_CERT} ${SHA3_RSA_DIR}/certs/${SERIAL}.pem
|
||||
|
||||
# Put a copy in the botan openssl-ikev2 and wolfssl net2net-sha3-rsa-cert scenarios
|
||||
for d in botan openssl-ikev2 wolfssl
|
||||
# Put a copy in the botan and wolfssl net2net-sha3-rsa-cert scenarios
|
||||
for d in botan wolfssl
|
||||
do
|
||||
TEST="${TEST_DIR}/${d}/net2net-sha3-rsa-cert"
|
||||
cd ${TEST}/hosts/moon/${SWANCTL_DIR}
|
||||
|
||||
-1
@@ -2,5 +2,4 @@
|
||||
|
||||
charon {
|
||||
load = random nonce pem pkcs1 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
multiple_authentication = no
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce pem pkcs1 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce pem pkcs1 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce pem pkcs1 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,2 +0,0 @@
|
||||
*.pem
|
||||
*.p12
|
||||
@@ -1,5 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce aes sha1 sha2 gmp pem pkcs1 hmac kdf x509 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,5 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce aes des sha1 sha2 gmp pem pkcs1 hmac kdf x509 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,5 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce aes sha1 sha2 gmp pem pkcs1 hmac kdf x509 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,5 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce aes des sha1 sha2 gmp pem pkcs1 hmac kdf x509 openssl curl revocation vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,5 +0,0 @@
|
||||
A connection between the subnets behind the gateways <b>moon</b> and <b>sun</b> is set up.
|
||||
The authentication is based on <b>X.509 certificates</b> which contain a <b>critical</b> but
|
||||
unsupported 'strongSwan' extension. Whereas <b>moon</b> ignores unsupported critical
|
||||
extensions by setting <b>libstrongswan.x509.enforce_critical = no</b> in strongswan.conf,
|
||||
<b>sun</b> discards such certificates and aborts the connection setup.
|
||||
@@ -1,4 +0,0 @@
|
||||
moon::cat /var/log/daemon.log::sending end entity cert::YES
|
||||
moon::cat /var/log/daemon.log::received AUTHENTICATION_FAILED notify error::YES
|
||||
sun:: cat /var/log/daemon.log::found unsupported critical X.509 extension::YES
|
||||
sun:: cat /var/log/daemon.log::building CRED_CERTIFICATE - X509 failed::YES
|
||||
@@ -1,12 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce pem pkcs1 openssl revocation curl vici kernel-netlink socket-default updown
|
||||
multiple_authentication = no
|
||||
}
|
||||
|
||||
libstrongswan {
|
||||
x509 {
|
||||
enforce_critical = no
|
||||
}
|
||||
}
|
||||
@@ -1,26 +0,0 @@
|
||||
connections {
|
||||
|
||||
gw-gw {
|
||||
local_addrs = 192.168.0.1
|
||||
remote_addrs = 192.168.0.2
|
||||
|
||||
local {
|
||||
auth = pubkey
|
||||
id = moon.strongswan.org
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
id = sun.strongswan.org
|
||||
}
|
||||
children {
|
||||
net-net {
|
||||
local_ts = 10.1.0.0/16
|
||||
remote_ts = 10.2.0.0/16
|
||||
esp_proposals = aes128gcm128-ecp256
|
||||
}
|
||||
}
|
||||
version = 2
|
||||
mobike = no
|
||||
proposals = aes128-sha256-ecp256
|
||||
}
|
||||
}
|
||||
@@ -1,26 +0,0 @@
|
||||
connections {
|
||||
|
||||
gw-gw {
|
||||
local_addrs = 192.168.0.2
|
||||
remote_addrs = 192.168.0.1
|
||||
|
||||
local {
|
||||
auth = pubkey
|
||||
id = sun.strongswan.org
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
id = moon.strongswan.org
|
||||
}
|
||||
children {
|
||||
net-net {
|
||||
local_ts = 10.2.0.0/16
|
||||
remote_ts = 10.1.0.0/16
|
||||
esp_proposals = aes128gcm128-ecp256
|
||||
}
|
||||
}
|
||||
version = 2
|
||||
mobike = no
|
||||
proposals = aes128-sha256-ecp256
|
||||
}
|
||||
}
|
||||
@@ -1,2 +0,0 @@
|
||||
moon::systemctl stop strongswan
|
||||
sun::systemctl stop strongswan
|
||||
@@ -1,5 +0,0 @@
|
||||
moon::systemctl start strongswan
|
||||
sun::systemctl start strongswan
|
||||
moon::expect-connection gw-gw
|
||||
sun::expect-connection gw-gw
|
||||
moon::swanctl --initiate --child net-net 2> /dev/null
|
||||
@@ -1,25 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# This configuration file provides information on the
|
||||
# guest instances used for this test
|
||||
|
||||
# All guest instances that are required for this test
|
||||
#
|
||||
VIRTHOSTS="alice moon winnetou sun bob"
|
||||
|
||||
# Corresponding block diagram
|
||||
#
|
||||
DIAGRAM="a-m-w-s-b.png"
|
||||
|
||||
# Guest instances on which tcpdump is to be started
|
||||
#
|
||||
TCPDUMPHOSTS=""
|
||||
|
||||
# Guest instances on which IPsec is started
|
||||
# Used for IPsec logging purposes
|
||||
#
|
||||
IPSECHOSTS="moon sun"
|
||||
|
||||
# charon controlled by swanctl
|
||||
#
|
||||
SWANCTL=1
|
||||
@@ -1,8 +0,0 @@
|
||||
A connection between the subnets behind the gateways <b>moon</b> and <b>sun</b> is set up.
|
||||
The authentication is based on <b>X.509 certificates</b> and an RSA private key stored in
|
||||
<b>PKCS12</b> format.
|
||||
<p/>
|
||||
Upon the successful establishment of the IPsec tunnels, <b>leftfirewall=yes</b>
|
||||
automatically inserts iptables-based firewall rules that let pass the tunneled traffic.
|
||||
In order to test both tunnel and firewall, client <b>alice</b> behind gateway <b>moon</b>
|
||||
pings client <b>bob</b> located behind gateway <b>sun</b>.
|
||||
@@ -1,5 +0,0 @@
|
||||
alice::ping -c 1 PH_IP_BOB::64 bytes from PH_IP_BOB: icmp_.eq=1::YES
|
||||
moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-port=500 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-port=500 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
|
||||
sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-port=500 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-port=500 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
|
||||
sun::tcpdump::IP moon.strongswan.org > sun.strongswan.org: ESP::YES
|
||||
sun::tcpdump::IP sun.strongswan.org > moon.strongswan.org: ESP::YES
|
||||
@@ -1,9 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
swanctl {
|
||||
load = pem openssl
|
||||
}
|
||||
|
||||
charon-systemd {
|
||||
load = pem nonce openssl curl vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,36 +0,0 @@
|
||||
connections {
|
||||
|
||||
gw-gw {
|
||||
local_addrs = 192.168.0.1
|
||||
remote_addrs = 192.168.0.2
|
||||
|
||||
local {
|
||||
auth = pubkey
|
||||
id = moon.strongswan.org
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
id = sun.strongswan.org
|
||||
}
|
||||
children {
|
||||
net-net {
|
||||
local_ts = 10.1.0.0/16
|
||||
remote_ts = 10.2.0.0/16
|
||||
|
||||
updown = /usr/local/libexec/ipsec/_updown iptables
|
||||
esp_proposals = aes128gcm128-modp3072
|
||||
}
|
||||
}
|
||||
version = 2
|
||||
mobike = no
|
||||
proposals = aes128-sha256-modp3072
|
||||
}
|
||||
}
|
||||
|
||||
secrets {
|
||||
|
||||
pkcs12-moon {
|
||||
file = moonCert.p12
|
||||
secret = "kUqd8O7mzbjXNJKQ"
|
||||
}
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
swanctl {
|
||||
load = pem openssl
|
||||
}
|
||||
|
||||
charon-systemd {
|
||||
load = pem nonce openssl curl vici kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,36 +0,0 @@
|
||||
connections {
|
||||
|
||||
gw-gw {
|
||||
local_addrs = 192.168.0.2
|
||||
remote_addrs = 192.168.0.1
|
||||
|
||||
local {
|
||||
auth = pubkey
|
||||
id = sun.strongswan.org
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
id = moon.strongswan.org
|
||||
}
|
||||
children {
|
||||
net-net {
|
||||
local_ts = 10.2.0.0/16
|
||||
remote_ts = 10.1.0.0/16
|
||||
|
||||
updown = /usr/local/libexec/ipsec/_updown iptables
|
||||
esp_proposals = aes128gcm128-modp3072
|
||||
}
|
||||
}
|
||||
version = 2
|
||||
mobike = no
|
||||
proposals = aes128-sha256-modp3072
|
||||
}
|
||||
}
|
||||
|
||||
secrets {
|
||||
|
||||
pkcs12-sun {
|
||||
file = sunCert.p12
|
||||
secret = "IxjQVCF3JGI+MoPi"
|
||||
}
|
||||
}
|
||||
@@ -1,6 +0,0 @@
|
||||
moon::systemctl stop strongswan
|
||||
sun::systemctl stop strongswan
|
||||
moon::iptables-restore < /etc/iptables.flush
|
||||
sun::iptables-restore < /etc/iptables.flush
|
||||
moon::rm /etc/swanctl/pkcs12/moonCert.p12
|
||||
sun::rm /etc/swanctl/pkcs12/sunCert.p12
|
||||
@@ -1,9 +0,0 @@
|
||||
moon::cd /etc/swanctl; rm rsa/moonKey.pem x509/moonCert.pem x509ca/strongswanCert.pem
|
||||
sun::cd /etc/swanctl; rm rsa/sunKey.pem x509/sunCert.pem x509ca/strongswanCert.pem
|
||||
moon::iptables-restore < /etc/iptables.rules
|
||||
sun::iptables-restore < /etc/iptables.rules
|
||||
moon::systemctl start strongswan
|
||||
sun::systemctl start strongswan
|
||||
moon::expect-connection gw-gw
|
||||
sun::expect-connection gw-gw
|
||||
moon::swanctl --initiate --child net-net 2> /dev/null
|
||||
@@ -1,25 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# This configuration file provides information on the
|
||||
# guest instances used for this test
|
||||
|
||||
# All guest instances that are required for this test
|
||||
#
|
||||
VIRTHOSTS="alice moon winnetou sun bob"
|
||||
|
||||
# Corresponding block diagram
|
||||
#
|
||||
DIAGRAM="a-m-w-s-b.png"
|
||||
|
||||
# Guest instances on which tcpdump is to be started
|
||||
#
|
||||
TCPDUMPHOSTS="sun"
|
||||
|
||||
# Guest instances on which IPsec is started
|
||||
# Used for IPsec logging purposes
|
||||
#
|
||||
IPSECHOSTS="moon sun"
|
||||
|
||||
# charon controlled by swanctl
|
||||
#
|
||||
SWANCTL=1
|
||||
@@ -1,8 +0,0 @@
|
||||
A connection between the subnets behind the gateways <b>moon</b> and <b>sun</b> is set up.
|
||||
The authentication is based on <b>X.509 certificates</b> with signatures consisting of
|
||||
<b>RSA-encrypted SHA-3 hashes</b>.
|
||||
<p/>
|
||||
Upon the successful establishment of the IPsec tunnel, the updown script automatically
|
||||
inserts iptables-based firewall rules that let pass the tunneled traffic.
|
||||
In order to test both tunnel and firewall, client <b>alice</b> behind gateway <b>moon</b>
|
||||
pings client <b>bob</b> located behind gateway <b>sun</b>.
|
||||
@@ -1,5 +0,0 @@
|
||||
moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-port=500 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-port=500 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=CURVE_25519.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
|
||||
sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-port=500 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-port=500 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=CURVE_25519.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
|
||||
alice::ping -c 1 PH_IP_BOB::64 bytes from PH_IP_BOB: icmp_.eq=1::YES
|
||||
sun::tcpdump::IP moon.strongswan.org > sun.strongswan.org: ESP::YES
|
||||
sun::tcpdump::IP sun.strongswan.org > moon.strongswan.org: ESP::YES
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user