testing: Converted tnc scenarios to swanctl

This commit is contained in:
Andreas Steffen
2015-12-11 18:26:54 +01:00
parent 74270c8c86
commit 6aa7703122
386 changed files with 5091 additions and 2383 deletions
@@ -1,9 +0,0 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
config setup
charondebug="tls 2, tnc 2, imv 3"
conn aaa
leftcert=aaaCert.pem
leftid=aaa.strongswan.org
auto=add
@@ -1,6 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA aaaKey.pem
carol : EAP "Ar3etTnp"
dave : EAP "W7R0g3do"
@@ -1,8 +1,21 @@
# /etc/strongswan.conf - strongSwan configuration file
charon {
load = pem pkcs1 nonce x509 openssl curl revocation constraints socket-default kernel-netlink stroke tnc-pdp tnc-imv tnc-tnccs tnccs-20 sqlite
load = random nonce pem pkcs1 x509 openssl revocation constraints curl vici socket-default kernel-netlink tnc-pdp tnc-imv tnc-tnccs tnccs-20 sqlite
start-scripts {
creds = /usr/local/sbin/swanctl --load-creds
}
syslog {
auth {
default = 0
}
daemon {
tls = 2
tnc = 2
imv = 3
}
}
plugins {
tnc-pdp {
server = aaa.strongswan.org
@@ -0,0 +1,7 @@
secrets {
eap-carol {
id = carol
secret = "Ar3etTnp"
}
}
@@ -1,3 +0,0 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
# the PT-TLS client reads its configuration via the command line
@@ -1,3 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
# the PT-TLS client loads its secrets via the command line
@@ -1,6 +1,6 @@
--connect aaa.strongswan.org
--client carol
--secret "Ar3etTnp"
--cert /etc/ipsec.d/cacerts/strongswanCert.pem
--cert /etc/swanctl/x509ca/strongswanCert.pem
--quiet
--debug 2
@@ -0,0 +1 @@
# the PT-TLS client reads its configuration and secrets via the command line
@@ -1,3 +0,0 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
# the PT-TLS client reads its configuration via the command line
@@ -1,3 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
# the PT-TLS client loads its secrets via the command line
@@ -1,7 +1,7 @@
--connect aaa.strongswan.org
--client [email protected]
--key /etc/ipsec.d/private/daveKey.pem
--cert /etc/ipsec.d/certs/daveCert.pem
--cert /etc/ipsec.d/cacerts/strongswanCert.pem
--key /etc/swanctl/rsa/daveKey.pem
--cert /etc/swanctl/x509/daveCert.pem
--cert /etc/swanctl/x509ca/strongswanCert.pem
--quiet
--debug 2
@@ -0,0 +1 @@
# the PT-TLS client reads its configuration and secrets via the command line
@@ -1,3 +0,0 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
# this file is not used in this scenario
@@ -1,3 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
# this file is not used in this scenario
@@ -0,0 +1 @@
# this file is not used in this scenario