testing: Converted swanctl to systemd

This commit is contained in:
Andreas Steffen
2017-11-11 16:41:15 +01:00
parent 65f74cd13d
commit 70dc5bb8ad
181 changed files with 1170 additions and 849 deletions
@@ -1,16 +1,20 @@
# /etc/strongswan.conf - strongSwan configuration file
swanctl {
load = pem pkcs1 x509 revocation constraints pubkey openssl random
load = pem pkcs1 x509 revocation constraints pubkey openssl random
}
charon {
charon-systemd {
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac vici kernel-netlink socket-default sqlite fips-prf eap-aka eap-simaka-sql updown
start-scripts {
creds = /usr/local/sbin/swanctl --load-creds
conns = /usr/local/sbin/swanctl --load-conns
}
syslog {
daemon {
default = 1
}
auth {
default = 0
}
}
plugins {
eap-simaka-sql {
database = sqlite:///etc/ipsec.d/ipsec.db
@@ -1,16 +1,20 @@
# /etc/strongswan.conf - strongSwan configuration file
swanctl {
load = pem pkcs1 x509 revocation constraints pubkey openssl random
load = pem pkcs1 x509 revocation constraints pubkey openssl random
}
charon {
charon-systemd {
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac vici kernel-netlink socket-default sqlite fips-prf eap-aka eap-simaka-sql updown
start-scripts {
creds = /usr/local/sbin/swanctl --load-creds
conns = /usr/local/sbin/swanctl --load-conns
}
syslog {
daemon {
default = 1
}
auth {
default = 0
}
}
plugins {
eap-simaka-sql {
database = sqlite:///etc/ipsec.d/ipsec.db
@@ -1,5 +1,5 @@
carol::swanctl --terminate --ike home
carol::service charon stop 2> /dev/null
moon::service charon stop 2> /dev/null
carol::systemctl stop strongswan-swanctl
moon::systemctl stop strongswan-swanctl
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
@@ -3,8 +3,8 @@ carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/ipsec.d; cat tables.sql data.sql > ipsec.sql; cat ipsec.sql | sqlite3 ipsec.db
moon::cd /etc/ipsec.d; cat tables.sql data.sql > ipsec.sql; cat ipsec.sql | sqlite3 ipsec.db
carol::cd /etc/swanctl; rm rsa/* x509/*
moon::service charon start 2> /dev/null
carol::service charon start 2> /dev/null
moon::systemctl start strongswan-swanctl
carol::systemctl start strongswan-swanctl
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null