From 76206ecab9882dcb8b1eade88d9ebaf3d4d3a577 Mon Sep 17 00:00:00 2001 From: Andreas Steffen Date: Thu, 26 Mar 2009 12:56:16 +0000 Subject: [PATCH] cosmetics in ikev2/rw-eap-aka-id-rsa scenario --- testing/tests/ikev2/rw-eap-aka-id-rsa/description.txt | 5 +++-- testing/tests/ikev2/rw-eap-aka-id-rsa/evaltest.dat | 2 +- .../tests/ikev2/rw-eap-aka-id-rsa/hosts/moon/etc/ipsec.conf | 2 +- 3 files changed, 5 insertions(+), 4 deletions(-) diff --git a/testing/tests/ikev2/rw-eap-aka-id-rsa/description.txt b/testing/tests/ikev2/rw-eap-aka-id-rsa/description.txt index e7d2c784a..6d886024b 100644 --- a/testing/tests/ikev2/rw-eap-aka-id-rsa/description.txt +++ b/testing/tests/ikev2/rw-eap-aka-id-rsa/description.txt @@ -1,8 +1,9 @@ +at the outset the gateway authenticates itself to the client by sending an +IKEv2 RSA signature accompanied by a certificate. The roadwarrior carol sets up a connection to gateway moon. carol uses the Extensible Authentication Protocol in association with the Authentication and Key Agreement protocol (EAP-AKA) to authenticate against the gateway. This protocol is used in UMTS, but here a secret from ipsec.secrets is used instead of a USIM/(R)UIM. In addition to her IKEv2 identity carol@strongswan.org, roadwarrior carol -uses the EAP identy carol. Gateway moon additionaly uses an RSA signature -to authenticate itself against carol. +uses the EAP identity carol. diff --git a/testing/tests/ikev2/rw-eap-aka-id-rsa/evaltest.dat b/testing/tests/ikev2/rw-eap-aka-id-rsa/evaltest.dat index 5d0b469bf..d5cbbdbf7 100644 --- a/testing/tests/ikev2/rw-eap-aka-id-rsa/evaltest.dat +++ b/testing/tests/ikev2/rw-eap-aka-id-rsa/evaltest.dat @@ -2,7 +2,7 @@ carol::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with RSA carol::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with EAP successful::YES moon::cat /var/log/daemon.log::using EAP identity.*carol::YES moon::cat /var/log/daemon.log::authentication of 'carol@strongswan.org' with EAP successful::YES -moon::ipsec statusall::rw-eapaka.*ESTABLISHED::YES +moon::ipsec statusall::rw-eap.*ESTABLISHED::YES carol::ipsec statusall::home.*ESTABLISHED::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES diff --git a/testing/tests/ikev2/rw-eap-aka-id-rsa/hosts/moon/etc/ipsec.conf b/testing/tests/ikev2/rw-eap-aka-id-rsa/hosts/moon/etc/ipsec.conf index 350fc48b6..b239e7718 100755 --- a/testing/tests/ikev2/rw-eap-aka-id-rsa/hosts/moon/etc/ipsec.conf +++ b/testing/tests/ikev2/rw-eap-aka-id-rsa/hosts/moon/etc/ipsec.conf @@ -11,7 +11,7 @@ conn %default keyingtries=1 keyexchange=ikev2 -conn rw-eapaka +conn rw-eap authby=rsasig eap=aka eap_identity=%identity