testing: Script building fresh certificates

This commit is contained in:
Andreas Steffen
2019-05-08 14:56:48 +02:00
committed by Tobias Brunner
parent 3ee352a691
commit 8db01c6a3f
164 changed files with 2064 additions and 690 deletions
@@ -1,30 +0,0 @@
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,7E1D40A7901772BA4D22AF58AA2DC76F
1jt4EsxtHvgpSLN8PA/kSVKgoAsBEBQb8RK6VGnZywMCnpJdLKdPisGGYKNPg53b
/0AFBmQVE60M8icbSAIUrAtyKxaBkoc9A7ibNCjobi0UzXTm3GcZZ1EC4/lE9PQZ
/2FbcPgQWN3kZraZDkeP9XBXl6PorES8xvQUxJ9pd4hL7/c28fIApGhEimkIZO8o
Qb7bR2cNCLYQAR6PeDoqhV39gvWoh77wp1WB3tQVbkS6MI/xl3wY2QVdq3Sbszh+
f6lDU/SZS8BU0f44FRoInPp0GasgJ7MCiuEIshjuNPa50QkMcnNJsSgVEuw2hjN6
LvAXx7vPt9pKpQfnu7YSJUsXDYN6PyXt7sZ8hDqraYIcI6eMpEBaTpItPSV2eckv
06KC24Oa66E1yufNFAY49S2OY+pJA0W5zmcCqCjdrfJ+wNQYKZpbrfGz4VRzlFJC
e3VkmAFwA5rcZdlp/mU2XREy+TaWsHMnpL0NcMHGmsfkTgaJIkRWalrdxlNTeitr
3boNHWk0ESyMcBYRpM3eNXsGpiYy93u0bhrPbnqJsV6miKqpbs1aBNjlJ9s1Y2fC
sko5/v7uMjb5tLF3lWQZfTu+bYtpGxFrqHJjhd8yd4gL1cFi30JcjczhwRY3Dily
c0BFekMGmPc1djn6tfIFu13X9xTxyidCpVaT9UGnOaQs9OF1u8XAnZDaQgPwjLiy
UlOE8xQ60LrhWLD582FsFnZz56bZ+QOQRWDMsB8nJeqnFXKfcRlnr0qlG6lTfA8h
XkK/qGpdVvivS+CpbhVP6ixdEfa91Rx4NjLj53LGqOYwFEkM/OAIuMJetBfx3v9T
iQfv594KE32nv9besnKlmJr2cGQWBYg1pUOtFj/aZ00yuXacv8qwzbrt4xGGDYGO
Aj5Yf93UEcVkTySO1xJ1yiC6GJv1lLm0i5StwykHypxFijKe/zOpgtHVa5v5igjO
v6cfhfJGGgIPTYrtt+EDKXcayvy2e2U/3HYVCHYiiMPX8AvP/R6m7MGrzYxm/WyO
t68EWXSDLfuR3qcIlpP4aSBxuSpKhY/dIkS/beKZ7Njx1s4jSuYDMbKuuCRFSU2H
8ISHS0kh3FetiS8IyIYzxab+KQZwnVtiGj4oaAhgFTIIoH26Fv5+xka74JdzOSUA
jR9puKuxaegVWQVBx4cCyg6hAdewRm64PAcbApZWrPvMPBfTZFnXeifmaurcdK8p
p/1eLrrPnNM6+Fh6lcKdX74yHPz3eWP3K1njZegzWnChhEWElPhJr6qYNQjd+lAS
7650RJ3CJLUxBffnRR9nTArxFNI5jGWg/plLJTaRT5x5qg1dGNMqntpoeiY++Ttk
GFDGVIOICBze6SOvzkZBbuXLJSWmWj5g9J2cYsLoOvlwsDT7FzKl8p6VY4V+SQb+
4PN8qZWmOeczaLEhZ1QLmTKFpz9+wUZsXeBd1s78bWJR0zhraMPa0UJ9GBGq6uQ0
yZ4Xm5KHKcgoewCUQMekU9ECsmR5NuC7VFDaa1OdPEVnEYR1xtaWUY0lYKOiixnd
+85fSq/yAXI/r0O4ISA55o9y1kDqVibTwJacb6xXGg8dHSH+TtigwD8fK9mekkDC
-----END RSA PRIVATE KEY-----
@@ -1,30 +0,0 @@
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,7E1D40A7901772BA4D22AF58AA2DC76F
1jt4EsxtHvgpSLN8PA/kSVKgoAsBEBQb8RK6VGnZywMCnpJdLKdPisGGYKNPg53b
/0AFBmQVE60M8icbSAIUrAtyKxaBkoc9A7ibNCjobi0UzXTm3GcZZ1EC4/lE9PQZ
/2FbcPgQWN3kZraZDkeP9XBXl6PorES8xvQUxJ9pd4hL7/c28fIApGhEimkIZO8o
Qb7bR2cNCLYQAR6PeDoqhV39gvWoh77wp1WB3tQVbkS6MI/xl3wY2QVdq3Sbszh+
f6lDU/SZS8BU0f44FRoInPp0GasgJ7MCiuEIshjuNPa50QkMcnNJsSgVEuw2hjN6
LvAXx7vPt9pKpQfnu7YSJUsXDYN6PyXt7sZ8hDqraYIcI6eMpEBaTpItPSV2eckv
06KC24Oa66E1yufNFAY49S2OY+pJA0W5zmcCqCjdrfJ+wNQYKZpbrfGz4VRzlFJC
e3VkmAFwA5rcZdlp/mU2XREy+TaWsHMnpL0NcMHGmsfkTgaJIkRWalrdxlNTeitr
3boNHWk0ESyMcBYRpM3eNXsGpiYy93u0bhrPbnqJsV6miKqpbs1aBNjlJ9s1Y2fC
sko5/v7uMjb5tLF3lWQZfTu+bYtpGxFrqHJjhd8yd4gL1cFi30JcjczhwRY3Dily
c0BFekMGmPc1djn6tfIFu13X9xTxyidCpVaT9UGnOaQs9OF1u8XAnZDaQgPwjLiy
UlOE8xQ60LrhWLD582FsFnZz56bZ+QOQRWDMsB8nJeqnFXKfcRlnr0qlG6lTfA8h
XkK/qGpdVvivS+CpbhVP6ixdEfa91Rx4NjLj53LGqOYwFEkM/OAIuMJetBfx3v9T
iQfv594KE32nv9besnKlmJr2cGQWBYg1pUOtFj/aZ00yuXacv8qwzbrt4xGGDYGO
Aj5Yf93UEcVkTySO1xJ1yiC6GJv1lLm0i5StwykHypxFijKe/zOpgtHVa5v5igjO
v6cfhfJGGgIPTYrtt+EDKXcayvy2e2U/3HYVCHYiiMPX8AvP/R6m7MGrzYxm/WyO
t68EWXSDLfuR3qcIlpP4aSBxuSpKhY/dIkS/beKZ7Njx1s4jSuYDMbKuuCRFSU2H
8ISHS0kh3FetiS8IyIYzxab+KQZwnVtiGj4oaAhgFTIIoH26Fv5+xka74JdzOSUA
jR9puKuxaegVWQVBx4cCyg6hAdewRm64PAcbApZWrPvMPBfTZFnXeifmaurcdK8p
p/1eLrrPnNM6+Fh6lcKdX74yHPz3eWP3K1njZegzWnChhEWElPhJr6qYNQjd+lAS
7650RJ3CJLUxBffnRR9nTArxFNI5jGWg/plLJTaRT5x5qg1dGNMqntpoeiY++Ttk
GFDGVIOICBze6SOvzkZBbuXLJSWmWj5g9J2cYsLoOvlwsDT7FzKl8p6VY4V+SQb+
4PN8qZWmOeczaLEhZ1QLmTKFpz9+wUZsXeBd1s78bWJR0zhraMPa0UJ9GBGq6uQ0
yZ4Xm5KHKcgoewCUQMekU9ECsmR5NuC7VFDaa1OdPEVnEYR1xtaWUY0lYKOiixnd
+85fSq/yAXI/r0O4ISA55o9y1kDqVibTwJacb6xXGg8dHSH+TtigwD8fK9mekkDC
-----END RSA PRIVATE KEY-----
@@ -1,30 +0,0 @@
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,7E1D40A7901772BA4D22AF58AA2DC76F
1jt4EsxtHvgpSLN8PA/kSVKgoAsBEBQb8RK6VGnZywMCnpJdLKdPisGGYKNPg53b
/0AFBmQVE60M8icbSAIUrAtyKxaBkoc9A7ibNCjobi0UzXTm3GcZZ1EC4/lE9PQZ
/2FbcPgQWN3kZraZDkeP9XBXl6PorES8xvQUxJ9pd4hL7/c28fIApGhEimkIZO8o
Qb7bR2cNCLYQAR6PeDoqhV39gvWoh77wp1WB3tQVbkS6MI/xl3wY2QVdq3Sbszh+
f6lDU/SZS8BU0f44FRoInPp0GasgJ7MCiuEIshjuNPa50QkMcnNJsSgVEuw2hjN6
LvAXx7vPt9pKpQfnu7YSJUsXDYN6PyXt7sZ8hDqraYIcI6eMpEBaTpItPSV2eckv
06KC24Oa66E1yufNFAY49S2OY+pJA0W5zmcCqCjdrfJ+wNQYKZpbrfGz4VRzlFJC
e3VkmAFwA5rcZdlp/mU2XREy+TaWsHMnpL0NcMHGmsfkTgaJIkRWalrdxlNTeitr
3boNHWk0ESyMcBYRpM3eNXsGpiYy93u0bhrPbnqJsV6miKqpbs1aBNjlJ9s1Y2fC
sko5/v7uMjb5tLF3lWQZfTu+bYtpGxFrqHJjhd8yd4gL1cFi30JcjczhwRY3Dily
c0BFekMGmPc1djn6tfIFu13X9xTxyidCpVaT9UGnOaQs9OF1u8XAnZDaQgPwjLiy
UlOE8xQ60LrhWLD582FsFnZz56bZ+QOQRWDMsB8nJeqnFXKfcRlnr0qlG6lTfA8h
XkK/qGpdVvivS+CpbhVP6ixdEfa91Rx4NjLj53LGqOYwFEkM/OAIuMJetBfx3v9T
iQfv594KE32nv9besnKlmJr2cGQWBYg1pUOtFj/aZ00yuXacv8qwzbrt4xGGDYGO
Aj5Yf93UEcVkTySO1xJ1yiC6GJv1lLm0i5StwykHypxFijKe/zOpgtHVa5v5igjO
v6cfhfJGGgIPTYrtt+EDKXcayvy2e2U/3HYVCHYiiMPX8AvP/R6m7MGrzYxm/WyO
t68EWXSDLfuR3qcIlpP4aSBxuSpKhY/dIkS/beKZ7Njx1s4jSuYDMbKuuCRFSU2H
8ISHS0kh3FetiS8IyIYzxab+KQZwnVtiGj4oaAhgFTIIoH26Fv5+xka74JdzOSUA
jR9puKuxaegVWQVBx4cCyg6hAdewRm64PAcbApZWrPvMPBfTZFnXeifmaurcdK8p
p/1eLrrPnNM6+Fh6lcKdX74yHPz3eWP3K1njZegzWnChhEWElPhJr6qYNQjd+lAS
7650RJ3CJLUxBffnRR9nTArxFNI5jGWg/plLJTaRT5x5qg1dGNMqntpoeiY++Ttk
GFDGVIOICBze6SOvzkZBbuXLJSWmWj5g9J2cYsLoOvlwsDT7FzKl8p6VY4V+SQb+
4PN8qZWmOeczaLEhZ1QLmTKFpz9+wUZsXeBd1s78bWJR0zhraMPa0UJ9GBGq6uQ0
yZ4Xm5KHKcgoewCUQMekU9ECsmR5NuC7VFDaa1OdPEVnEYR1xtaWUY0lYKOiixnd
+85fSq/yAXI/r0O4ISA55o9y1kDqVibTwJacb6xXGg8dHSH+TtigwD8fK9mekkDC
-----END RSA PRIVATE KEY-----
@@ -16,6 +16,6 @@ conn alice
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
rightsubnet=PH_IP_ALICE/32
auto=add
@@ -16,6 +16,6 @@ conn venus
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -22,12 +22,12 @@ conn alice
leftsubnet=PH_IP_ALICE/32
right=PH_IP_CAROL
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=PH_IP_DAVE
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
@@ -13,7 +13,7 @@ conn %default
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
@@ -13,7 +13,7 @@ conn %default
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn venus
rightsubnet=PH_IP_VENUS/32
@@ -21,11 +21,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
@@ -13,12 +13,12 @@ conn %default
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -13,12 +13,12 @@ conn %default
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -21,11 +21,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Sales, CN=Sales CA"
rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
auto=add
@@ -7,5 +7,5 @@ dave::iptables-restore < /etc/iptables.flush
moon::rm /etc/ipsec.d/acerts/carol-sales-finance.pem
moon::rm /etc/ipsec.d/acerts/dave-sales-expired.pem
moon::rm /etc/ipsec.d/acerts/dave-marketing.pem
moon::rm /etc/ipsec.d/private/aa.pem
moon::rm /etc/ipsec.d/aacerts/aa.pem
moon::rm /etc/ipsec.d/private/aaKey.pem
moon::rm /etc/ipsec.d/aacerts/aaCert.pem
@@ -1,23 +0,0 @@
# Carols acert for sales and finance
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem \
--in ../../../hosts/carol/etc/ipsec.d/certs/carolCert.pem \
--group sales --group finance -l 87600 -f pem \
> hosts/moon/etc/ipsec.d/acerts/carol-sales-finance.pem
# Daves acert for marketing
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem \
--in ../../../hosts/dave/etc/ipsec.d/certs/daveCert.pem \
--group marketing -l 87600 -f pem \
> hosts/moon/etc/ipsec.d/acerts/dave-marketing.pem
# Daves expired acert for sales
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem \
--in ../../../hosts/dave/etc/ipsec.d/certs/daveCert.pem \
--group sales -F "01.01.13 08:00:00" -l 240 -f pem \
> hosts/moon/etc/ipsec.d/acerts/dave-sales-expired.pem
@@ -4,5 +4,5 @@ moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::rm /etc/ipsec.d/acerts/carol-sales.pem
carol::rm /etc/ipsec.d/acerts/carol-finance-expired.pem
moon::rm /etc/ipsec.d/private/aa.pem
moon::rm /etc/ipsec.d/aacerts/aa.pem
moon::rm /etc/ipsec.d/private/aaKey.pem
moon::rm /etc/ipsec.d/aacerts/aaCert.pem
@@ -1,15 +0,0 @@
# Carols expired acert for finance
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem \
--in ../../../hosts/carol/etc/ipsec.d/certs/carolCert.pem \
--group finance -F "01.01.13 08:00:00" -l 240 -f pem \
> ./hosts/carol/etc/ipsec.d/acerts/carol-finance-expired.pem
# Carols valid acert for sales
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem \
--in ../../../hosts/carol/etc/ipsec.d/certs/carolCert.pem \
--group sales -l 87600 -f pem \
> hosts/carol/etc/ipsec.d/acerts/carol-sales.pem
@@ -3,9 +3,9 @@ dave:: ipsec status 2> /dev/null::home.*ESTABLISHED.*[email protected].*moon.s
moon:: ipsec status 2> /dev/null::rw\[1]: ESTABLISHED.*moon.strongswan.org.*[email protected]::YES
moon:: ipsec status 2> /dev/null::rw\[2]: ESTABLISHED.*moon.strongswan.org.*[email protected]::NO
moon::cat /var/log/daemon.log::constraint check failed: group membership to 'sales' required::YES
carol::cat /var/log/daemon.log::sending attribute certificate issued by \"C=CH, O=Linux strongSwan, CN=strongSwan AA\"::YES
dave::cat /var/log/daemon.log::sending attribute certificate issued by \"C=CH, O=Linux strongSwan, CN=strongSwan AA\"::YES
dave::cat /var/log/daemon.log::sending attribute certificate issued by \"C=CH, O=Linux strongSwan, CN=expired AA\"::YES
carol::cat /var/log/daemon.log::sending attribute certificate issued by \"C=CH, O=strongSwan Project, CN=strongSwan Attribute Authority\"::YES
dave::cat /var/log/daemon.log::sending attribute certificate issued by \"C=CH, O=strongSwan Project, CN=strongSwan Attribute Authority\"::YES
dave::cat /var/log/daemon.log::sending attribute certificate issued by \"C=CH, O=strongSwan Project, CN=strongSwan Legacy AA\"::YES
dave::cat /var/log/daemon.log::received AUTHENTICATION_FAILED notify error::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_.eq=1::YES
dave:: ping -c 1 -W 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_.eq=1::NO
@@ -7,7 +7,7 @@ dave::iptables-restore < /etc/iptables.flush
carol::rm /etc/ipsec.d/acerts/carol-sales.pem
dave::rm /etc/ipsec.d/acerts/dave-expired-aa.pem
dave::rm /etc/ipsec.d/acerts/dave-marketing.pem
moon::rm /etc/ipsec.d/private/aa-expired.pem
moon::rm /etc/ipsec.d/private/aa.pem
moon::rm /etc/ipsec.d/aacerts/aa-expired.pem
moon::rm /etc/ipsec.d/aacerts/aa.pem
moon::rm /etc/ipsec.d/private/aaKey-expired.pem
moon::rm /etc/ipsec.d/private/aaKey.pem
moon::rm /etc/ipsec.d/aacerts/aaCert-expired.pem
moon::rm /etc/ipsec.d/aacerts/aaCert.pem
@@ -1,23 +0,0 @@
# Carols sales acert
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem --in \
../../../hosts/carol/etc/ipsec.d/certs/carolCert.pem \
--group sales -l 87600 -f pem \
> hosts/carol/etc/ipsec.d/acerts/carol-sales.pem
# Daves marketing acert
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa.pem \
--in ../../../hosts/dave/etc/ipsec.d/certs/daveCert.pem \
--group marketing -l 87600 -f pem
> hosts/dave/etc/ipsec.d/acerts/dave-marketing.pem
# Daves sales acert from expired AA
pki --acert \
--issuercert hosts/moon/etc/ipsec.d/aacerts/aa-expired.pem \
--issuerkey hosts/moon/etc/ipsec.d/private/aa-expired.pem \
--in ../../../hosts/dave/etc/ipsec.d/certs/daveCert.pem \
--group sales -l 87600 -f pem \
> hosts/dave/etc/ipsec.d/acerts/dave-expired-aa.pem
@@ -16,7 +16,7 @@ conn %default
left=%any
leftcert=bobCert.pem
conn sun
conn sun
right=PH_IP_SUN1
rightid="C=CH, O=Linux strongSwan, CN=sun.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=sun.strongswan.org"
auto=route
@@ -18,10 +18,10 @@ conn %default
conn alice
right=PH_IP_ALICE
rightid="C=CH, O=Linux strongSwan, OU=Sales, [email protected]"
rightid="C=CH, O=strongSwan Project, OU=Sales, [email protected]"
auto=route
conn sun
conn sun
right=PH_IP_SUN
rightid="C=CH, O=Linux strongSwan, CN=sun.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=sun.strongswan.org"
auto=route
@@ -6,7 +6,7 @@ config setup
ca strongswan
cacert=strongswanCert.pem
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
conn %default
@@ -6,7 +6,7 @@ config setup
ca strongswan
cacert=strongswanCert.pem
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
conn %default
@@ -11,7 +11,7 @@ conn %default
conn home
left=PH_IP_CAROL
leftcert=carolRevokedCert.pem
leftcert=carolCert.pem
[email protected]
right=PH_IP_MOON
rightsubnet=10.1.0.0/16
@@ -1,3 +1,3 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA carolRevokedKey.pem
: RSA carolKey.pem
@@ -1,4 +1,2 @@
moon::ipsec stop
carol::ipsec stop
carol::rm /etc/ipsec.d/private/*
carol::rm /etc/ipsec.d/certs/*
@@ -1,4 +1,4 @@
moon:: ipsec status 2> /dev/null::rw.*ESTABLISHED.*moon.strongswan.org.*[email protected]::YES
carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*[email protected].*moon.strongswan.org::YES
moon:: cat /var/log/daemon.log::written crl .*/etc/ipsec.d/crls/5da7dd700651327ee7b66db3b5e5e060ea2e4def.crl::YES
carol::cat /var/log/daemon.log::written crl .*/etc/ipsec.d/crls/5da7dd700651327ee7b66db3b5e5e060ea2e4def.crl::YES
moon:: cat /var/log/daemon.log::written crl .*/etc/ipsec.d/crls/.*.crl::YES
carol::cat /var/log/daemon.log::written crl .*/etc/ipsec.d/crls/.*.crl::YES
@@ -5,7 +5,7 @@ config setup
ca strongswan
cacert=strongswanCert.pem
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
conn %default
@@ -18,12 +18,12 @@ conn %default
leftcert=carolCert.pem
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -5,7 +5,7 @@ config setup
ca strongswan
cacert=strongswanCert.pem
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
conn %default
@@ -18,12 +18,12 @@ conn %default
leftcert=daveCert.pem
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -5,19 +5,19 @@ config setup
ca strongswan
cacert=strongswanCert.pem
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
ca research
ca research
cacert=researchCert.pem
crluri="ldap://ldap.strongswan.org/cn=Research CA, ou=Research, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=Research CA, ou=Research, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
ca sales
ca sales
cacert=salesCert.pem
crluri="ldap://ldap.strongswan.org/cn=Sales CA, ou=Sales, o=Linux strongSwan, c=CH?certificateRevocationList"
crluri="ldap://ldap.strongswan.org/cn=Sales CA, ou=Sales, o=strongSwan Project, c=CH?certificateRevocationList"
auto=add
conn %default
ikelifetime=60m
keylife=20m
@@ -32,11 +32,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Sales, CN=Sales CA"
rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
auto=add
@@ -17,5 +17,5 @@ conn home
right=PH_IP_MOON
rightsubnet=10.1.0.0/16
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
@@ -3,11 +3,6 @@
config setup
strictcrlpolicy=yes
ca strongswan
cacert=strongswanCert.pem
crluri=http://crl.strongswan.org/strongswan.crl
auto=add
conn %default
ikelifetime=60m
keylife=20m
@@ -21,5 +16,5 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
@@ -17,5 +17,5 @@ conn home
right=PH_IP_MOON
rightsubnet=10.1.0.0/16
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
@@ -3,11 +3,6 @@
config setup
strictcrlpolicy=yes
ca strongswan
cacert=strongswanCert.pem
crluri=http://crl.strongswan.org/not-available.crl
auto=add
conn %default
ikelifetime=60m
keylife=20m
@@ -21,5 +16,5 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
@@ -14,12 +14,12 @@ conn %default
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -14,12 +14,12 @@ conn %default
leftsendcert=ifasked
right=PH_IP_MOON
[email protected]
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -22,11 +22,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, CN=strongSwan Root CA"
rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
auto=add
@@ -2,11 +2,6 @@
config setup
ca strongswan
cacert=strongswanCert.pem
crluri=http://crl.strongswan.org/strongswan.crl
auto=add
conn %default
ikelifetime=60m
keylife=20m
@@ -21,11 +16,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Sales, CN=Sales CA"
rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
auto=add
@@ -3,5 +3,5 @@
charon {
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac stroke kernel-netlink socket-default updown
fragment_size = 1024
fragment_size = 1088
}
@@ -3,5 +3,5 @@
charon {
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac stroke kernel-netlink socket-default updown
fragment_size = 1024
fragment_size = 1088
}
@@ -13,12 +13,12 @@ conn net-net
left=PH_IP_MOON
leftsubnet=10.1.0.0/16
[email protected]
leftsigkey=moonPub.der
leftsigkey=moonPub.pem
leftauth=pubkey
leftfirewall=yes
right=PH_IP_SUN
rightsubnet=10.2.0.0/16
[email protected]
rightsigkey=sunPub.der
rightsigkey=sunPub.pem
rightauth=pubkey
auto=add
@@ -1,3 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA moonKey.der
@@ -13,10 +13,10 @@ conn net-net
left=PH_IP_SUN
leftsubnet=10.2.0.0/16
[email protected]
leftsigkey=sunPub.der
leftsigkey=sunPub.pem
leftfirewall=yes
right=PH_IP_MOON
rightsubnet=10.1.0.0/16
[email protected]
rightsigkey=moonPub.der
rightsigkey=moonPub.pem
auto=add
@@ -1,3 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA sunKey.der
@@ -1,6 +1,6 @@
#!/bin/bash
cd /etc/openssl
cd /etc/ca
echo "Content-type: application/ocsp-response"
echo ""
@@ -31,11 +31,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Sales, CN=Sales CA"
rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
auto=add
@@ -4,5 +4,7 @@ dave::ipsec start
moon::expect-connection alice
carol::expect-connection alice
carol::ipsec up alice
carol::ipsec up venus
dave::expect-connection venus
dave::ipsec up venus
dave::ipsec up alice
@@ -1,6 +1,6 @@
#!/bin/bash
cd /etc/openssl
cd /etc/ca
echo "Content-type: application/ocsp-response"
echo ""
@@ -15,7 +15,7 @@ conn %default
rekeymargin=3m
keyingtries=1
left=PH_IP_CAROL
leftcert=carolRevokedCert.pem
leftcert=carolCert.pem
[email protected]
conn home
@@ -1,3 +1,3 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA carolRevokedKey.pem
: RSA carolKey.pem
@@ -1,4 +1,2 @@
moon::ipsec stop
carol::ipsec stop
carol::rm /etc/ipsec.d/private/*
carol::rm /etc/ipsec.d/certs/*
@@ -15,7 +15,7 @@ conn %default
rekeymargin=3m
keyingtries=1
left=PH_IP_CAROL
leftcert=carolCert-ocsp.pem
leftcert=carolCert.pem
[email protected]
conn home
@@ -1,3 +1,3 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA carolKey-ocsp.pem
: RSA carolKey.pem
@@ -1,4 +1,2 @@
moon::ipsec stop
carol::ipsec stop
carol::rm /etc/ipsec.d/certs/*
carol::rm /etc/ipsec.d/private/*
@@ -10,14 +10,14 @@ conn %default
keyingtries=1
keyexchange=ikev2
left=PH_IP_CAROL
leftcert=carolCert-ifuri.pem
leftcert=carolCert.pem
right=PH_IP_MOON
[email protected]
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -2,7 +2,7 @@
config setup
strictcrlpolicy=ifuri
conn %default
ikelifetime=60m
keylife=20m
@@ -10,14 +10,14 @@ conn %default
keyingtries=1
keyexchange=ikev2
left=PH_IP_DAVE
leftcert=daveCert-ifuri.pem
leftcert=daveCert.pem
right=PH_IP_MOON
[email protected]
conn alice
rightsubnet=PH_IP_ALICE/32
auto=add
conn venus
rightsubnet=PH_IP_VENUS/32
auto=add
@@ -16,11 +16,11 @@ conn %default
conn alice
leftsubnet=PH_IP_ALICE/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Research, CN=Research CA"
rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
auto=add
conn venus
leftsubnet=PH_IP_VENUS/32
right=%any
rightca="C=CH, O=Linux strongSwan, OU=Sales, CN=Sales CA"
rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
auto=add
@@ -8,7 +8,7 @@ ca strongswan-ca
ocspuri1=http://bob.strongswan.org:8800
ocspuri2=http://ocsp.strongswan.org:8880
auto=add
conn %default
keyexchange=ikev2
ikelifetime=60m
@@ -16,7 +16,7 @@ conn %default
rekeymargin=3m
keyingtries=1
left=PH_IP_CAROL
leftcert=carolCert-ocsp.pem
leftcert=carolCert.pem
[email protected]
conn home
@@ -1,3 +1,3 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA carolKey-ocsp.pem
: RSA carolKey.pem
@@ -1,4 +1,2 @@
moon::ipsec stop
carol::ipsec stop
carol::rm /etc/ipsec.d/certs/*
carol::rm /etc/ipsec.d/private/*
@@ -1,6 +1,6 @@
#!/bin/bash
cd /etc/openssl
cd /etc/ca
echo "Content-type: application/ocsp-response"
echo ""
@@ -2,7 +2,7 @@ carol::cat /var/log/daemon.log::server requested EAP_PEAP authentication::YES
carol::cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
carol::cat /var/log/daemon.log::server requested EAP_MD5 authentication::YES
carol::cat /var/log/daemon.log::EAP method EAP_PEAP succeeded, MSK established::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' with EAP successful::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, CN=moon.strongswan.org' with EAP successful::YES
dave:: cat /var/log/daemon.log::server requested EAP_PEAP authentication::YES
dave:: cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
dave:: cat /var/log/daemon.log::server requested EAP_MD5 authentication::YES
@@ -17,7 +17,7 @@ dave:: ipsec status 2> /dev/null::home.*ESTABLISHED.*[email protected].*CN=moo
moon:: ipsec status 2> /dev/null::rw-eap[{]1}.*INSTALLED, TUNNEL::YES
moon:: ipsec status 2> /dev/null::rw-eap[{]2}.*INSTALLED::NO
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
dave:: ipsec status 2> /dev/null::home.*INSTALLED::NO
dave:: ipsec status 2> /dev/null::home.*INSTALLED::NO
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_.eq=1::YES
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
@@ -15,7 +15,7 @@ conn home
leftauth=eap
leftfirewall=yes
right=PH_IP_MOON
rightid="C=CH, O=Linux strongSwan, CN=moon.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=moon.strongswan.org"
rightauth=any
rightsubnet=10.1.0.0/16
rightsendcert=never
@@ -15,7 +15,7 @@ conn home
leftauth=eap
leftfirewall=yes
right=PH_IP_MOON
rightid="C=CH, O=Linux strongSwan, CN=moon.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=moon.strongswan.org"
rightauth=any
rightsubnet=10.1.0.0/16
rightsendcert=never
@@ -2,7 +2,7 @@ carol::cat /var/log/daemon.log::server requested EAP_PEAP authentication::YES
carol::cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
carol::cat /var/log/daemon.log::server requested EAP_MSCHAPV2 authentication::YES
carol::cat /var/log/daemon.log::EAP method EAP_PEAP succeeded, MSK established::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' with EAP successful::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, CN=moon.strongswan.org' with EAP successful::YES
dave:: cat /var/log/daemon.log::server requested EAP_PEAP authentication::YES
dave:: cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
dave:: cat /var/log/daemon.log::server requested EAP_MSCHAPV2 authentication::YES
@@ -15,7 +15,7 @@ conn home
leftauth=eap
leftfirewall=yes
right=PH_IP_MOON
rightid="C=CH, O=Linux strongSwan, CN=moon.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=moon.strongswan.org"
rightauth=any
rightsubnet=10.1.0.0/16
rightsendcert=never
@@ -15,7 +15,7 @@ conn home
leftauth=eap
leftfirewall=yes
right=PH_IP_MOON
rightid="C=CH, O=Linux strongSwan, CN=moon.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=moon.strongswan.org"
rightauth=any
rightsubnet=10.1.0.0/16
rightsendcert=never
@@ -18,5 +18,5 @@ conn home
[email protected]
rightsubnet=10.1.0.0/16
rightauth=pubkey
aaa_identity="C=CH, O=Linux strongSwan, CN=aaa.strongswan.org"
aaa_identity="C=CH, O=strongSwan Project, CN=aaa.strongswan.org"
auto=add
@@ -18,5 +18,5 @@ conn home
[email protected]
rightsubnet=10.1.0.0/16
rightauth=pubkey
aaa_identity="C=CH, O=Linux strongSwan, CN=aaa.strongswan.org"
aaa_identity="C=CH, O=strongSwan Project, CN=aaa.strongswan.org"
auto=add
@@ -1,8 +1,8 @@
carol::cat /var/log/daemon.log::server requested EAP_TLS authentication::YES
carol::cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
carol::cat /var/log/daemon.log::negotiated TLS 1.2 using suite TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' with EAP successful::YES
moon:: cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, OU=Research, [email protected]' with EAP successful::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, CN=moon.strongswan.org' with EAP successful::YES
moon:: cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, OU=Research, [email protected]' with EAP successful::YES
moon:: ipsec status 2> /dev/null::rw-eap.*ESTABLISHED::YES
carol::ipsec status 2> /dev/null::home.*ESTABLISHED::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_.eq=1::YES
@@ -13,7 +13,7 @@ conn home
leftauth=eap
leftfirewall=yes
right=PH_IP_MOON
rightid="C=CH, O=Linux strongSwan, CN=moon.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=moon.strongswan.org"
rightauth=any
rightsubnet=10.1.0.0/16
rightsendcert=never
@@ -1,7 +1,7 @@
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' with RSA.* successful::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, CN=moon.strongswan.org' with RSA.* successful::YES
carol::cat /var/log/daemon.log::server requested EAP_TLS authentication::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' with EAP successful::YES
moon:: cat /var/log/daemon.log::authentication of 'C=CH, O=Linux strongSwan, OU=Research, [email protected]' with EAP successful::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, CN=moon.strongswan.org' with EAP successful::YES
moon:: cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, OU=Research, [email protected]' with EAP successful::YES
moon:: ipsec status 2> /dev/null::rw-eap.*ESTABLISHED::YES
carol::ipsec status 2> /dev/null::home.*ESTABLISHED::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_.eq=1::YES
@@ -13,8 +13,8 @@ conn home
leftauth=eap
leftfirewall=yes
right=PH_IP_MOON
rightid="C=CH, O=Linux strongSwan, CN=moon.strongswan.org"
rightid="C=CH, O=strongSwan Project, CN=moon.strongswan.org"
rightsubnet=10.1.0.0/16
rightauth=pubkey
aaa_identity="C=CH, O=Linux strongSwan, CN=aaa.strongswan.org"
aaa_identity="C=CH, O=strongSwan Project, CN=aaa.strongswan.org"
auto=add
@@ -15,7 +15,7 @@ conn rw-eap
leftcert=moonCert.pem
leftauth=pubkey
leftfirewall=yes
rightid="C=CH, O=Linux strongSwan, OU=Research, [email protected]"
rightid="C=CH, O=strongSwan Project, OU=Research, [email protected]"
rightauth=eap-radius
rightsendcert=never
right=%any

Some files were not shown because too many files have changed in this diff Show More