testing: Negotiate TLS 1.3 for part of the EAP-TLS scenarios

This commit is contained in:
Andreas Steffen
2023-03-02 09:02:38 +01:00
parent d605584a7a
commit edd3c797b0
42 changed files with 114 additions and 42 deletions
@@ -1,10 +1,12 @@
carol::cat /var/log/daemon.log::server requested EAP_TTLS authentication::YES
carol::cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
carol::cat /var/log/daemon.log::negotiated TLS 1.3 using suite TLS_AES_256_GCM_SHA384::YES
carol::cat /var/log/daemon.log::server requested EAP_MD5 authentication::YES
carol::cat /var/log/daemon.log::EAP method EAP_TTLS succeeded, MSK established::YES
carol::cat /var/log/daemon.log::authentication of 'C=CH, O=strongSwan Project, CN=moon.strongswan.org' with EAP successful::YES
dave:: cat /var/log/daemon.log::server requested EAP_TTLS authentication::YES
dave:: cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
dave:: cat /var/log/daemon.log::negotiated TLS 1.2 using suite TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::YES
dave:: cat /var/log/daemon.log::server requested EAP_MD5 authentication::YES
dave:: cat /var/log/daemon.log::received EAP_FAILURE, EAP authentication failed::YES
moon:: cat /var/log/daemon.log::EAP_TTLS phase2 authentication of '[email protected]' with EAP_MD5 successful::YES
@@ -16,5 +16,6 @@ charon-systemd {
}
libtls {
suites = TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
version_max = 1.3
suites = TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384
}
@@ -19,3 +19,7 @@ charon-systemd {
}
}
}
libtls {
version_max = 1.3
}