This took a while as in the OpenSSL package shipped with Debian and on which our FIPS-enabled package is based, the function SSL_export_keying_material(), which is used by FreeRADIUS to derive the MSK, did not use the correct digest to calculate the result when TLS 1.2 was used. This caused IKE to fail with "verification of AUTH payload with EAP MSK failed". The fix was only backported to jessie recently.
38 lines
696 B
Plaintext
38 lines
696 B
Plaintext
# /etc/strongswan.conf - strongSwan configuration file
|
|
|
|
charon {
|
|
load = random nonce aes sha1 sha2 md5 pem pkcs1 gmp hmac x509 revocation curl vici kernel-netlink socket-default eap-identity eap-md5 eap-ttls eap-tnc tnc-imc tnc-tnccs tnccs-11 updown
|
|
|
|
multiple_authentication=no
|
|
|
|
start-scripts {
|
|
creds = /usr/local/sbin/swanctl --load-creds
|
|
conns = /usr/local/sbin/swanctl --load-conns
|
|
}
|
|
syslog {
|
|
auth {
|
|
default = 0
|
|
}
|
|
daemon {
|
|
tnc = 3
|
|
imc = 3
|
|
}
|
|
}
|
|
plugins {
|
|
eap-tnc {
|
|
protocol = tnccs-1.1
|
|
}
|
|
}
|
|
}
|
|
|
|
libimcv {
|
|
plugins {
|
|
imc-test {
|
|
command = allow
|
|
}
|
|
}
|
|
}
|
|
libtls {
|
|
suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
|
|
}
|