RFC 7427 signature authentication is now used between strongSwan hosts by default, which causes the actual signature schemes to get logged.
15 lines
1.1 KiB
Plaintext
15 lines
1.1 KiB
Plaintext
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with pre-shared key successful::YES
|
|
moon:: cat /var/log/daemon.log::authentication of 'PH_IP_MOON' (myself) with pre-shared key::YES
|
|
moon:: ipsec status 2> /dev/null::rw-psk.*INSTALLED, TUNNEL::YES
|
|
carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*[email protected].*\[PH_IP_MOON]::YES
|
|
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with RSA.* successful::YES
|
|
moon:: cat /var/log/daemon.log::authentication of 'moon.strongswan.org' (myself) with RSA.* successful::YES
|
|
moon:: ipsec status 2> /dev/null::rw-rsasig.*INSTALLED, TUNNEL::YES
|
|
dave:: ipsec status 2> /dev/null::home.*ESTABLISHED.*[email protected].*moon.strongswan.org::YES
|
|
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_req=1::YES
|
|
dave:: ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_req=1::YES
|
|
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES
|
|
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
|
|
moon::tcpdump::IP dave.strongswan.org > moon.strongswan.org: ESP::YES
|
|
moon::tcpdump::IP moon.strongswan.org > dave.strongswan.org: ESP::YES
|