FIPS Product: YES FIPS Kernel: NO FIPS Mode: NO NSS DB directory: sql:/etc/ipsec.d Initializing NSS Opening NSS database "sql:/etc/ipsec.d" read-only NSS initialized NSS crypto library initialized FIPS HMAC integrity support [enabled] FIPS mode disabled for pluto daemon FIPS HMAC integrity verification self-test FAILED libcap-ng support [enabled] Linux audit support [enabled] Linux audit activated Starting Pluto (Libreswan Version v3.28-685-gbfd5aef521-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:28794 core dump dir: /run/pluto secrets file: /etc/ipsec.secrets leak-detective enabled NSS crypto [enabled] XAUTH PAM support [enabled] | libevent is using pluto's memory allocator Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) | libevent_malloc: new ptr-libevent@0x5579652636f8 size 40 | libevent_malloc: new ptr-libevent@0x557965263678 size 40 | libevent_malloc: new ptr-libevent@0x5579652635f8 size 40 | creating event base | libevent_malloc: new ptr-libevent@0x557965255228 size 56 | libevent_malloc: new ptr-libevent@0x5579651dedb8 size 664 | libevent_malloc: new ptr-libevent@0x55796529dd18 size 24 | libevent_malloc: new ptr-libevent@0x55796529dd68 size 384 | libevent_malloc: new ptr-libevent@0x55796529dcd8 size 16 | libevent_malloc: new ptr-libevent@0x557965263578 size 40 | libevent_malloc: new ptr-libevent@0x5579652634f8 size 48 | libevent_realloc: new ptr-libevent@0x5579651dea48 size 256 | libevent_malloc: new ptr-libevent@0x55796529df18 size 16 | libevent_free: release ptr-libevent@0x557965255228 | libevent initialized | libevent_realloc: new ptr-libevent@0x557965255228 size 64 | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds | init_nat_traversal() initialized with keep_alive=0s NAT-Traversal support [enabled] | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized | global one-shot timer EVENT_FREE_ROOT_CERTS initialized | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds | global one-shot timer EVENT_REVIVE_CONNS initialized | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Encryption algorithms: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac NULL IKEv1: ESP IKEv2: ESP [] CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Hash algorithms: MD5 IKEv1: IKE IKEv2: SHA1 IKEv1: IKE IKEv2: FIPS sha SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 PRF algorithms: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Integrity algorithms: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac NONE IKEv1: ESP IKEv2: IKE ESP FIPS null DH algorithms: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 testing CAMELLIA_CBC: Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 256-bit key Camellia: 16 bytes with 256-bit key testing AES_GCM_16: empty string one block two blocks two blocks with associated data testing AES_CTR: Encrypting 16 octets using AES-CTR with 128-bit key Encrypting 32 octets using AES-CTR with 128-bit key Encrypting 36 octets using AES-CTR with 128-bit key Encrypting 16 octets using AES-CTR with 192-bit key Encrypting 32 octets using AES-CTR with 192-bit key Encrypting 36 octets using AES-CTR with 192-bit key Encrypting 16 octets using AES-CTR with 256-bit key Encrypting 32 octets using AES-CTR with 256-bit key Encrypting 36 octets using AES-CTR with 256-bit key testing AES_CBC: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key testing AES_XCBC: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) testing HMAC_MD5: RFC 2104: MD5_HMAC test 1 RFC 2104: MD5_HMAC test 2 RFC 2104: MD5_HMAC test 3 8 CPU cores online starting up 7 crypto helpers started thread for crypto helper 0 | starting up helper thread 0 | status value returned by setting the priority of this thread (crypto helper 0) 22 | crypto helper 0 waiting (nothing to do) started thread for crypto helper 1 | starting up helper thread 1 | status value returned by setting the priority of this thread (crypto helper 1) 22 | crypto helper 1 waiting (nothing to do) started thread for crypto helper 2 | starting up helper thread 2 | status value returned by setting the priority of this thread (crypto helper 2) 22 | crypto helper 2 waiting (nothing to do) started thread for crypto helper 3 | starting up helper thread 3 | status value returned by setting the priority of this thread (crypto helper 3) 22 | crypto helper 3 waiting (nothing to do) started thread for crypto helper 4 | starting up helper thread 4 | status value returned by setting the priority of this thread (crypto helper 4) 22 | crypto helper 4 waiting (nothing to do) started thread for crypto helper 5 | starting up helper thread 5 | status value returned by setting the priority of this thread (crypto helper 5) 22 | crypto helper 5 waiting (nothing to do) started thread for crypto helper 6 | checking IKEv1 state table | starting up helper thread 6 | status value returned by setting the priority of this thread (crypto helper 6) 22 | MAIN_R0: category: half-open IKE SA flags: 0: | -> MAIN_R1 EVENT_SO_DISCARD | MAIN_I1: category: half-open IKE SA flags: 0: | -> MAIN_I2 EVENT_RETRANSMIT | crypto helper 6 waiting (nothing to do) | MAIN_R1: category: open IKE SA flags: 200: | -> MAIN_R2 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_I2: category: open IKE SA flags: 0: | -> MAIN_I3 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_R2: category: open IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | -> MAIN_R3 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_I3: category: open IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | -> MAIN_I4 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_R3: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | MAIN_I4: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | AGGR_R0: category: half-open IKE SA flags: 0: | -> AGGR_R1 EVENT_SO_DISCARD | AGGR_I1: category: half-open IKE SA flags: 0: | -> AGGR_I2 EVENT_SA_REPLACE | -> AGGR_I2 EVENT_SA_REPLACE | AGGR_R1: category: open IKE SA flags: 200: | -> AGGR_R2 EVENT_SA_REPLACE | -> AGGR_R2 EVENT_SA_REPLACE | AGGR_I2: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | AGGR_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | QUICK_R0: category: established CHILD SA flags: 0: | -> QUICK_R1 EVENT_RETRANSMIT | QUICK_I1: category: established CHILD SA flags: 0: | -> QUICK_I2 EVENT_SA_REPLACE | QUICK_R1: category: established CHILD SA flags: 0: | -> QUICK_R2 EVENT_SA_REPLACE | QUICK_I2: category: established CHILD SA flags: 200: | -> UNDEFINED EVENT_NULL | QUICK_R2: category: established CHILD SA flags: 0: | -> UNDEFINED EVENT_NULL | INFO: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | INFO_PROTECTED: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | XAUTH_R0: category: established IKE SA flags: 0: | -> XAUTH_R1 EVENT_NULL | XAUTH_R1: category: established IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | MODE_CFG_R0: category: informational flags: 0: | -> MODE_CFG_R1 EVENT_SA_REPLACE | MODE_CFG_R1: category: established IKE SA flags: 0: | -> MODE_CFG_R2 EVENT_SA_REPLACE | MODE_CFG_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | MODE_CFG_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | XAUTH_I0: category: established IKE SA flags: 0: | -> XAUTH_I1 EVENT_RETRANSMIT | XAUTH_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_RETRANSMIT | checking IKEv2 state table | PARENT_I0: category: ignore flags: 0: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) | PARENT_I1: category: half-open IKE SA flags: 0: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) | PARENT_I2: category: open IKE SA flags: 0: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) | PARENT_I3: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) | PARENT_R0: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) | PARENT_R1: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) | PARENT_R2: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) | V2_CREATE_I0: category: established IKE SA flags: 0: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) | V2_CREATE_I: category: established IKE SA flags: 0: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) | V2_REKEY_IKE_I: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: | V2_CREATE_R: category: established IKE SA flags: 0: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) | V2_REKEY_IKE_R: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: | V2_IPSEC_I: category: established CHILD SA flags: 0: | V2_IPSEC_R: category: established CHILD SA flags: 0: | IKESA_DEL: category: established IKE SA flags: 0: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) | CHILDSA_DEL: category: informational flags: 0: Using Linux XFRM/NETKEY IPsec interface code on 5.1.18-200.fc29.x86_64 | Hard-wiring algorithms | adding AES_CCM_16 to kernel algorithm db | adding AES_CCM_12 to kernel algorithm db | adding AES_CCM_8 to kernel algorithm db | adding 3DES_CBC to kernel algorithm db | adding CAMELLIA_CBC to kernel algorithm db | adding AES_GCM_16 to kernel algorithm db | adding AES_GCM_12 to kernel algorithm db | adding AES_GCM_8 to kernel algorithm db | adding AES_CTR to kernel algorithm db | adding AES_CBC to kernel algorithm db | adding SERPENT_CBC to kernel algorithm db | adding TWOFISH_CBC to kernel algorithm db | adding NULL_AUTH_AES_GMAC to kernel algorithm db | adding NULL to kernel algorithm db | adding CHACHA20_POLY1305 to kernel algorithm db | adding HMAC_MD5_96 to kernel algorithm db | adding HMAC_SHA1_96 to kernel algorithm db | adding HMAC_SHA2_512_256 to kernel algorithm db | adding HMAC_SHA2_384_192 to kernel algorithm db | adding HMAC_SHA2_256_128 to kernel algorithm db | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db | adding AES_XCBC_96 to kernel algorithm db | adding AES_CMAC_96 to kernel algorithm db | adding NONE to kernel algorithm db | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds | setup kernel fd callback | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x55796525d418 | libevent_malloc: new ptr-libevent@0x55796529c488 size 128 | libevent_malloc: new ptr-libevent@0x5579652a3518 size 16 | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x5579652a34a8 | libevent_malloc: new ptr-libevent@0x557965255ed8 size 128 | libevent_malloc: new ptr-libevent@0x5579652a3178 size 16 | global one-shot timer EVENT_CHECK_CRLS initialized selinux support is enabled. | unbound context created - setting debug level to 5 | /etc/hosts lookups activated | /etc/resolv.conf usage activated | outgoing-port-avoid set 0-65535 | outgoing-port-permit set 32768-60999 | Loading dnssec root key from:/var/lib/unbound/root.key | No additional dnssec trust anchors defined via dnssec-trusted= option | Setting up events, loop start | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x5579652a3948 | libevent_malloc: new ptr-libevent@0x5579652af828 size 128 | libevent_malloc: new ptr-libevent@0x5579652bab18 size 16 | libevent_realloc: new ptr-libevent@0x5579652bab58 size 256 | libevent_malloc: new ptr-libevent@0x5579652bac88 size 8 | libevent_realloc: new ptr-libevent@0x5579652bacc8 size 144 | libevent_malloc: new ptr-libevent@0x5579652619e8 size 152 | libevent_malloc: new ptr-libevent@0x5579652bad88 size 16 | signal event handler PLUTO_SIGCHLD installed | libevent_malloc: new ptr-libevent@0x5579652badc8 size 8 | libevent_malloc: new ptr-libevent@0x5579651df728 size 152 | signal event handler PLUTO_SIGTERM installed | libevent_malloc: new ptr-libevent@0x5579652bae08 size 8 | libevent_malloc: new ptr-libevent@0x5579652bae48 size 152 | signal event handler PLUTO_SIGHUP installed | libevent_malloc: new ptr-libevent@0x5579652baf18 size 8 | libevent_realloc: release ptr-libevent@0x5579652bacc8 | libevent_realloc: new ptr-libevent@0x5579652baf58 size 256 | libevent_malloc: new ptr-libevent@0x5579652bb088 size 152 | signal event handler PLUTO_SIGSYS installed | created addconn helper (pid:28913) using fork+execve | forked child 28913 | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.2.254 | Inspecting interface eth1 | found eth1 with address 192.1.2.23 Kernel supports NIC esp-hw-offload adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.2.23:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth1/eth1 192.1.2.23:4500 adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.2.254:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0/eth0 192.0.2.254:4500 adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface lo/lo 127.0.0.1:4500 | no interfaces to sort | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | add_fd_read_event_handler: new ethX-pe@0x5579652bb668 | libevent_malloc: new ptr-libevent@0x5579652af778 size 128 | libevent_malloc: new ptr-libevent@0x5579652bb6d8 size 16 | setup callback for interface lo 127.0.0.1:4500 fd 22 | add_fd_read_event_handler: new ethX-pe@0x5579652bb718 | libevent_malloc: new ptr-libevent@0x557965255f88 size 128 | libevent_malloc: new ptr-libevent@0x5579652bb788 size 16 | setup callback for interface lo 127.0.0.1:500 fd 21 | add_fd_read_event_handler: new ethX-pe@0x5579652bb7c8 | libevent_malloc: new ptr-libevent@0x5579652558a8 size 128 | libevent_malloc: new ptr-libevent@0x5579652bb838 size 16 | setup callback for interface eth0 192.0.2.254:4500 fd 20 | add_fd_read_event_handler: new ethX-pe@0x5579652bb878 | libevent_malloc: new ptr-libevent@0x55796525d168 size 128 | libevent_malloc: new ptr-libevent@0x5579652bb8e8 size 16 | setup callback for interface eth0 192.0.2.254:500 fd 19 | add_fd_read_event_handler: new ethX-pe@0x5579652bb928 | libevent_malloc: new ptr-libevent@0x55796525d268 size 128 | libevent_malloc: new ptr-libevent@0x5579652bb998 size 16 | setup callback for interface eth1 192.1.2.23:4500 fd 18 | add_fd_read_event_handler: new ethX-pe@0x5579652bb9d8 | libevent_malloc: new ptr-libevent@0x55796525d368 size 128 | libevent_malloc: new ptr-libevent@0x5579652bba48 size 16 | setup callback for interface eth1 192.1.2.23:500 fd 17 | certs and keys locked by 'free_preshared_secrets' | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | saving Modulus | saving PublicExponent | ignoring PrivateExponent | ignoring Prime1 | ignoring Prime2 | ignoring Exponent1 | ignoring Exponent2 | ignoring Coefficient | ignoring CKAIDNSS | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 | computed rsa CKAID 8a 82 25 f1 loaded private key for keyid: PKK_RSA:AQO9bJbr3 | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.967 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.2.254 | Inspecting interface eth1 | found eth1 with address 192.1.2.23 | no interfaces to sort | libevent_free: release ptr-libevent@0x5579652af778 | free_event_entry: release EVENT_NULL-pe@0x5579652bb668 | add_fd_read_event_handler: new ethX-pe@0x5579652bb668 | libevent_malloc: new ptr-libevent@0x5579652af778 size 128 | setup callback for interface lo 127.0.0.1:4500 fd 22 | libevent_free: release ptr-libevent@0x557965255f88 | free_event_entry: release EVENT_NULL-pe@0x5579652bb718 | add_fd_read_event_handler: new ethX-pe@0x5579652bb718 | libevent_malloc: new ptr-libevent@0x557965255f88 size 128 | setup callback for interface lo 127.0.0.1:500 fd 21 | libevent_free: release ptr-libevent@0x5579652558a8 | free_event_entry: release EVENT_NULL-pe@0x5579652bb7c8 | add_fd_read_event_handler: new ethX-pe@0x5579652bb7c8 | libevent_malloc: new ptr-libevent@0x5579652558a8 size 128 | setup callback for interface eth0 192.0.2.254:4500 fd 20 | libevent_free: release ptr-libevent@0x55796525d168 | free_event_entry: release EVENT_NULL-pe@0x5579652bb878 | add_fd_read_event_handler: new ethX-pe@0x5579652bb878 | libevent_malloc: new ptr-libevent@0x55796525d168 size 128 | setup callback for interface eth0 192.0.2.254:500 fd 19 | libevent_free: release ptr-libevent@0x55796525d268 | free_event_entry: release EVENT_NULL-pe@0x5579652bb928 | add_fd_read_event_handler: new ethX-pe@0x5579652bb928 | libevent_malloc: new ptr-libevent@0x55796525d268 size 128 | setup callback for interface eth1 192.1.2.23:4500 fd 18 | libevent_free: release ptr-libevent@0x55796525d368 | free_event_entry: release EVENT_NULL-pe@0x5579652bb9d8 | add_fd_read_event_handler: new ethX-pe@0x5579652bb9d8 | libevent_malloc: new ptr-libevent@0x55796525d368 size 128 | setup callback for interface eth1 192.1.2.23:500 fd 17 | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | saving Modulus | saving PublicExponent | ignoring PrivateExponent | ignoring Prime1 | ignoring Prime2 | ignoring Exponent1 | ignoring Exponent2 | ignoring Coefficient | ignoring CKAIDNSS | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 | computed rsa CKAID 8a 82 25 f1 loaded private key for keyid: PKK_RSA:AQO9bJbr3 | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.707 milliseconds in whack | processing signal PLUTO_SIGCHLD | waitpid returned pid 28913 (exited with status 0) | reaped addconn helper child (status 0) | waitpid returned ECHILD (no child processes left) | spent 0.0143 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection nss-cert with policy ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | counting wild cards for %fromcert is 0 | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org" | ASCII to DN => 30 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 25 30 23 06 03 55 04 03 13 1c 4c 69 62 | ASCII to DN => 72 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 | ASCII to DN => 6f 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a | ASCII to DN => 86 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e | ASCII to DN => 67 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 | setting ID to ID_DER_ASN1_DN: 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading right certificate 'east' pubkey | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5579652c0a58 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5579652c09e8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5579652c08a8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5579652bfe18 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5579652bfdc8 | unreference key: 0x5579652c0aa8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | certs and keys locked by 'lsw_add_rsa_secret' | certs and keys unlocked by 'lsw_add_rsa_secret' | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@(nil): none | new hp@0x5579652c0d68 added connection description "nss-cert" | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.2.254/32===192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]...192.1.2.45<192.1.2.45>[%fromcert]===192.0.1.254/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.35 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.416 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | old debugging base+cpu-usage + none | base debugging = base+cpu-usage | old impairing none + suppress-retransmits | base impairing = suppress-retransmits | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.0813 milliseconds in whack | spent 0.00244 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 792 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 10 5e 9f 7c c0 6d e9 67 00 00 00 00 00 00 00 00 | 01 10 02 00 00 00 00 00 00 00 03 18 0d 00 02 84 | 00 00 00 01 00 00 00 01 00 00 02 78 00 01 00 12 | 03 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 01 01 00 00 80 0b 00 01 | 80 0c 0e 10 80 01 00 07 80 02 00 04 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 02 01 00 00 | 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 06 | 80 03 00 03 80 04 00 0e 80 0e 01 00 03 00 00 24 | 03 01 00 00 80 0b 00 01 80 0c 0e 10 80 01 00 07 | 80 02 00 06 80 03 00 03 80 04 00 0e 80 0e 00 80 | 03 00 00 24 04 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 05 01 00 00 80 0b 00 01 | 80 0c 0e 10 80 01 00 07 80 02 00 02 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 06 01 00 00 | 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 04 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 07 01 00 00 80 0b 00 01 80 0c 0e 10 80 01 00 07 | 80 02 00 04 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 24 08 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 06 80 03 00 03 80 04 00 05 | 80 0e 01 00 03 00 00 24 09 01 00 00 80 0b 00 01 | 80 0c 0e 10 80 01 00 07 80 02 00 06 80 03 00 03 | 80 04 00 05 80 0e 00 80 03 00 00 24 0a 01 00 00 | 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 02 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 0b 01 00 00 80 0b 00 01 80 0c 0e 10 80 01 00 07 | 80 02 00 02 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 20 0c 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 0e | 03 00 00 20 0d 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 0e | 03 00 00 20 0e 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 0e | 03 00 00 20 0f 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 05 | 03 00 00 20 10 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 05 | 00 00 00 20 11 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 05 | 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de 7f | 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 c9 | 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c 81 | 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 | 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 | ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 f8 | 7c fd b2 fc 68 b6 a4 48 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 10 5e 9f 7c c0 6d e9 67 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 792 (0x318) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: IKEv1 state not found (find_state_ikev1_init) | #null state always idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x2 opt: 0x2080 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 644 (0x284) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | message 'main_inI1_outR1' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | in statetime_start() with no state | find_host_connection local=192.1.2.23:500 remote=192.1.2.45:500 policy=IKEV1_ALLOW but ignoring ports | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (nss-cert) | find_next_host_connection returns nss-cert | find_next_host_connection policy=IKEV1_ALLOW | find_next_host_connection returns empty | creating state object #1 at 0x5579652c4dc8 | State DB: adding IKEv1 state #1 in UNDEFINED | pstats #1 ikev1.isakmp started | #1 updating local interface from to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2669) | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in main_inI1_outR1() at ikev1_main.c:667) | parent state #1: UNDEFINED(ignore) => MAIN_R0(half-open IKE SA) | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) "nss-cert" #1: responding to Main Mode | **emit ISAKMP Message: | initiator cookie: | 10 5e 9f 7c c0 6d e9 67 | responder cookie: | 0c 59 b4 31 23 61 09 c0 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 632 (0x278) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 18 (0x12) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | OAKLEY proposal verified unconditionally; no alg_info to check against | Oakley Transform 0 accepted | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | emitting 28 raw bytes of attributes into ISAKMP Transform Payload (ISAKMP) | attributes 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 04 | attributes 80 03 00 03 80 04 00 0e 80 0e 01 00 | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | no IKEv1 message padding required | emitting length of ISAKMP Message: 144 | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1 | parent state #1: MAIN_R0(half-open IKE SA) => MAIN_R1(open IKE SA) | event_already_set, deleting event | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 144 bytes for STATE_MAIN_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 10 5e 9f 7c c0 6d e9 67 0c 59 b4 31 23 61 09 c0 | 01 10 02 00 00 00 00 00 00 00 00 90 0d 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 0d 00 00 14 40 48 b7 d5 6e bc e8 85 | 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 00 00 00 14 | 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | !event_already_set at reschedule | event_schedule: new EVENT_SO_DISCARD-pe@0x5579652c1868 | inserting event EVENT_SO_DISCARD, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5579652bfd18 size 128 "nss-cert" #1: STATE_MAIN_R1: sent MR1, expecting MI2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.437 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00246 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 396 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 10 5e 9f 7c c0 6d e9 67 0c 59 b4 31 23 61 09 c0 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 3e 53 3f 54 a0 02 7c 00 5d e5 7b fd 6f 0d 94 53 | 09 a9 3a 48 b1 47 26 61 db 0c 5c aa 06 9c f7 8f | ed a5 38 7f 3e 30 3d 44 cc 52 66 0e ee ab a4 40 | cc f9 c0 e8 8a 47 2b 32 10 fa 27 be 19 dc 32 76 | 3a ae 64 72 ec 81 b9 7e c5 b8 34 6d 9c 80 be 5b | b4 a6 29 bd b8 d6 d8 6d 7b 79 01 e6 48 d6 4e 85 | fe 0e 3e a7 81 9a 5f c3 9a b2 f2 82 06 5b 04 70 | b6 66 44 03 1f 78 1a 8d 17 e0 75 98 47 af a4 c9 | c8 6f 3e 5b 2c 28 47 71 56 fb 2d 9d 82 9c 6c ef | eb 69 ff ba 76 2b 9a e2 d0 a2 59 fc 92 89 02 54 | df 49 e6 79 1b 2c 0d 15 70 86 27 5e 7b 55 16 dd | 72 f9 46 55 62 b4 36 e8 36 3d 29 fa 9e 00 a0 ea | 0f a2 89 00 2a de 97 99 9e e4 a8 1f c2 26 68 da | 8f 7b a5 ee c8 31 87 59 8f d2 1c 7f 83 dd 07 cc | eb 6f 8b 34 41 0a 7b 13 fc 21 78 a4 ea c8 2b 7a | 22 5d 81 90 c7 b5 b7 f0 f6 c2 32 3c 2f a2 5c 31 | 14 00 00 24 7c c5 a4 b4 0b 7f e8 b0 5e ca 3f 7e | d5 f5 e6 73 ce 5b 93 38 7b c9 13 93 b1 7e 00 09 | ed a8 4f f7 14 00 00 24 d5 50 de aa 82 6a ce 0d | 83 15 c1 3c 2e 0d 48 2c 2b bd 88 b2 51 5d 1f 78 | 96 df e1 c3 d6 1d 1b 73 00 00 00 24 2e db 95 6d | f1 85 b5 79 77 1c aa c1 bd ca 0b 31 05 6f 2f ef | f8 36 1a d7 ea c7 3c 99 f7 2a 80 8f | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 10 5e 9f 7c c0 6d e9 67 | responder cookie: | 0c 59 b4 31 23 61 09 c0 | next payload type: ISAKMP_NEXT_KE (0x4) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 396 (0x18c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #1 in MAIN_R1 (find_state_ikev1) | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x410 opt: 0x102080 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x102080 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | message 'main_inI2_outR2' HASH payload not checked early | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= 10 5e 9f 7c c0 6d e9 67 | natd_hash: rcookie= 0c 59 b4 31 23 61 09 c0 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= d5 50 de aa 82 6a ce 0d 83 15 c1 3c 2e 0d 48 2c | natd_hash: hash= 2b bd 88 b2 51 5d 1f 78 96 df e1 c3 d6 1d 1b 73 | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= 10 5e 9f 7c c0 6d e9 67 | natd_hash: rcookie= 0c 59 b4 31 23 61 09 c0 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 2e db 95 6d f1 85 b5 79 77 1c aa c1 bd ca 0b 31 | natd_hash: hash= 05 6f 2f ef f8 36 1a d7 ea c7 3c 99 f7 2a 80 8f | expected NAT-D(me): d5 50 de aa 82 6a ce 0d 83 15 c1 3c 2e 0d 48 2c | expected NAT-D(me): 2b bd 88 b2 51 5d 1f 78 96 df e1 c3 d6 1d 1b 73 | expected NAT-D(him): | 2e db 95 6d f1 85 b5 79 77 1c aa c1 bd ca 0b 31 | 05 6f 2f ef f8 36 1a d7 ea c7 3c 99 f7 2a 80 8f | received NAT-D: d5 50 de aa 82 6a ce 0d 83 15 c1 3c 2e 0d 48 2c | received NAT-D: 2b bd 88 b2 51 5d 1f 78 96 df e1 c3 d6 1d 1b 73 | received NAT-D: 2e db 95 6d f1 85 b5 79 77 1c aa c1 bd ca 0b 31 | received NAT-D: 05 6f 2f ef f8 36 1a d7 ea c7 3c 99 f7 2a 80 8f | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.45 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | adding inI2_outR2 KE work-order 1 for state #1 | state #1 requesting EVENT_SO_DISCARD to be deleted | libevent_free: release ptr-libevent@0x5579652bfd18 | free_event_entry: release EVENT_SO_DISCARD-pe@0x5579652c1868 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5579652c18d8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #1 and saving MD | #1 is busy; has a suspended MD | crypto helper 0 resuming | #1 spent 0.124 milliseconds in process_packet_tail() | crypto helper 0 starting work-order 1 for state #1 | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | crypto helper 0 doing build KE and nonce (inI2_outR2 KE); request ID 1 | stop processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.28 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 0 finished build KE and nonce (inI2_outR2 KE); request ID 1 time elapsed 0.001024 seconds | (#1) spent 1.03 milliseconds in crypto helper computing work-order 1: inI2_outR2 KE (pcr) | crypto helper 0 sending results from work-order 1 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f28f4002888 size 128 | crypto helper 0 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 0 replies to request ID 1 | calling continuation function 0x557964f2ab50 | main_inI2_outR2_continue for #1: calculated ke+nonce, sending R2 | **emit ISAKMP Message: | initiator cookie: | 10 5e 9f 7c c0 6d e9 67 | responder cookie: | 0c 59 b4 31 23 61 09 c0 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 09 12 ac f4 61 be 7e ce 85 f3 f1 3f c2 45 55 cf | keyex value 92 8a 91 52 cf 78 15 83 83 bb 8d dc 8d e4 77 ed | keyex value 94 69 05 23 9d 86 52 55 1c 07 20 73 7a 52 8d f2 | keyex value 77 94 5a 8e 18 57 da 68 e0 12 95 ce fa 73 47 4b | keyex value d0 6e d0 88 29 4a ce 24 bc 3d 1d dd 3c 59 ea 6e | keyex value 94 e5 9b a9 00 66 55 20 92 e8 83 f5 3e 7d 08 a3 | keyex value 83 40 f3 51 eb 74 a1 14 c4 d6 e1 49 07 60 69 c5 | keyex value 2a f9 87 4e 3a d0 4f ce 2f c9 78 a0 97 78 4c 9a | keyex value 55 f3 08 31 b7 af 73 b5 93 64 d4 a7 56 32 1b 2b | keyex value e3 ff 45 fd 28 40 5a 14 3d 5f 1c 9e 0d 15 07 e4 | keyex value 1f b3 69 34 fc 3b 5d 89 d4 a0 8f 69 1e f7 4a 92 | keyex value 94 19 8b c9 fa 52 48 cb f1 a8 cb 1b a5 54 23 2a | keyex value 0e e2 ef 96 dc a4 47 9f 71 90 54 05 3e a1 ef 34 | keyex value 0c b6 a0 41 05 6a 76 f9 a9 6d dd d9 a5 46 98 c6 | keyex value 94 55 90 79 4a 92 fa a1 29 86 98 b1 fd 86 4b 29 | keyex value 45 2e 7a 13 c6 0c ae 3f 99 8d b9 14 f3 49 61 56 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 3f 00 4a 09 46 9b 6f 8d b3 43 69 27 7d f2 58 f1 | Nr b4 2a 89 d6 76 17 76 e1 f3 c9 26 b4 20 a3 45 eb | emitting length of ISAKMP Nonce Payload: 36 | sending NAT-D payloads | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= 10 5e 9f 7c c0 6d e9 67 | natd_hash: rcookie= 0c 59 b4 31 23 61 09 c0 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 2e db 95 6d f1 85 b5 79 77 1c aa c1 bd ca 0b 31 | natd_hash: hash= 05 6f 2f ef f8 36 1a d7 ea c7 3c 99 f7 2a 80 8f | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D 2e db 95 6d f1 85 b5 79 77 1c aa c1 bd ca 0b 31 | NAT-D 05 6f 2f ef f8 36 1a d7 ea c7 3c 99 f7 2a 80 8f | emitting length of ISAKMP NAT-D Payload: 36 | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= 10 5e 9f 7c c0 6d e9 67 | natd_hash: rcookie= 0c 59 b4 31 23 61 09 c0 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= d5 50 de aa 82 6a ce 0d 83 15 c1 3c 2e 0d 48 2c | natd_hash: hash= 2b bd 88 b2 51 5d 1f 78 96 df e1 c3 d6 1d 1b 73 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D d5 50 de aa 82 6a ce 0d 83 15 c1 3c 2e 0d 48 2c | NAT-D 2b bd 88 b2 51 5d 1f 78 96 df e1 c3 d6 1d 1b 73 | emitting length of ISAKMP NAT-D Payload: 36 | no IKEv1 message padding required | emitting length of ISAKMP Message: 396 | main inI2_outR2: starting async DH calculation (group=14) | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->%fromcert of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->%fromcert of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding main_inI2_outR2_tail work-order 2 for state #1 | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5579652c18d8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5579652c2138 size 128 | #1 main_inI2_outR2_continue1_tail:1165 st->st_calculating = FALSE; | complete v1 state transition with STF_OK | crypto helper 1 resuming | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle; has background offloaded task | crypto helper 1 starting work-order 2 for state #1 | doing_xauth:no, t_xauth_client_done:no | crypto helper 1 doing compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 2 | IKEv1: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2 | parent state #1: MAIN_R1(open IKE SA) => MAIN_R2(open IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5579652c2138 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 396 bytes for STATE_MAIN_R1 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 10 5e 9f 7c c0 6d e9 67 0c 59 b4 31 23 61 09 c0 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 09 12 ac f4 61 be 7e ce 85 f3 f1 3f c2 45 55 cf | 92 8a 91 52 cf 78 15 83 83 bb 8d dc 8d e4 77 ed | 94 69 05 23 9d 86 52 55 1c 07 20 73 7a 52 8d f2 | 77 94 5a 8e 18 57 da 68 e0 12 95 ce fa 73 47 4b | d0 6e d0 88 29 4a ce 24 bc 3d 1d dd 3c 59 ea 6e | 94 e5 9b a9 00 66 55 20 92 e8 83 f5 3e 7d 08 a3 | 83 40 f3 51 eb 74 a1 14 c4 d6 e1 49 07 60 69 c5 | 2a f9 87 4e 3a d0 4f ce 2f c9 78 a0 97 78 4c 9a | 55 f3 08 31 b7 af 73 b5 93 64 d4 a7 56 32 1b 2b | e3 ff 45 fd 28 40 5a 14 3d 5f 1c 9e 0d 15 07 e4 | 1f b3 69 34 fc 3b 5d 89 d4 a0 8f 69 1e f7 4a 92 | 94 19 8b c9 fa 52 48 cb f1 a8 cb 1b a5 54 23 2a | 0e e2 ef 96 dc a4 47 9f 71 90 54 05 3e a1 ef 34 | 0c b6 a0 41 05 6a 76 f9 a9 6d dd d9 a5 46 98 c6 | 94 55 90 79 4a 92 fa a1 29 86 98 b1 fd 86 4b 29 | 45 2e 7a 13 c6 0c ae 3f 99 8d b9 14 f3 49 61 56 | 14 00 00 24 3f 00 4a 09 46 9b 6f 8d b3 43 69 27 | 7d f2 58 f1 b4 2a 89 d6 76 17 76 e1 f3 c9 26 b4 | 20 a3 45 eb 14 00 00 24 2e db 95 6d f1 85 b5 79 | 77 1c aa c1 bd ca 0b 31 05 6f 2f ef f8 36 1a d7 | ea c7 3c 99 f7 2a 80 8f 00 00 00 24 d5 50 de aa | 82 6a ce 0d 83 15 c1 3c 2e 0d 48 2c 2b bd 88 b2 | 51 5d 1f 78 96 df e1 c3 d6 1d 1b 73 | !event_already_set at reschedule "nss-cert" #1: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x5579652c1868 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5579652c2138 size 128 | #1 STATE_MAIN_R2: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11415.927238 "nss-cert" #1: STATE_MAIN_R2: sent MR2, expecting MI3 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 0.299 milliseconds in resume sending helper answer | stop processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f28f4002888 | crypto helper 1 finished compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 2 time elapsed 0.001148 seconds | (#1) spent 1.15 milliseconds in crypto helper computing work-order 2: main_inI2_outR2_tail (pcr) | crypto helper 1 sending results from work-order 2 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f28ec000f48 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 2 | calling continuation function 0x557964f2ab50 | main_inI2_outR2_calcdone for #1: calculate DH finished | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1015) | stop processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1028) | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 0.0131 milliseconds in resume sending helper answer | processing: STOP state #0 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f28ec000f48 | spent 0.00306 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 2060 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | 10 5e 9f 7c c0 6d e9 67 0c 59 b4 31 23 61 09 c0 | 05 10 02 01 00 00 00 00 00 00 08 0c 80 f5 8e 03 | 35 c8 f4 6c 10 0a e6 8c 59 6b b2 47 a2 3d 69 97 | e1 a2 04 c7 51 f0 24 e6 e4 38 5b 30 d6 a8 bf 55 | b4 74 08 df b1 b8 c4 33 5d d1 2f 57 30 82 00 2c | 6f 9c df d3 fb 37 64 dc 40 5d 3c 27 e0 ec 86 2f | cc a4 34 95 80 0b db 44 f3 ac 19 57 a2 e7 2d 02 | 23 85 02 f0 89 0d a5 d3 9d 0c f9 23 9b 6f ae a0 | 27 1e eb 8a 52 05 90 41 24 38 50 a0 c3 72 0e 06 | 69 99 9c d0 6a 5b 4f 05 cb e6 74 27 ef 9f 22 d0 | d7 b2 ca af 0e 0a 60 3d a1 8c 3e 69 35 37 39 8a | e8 de 72 d0 4f 8e 04 e1 11 4c d1 56 80 94 0c 41 | d3 db 85 af a6 fd 31 be dc 36 23 9e 16 4a 63 bf | b9 46 ac 6c 41 69 8d 4e 8f 12 32 a9 92 a5 c7 8c | b9 1b c4 d3 f6 bd 80 43 2b 46 ca eb 87 e5 9c 28 | 2e 19 38 9e 85 53 f9 17 27 49 57 c2 f4 6a bd 51 | 45 20 69 c6 ce 4a a2 e1 8f 23 11 f9 b2 81 cb 4c | 4e 0d 61 08 a3 5c bf 29 ed 92 13 8b 93 09 a9 81 | ac 43 85 0a 8f d0 62 9a ac d4 4d 68 41 9a a7 5e | b3 bb ac f9 b9 2b 28 7f 3f fc b3 19 ed 40 a7 8c | 62 e1 97 46 d1 d8 a0 7f f8 fd 4f 23 3e c7 d7 c5 | 73 57 67 8b 1b 7b 1d b9 83 43 ca 01 53 c5 6a 10 | 90 ef 2f 27 30 41 66 fb bc b1 77 d9 77 22 95 ac | 09 90 37 90 71 e8 83 f5 25 b7 7a 39 2a 0b 48 b7 | c1 ea fa e8 31 04 65 1f 8e d3 a5 bb fa 64 c5 96 | c6 5b 1f fb 5b 9b 6a 03 7c 71 df a4 1d a7 81 3e | ff 0d ff 18 fe 0e 92 04 58 40 9a c2 87 c4 0d ac | 04 db bf 74 af 13 78 a3 24 fc dc 03 60 60 2c bd | 1f f0 f7 a2 72 6a ec dd 6a 30 d5 ef 10 fd ba 40 | ff 82 22 12 3a b3 73 7b 38 b2 c0 4d f9 f1 11 e3 | ba f6 d8 6c 6a b7 80 06 03 03 f7 8c c6 bb 50 35 | c7 c0 65 3e af fa e5 e2 d5 93 a1 ac 52 a9 f3 da | 11 54 1d 47 90 f5 70 94 48 b6 da 9f 8a 4d 5a c9 | 03 e4 cf 18 f0 59 69 90 2e 28 f6 35 3c 58 72 0c | 52 f9 7b 89 91 a0 d5 d6 2c b1 03 df e8 9a f2 24 | 6e 85 8b 7b 95 cf dd 33 8e f5 51 35 9a b5 de 3b | e1 37 1d c8 64 c2 1b 81 29 c4 3d 11 c4 09 23 86 | 41 8d dc f3 93 60 d3 eb f0 1d 0f ce e3 9e c8 97 | 88 bf b6 43 b3 4d d7 c1 22 3c 72 d5 27 55 5f 99 | 8a 54 b4 b1 e8 9d cb 8f 03 23 56 e6 1f b4 f0 8d | c4 7b a9 5b 27 ac 1a ce de 85 97 df 3a 82 32 77 | 2c c8 41 40 1c b7 05 5a 3f 06 89 f2 d1 21 81 55 | f6 5c 33 a7 4e d2 b4 b5 e1 40 d1 7e a9 49 aa 71 | 40 2a 58 c2 5f fe 4d 6a 3a f1 8e a8 d3 e9 63 0d | a5 3f de 52 c9 50 7a 21 3b 8b 66 ec 27 42 f8 ba | 15 97 05 ca 70 9d 7f 84 7e 3c 07 ea 1d ad 34 e0 | 59 da 48 47 a1 8c 27 cb f4 c7 7e 56 ce e4 1e fe | 67 05 71 36 32 0f a6 47 b7 60 82 45 e9 56 10 f3 | e5 51 c1 64 7f 28 7a 04 83 3a 32 9d b5 e4 c2 fa | d3 f2 f4 7f 55 1e 7e 1e 02 5a 60 e2 11 11 dd db | 45 be 51 80 81 09 9d f5 6a 15 90 2e ba 6f fd ce | 0b 3d 89 0e 7f f4 01 6a df b1 97 1c 88 e8 11 57 | 72 6c 1b d9 af cb a8 77 7b ce b9 21 f3 1e c3 eb | 39 23 10 3f e1 c6 6d bc d6 c2 46 fd be a5 e2 98 | 5b 9e 99 10 a3 f9 09 1a 14 e8 23 93 87 b7 e3 9b | 40 06 cf 12 b0 9f c6 8b e1 91 04 70 7f 62 62 e0 | 15 09 ad aa bb 44 11 7a 28 84 61 24 36 98 f7 c7 | 2a 29 89 3a d6 f1 69 58 a0 36 9c 9a 16 0f 0a 73 | 3f 5e e2 86 fa a0 ac 5c 53 85 7c 1e 1d 75 80 20 | 44 6c 20 e8 37 a5 46 71 0b 16 fb 8d 0e 0c c4 5b | 47 49 b6 ff 3c ee 6b 2f 2c df e9 da 3d af 56 ca | 7e 5b 78 41 66 01 6d 60 91 bc d0 a2 ac 78 4d 34 | 51 60 1a 84 6e 7d 18 bc 66 c5 65 c7 df 6e db d7 | 09 db a8 a9 0f e3 4d 7c 7e d1 89 65 e0 a0 82 45 | 6f bc 58 32 63 c3 4a 92 22 17 2c fe e7 47 56 26 | 0d da 06 f8 40 93 20 53 d7 5b 95 28 69 95 97 d9 | 7d ee 90 68 a9 87 2b 80 2d 7c 45 c8 1a 52 87 fb | 6d 77 8a 27 cf 24 47 52 db 43 ad ce 43 88 08 94 | 33 69 d8 ce 8f 05 95 61 7f 28 57 a0 28 f0 a5 01 | d9 82 15 42 dc f3 45 c3 0a 2b 6b a2 ea ed 11 0b | 4b 75 70 2f 82 3d 99 57 30 fd a1 24 87 95 b9 21 | 85 1d ba 94 eb 41 05 3f 5c 80 1a bb 06 f6 ec 56 | 40 50 a9 74 43 c1 c9 90 a0 a6 43 7b d1 25 b2 20 | 3d f6 aa 8d 2d 57 2e 94 ec ba 22 8d 4c 0a a5 5c | d4 24 1c 8e 3e 84 ad 02 c6 eb 15 16 ca f9 83 d1 | ca d5 60 a1 23 e7 d4 e7 33 b0 f0 bc c3 55 b0 ed | ce 1f c8 a6 81 6f 72 76 fb 19 87 52 25 d3 38 44 | 87 85 92 27 9f a2 d4 95 61 59 ee b1 07 42 74 57 | d1 78 54 d0 d6 af 87 3b 5c 8b f4 db c4 bf 3e 11 | c4 58 84 41 e9 1e 17 6f fe c2 3a 15 b8 c3 89 48 | 4d af 49 40 9a 11 23 b8 de 10 09 db bf bc ca af | b1 d5 90 c3 71 d2 69 76 1f bc 45 59 54 cc f5 36 | 57 1a ea a1 4c ed 87 2c 29 bc ef b4 f3 e5 fa ed | eb c4 d6 77 7d 13 0c 73 a5 0d a2 32 00 e2 d5 9d | 7f de 25 91 de 83 44 9a 28 dc 0f be d9 ad 51 ab | 7d 3a a7 d5 55 cc 19 bd 56 51 dc 2f f6 6b b1 93 | 51 7c 41 dd 3f 00 38 39 29 17 e6 c1 83 49 0c 43 | 0f 0b 4e df ec e4 8f 50 53 a6 61 eb 5d bb 1e 54 | 2f db 57 cb eb 29 cb 73 06 2b d0 9b 65 27 95 aa | 2c f5 5b 4f f2 48 ae ee 94 3c 33 3f de 8e f1 7e | 44 1a 1c 02 4a f2 21 cf be 04 b6 ca cc 4a ec 9e | 7f 86 9e 65 2b 7d 24 46 f5 86 2b 4c 66 d8 a7 77 | ee 2e 7c 84 24 25 79 08 cc a3 17 61 85 04 b9 1a | 68 bd b2 fb 37 21 6b 17 bf 90 74 e0 0a f2 db a4 | 62 54 9f f9 38 b1 7e cd b4 32 4b df aa 3f b2 93 | ab 52 2d 59 70 45 0c aa 5c bd d8 9e 02 af 59 ba | 57 04 47 4b 03 94 c6 b2 54 a2 b7 3e 69 b4 14 76 | d2 0a aa cc 1c de b1 73 6d 06 da 3a 27 2d b5 ed | d9 c0 a5 9f 93 c6 fe a7 cd c2 3d 1e 01 75 04 8c | b7 54 67 71 3f eb 5a 85 8c a3 a9 39 0f ea 6f bd | be 8e 94 99 72 f4 a8 78 f1 68 92 80 3d 8d c1 84 | 8b de 18 62 7e f8 eb 19 81 d0 ad b5 56 50 02 8f | cc eb 4c 4e 65 b1 db fe 41 ba 10 9b 6a 28 46 e8 | 04 c6 62 9c d9 8e cb 68 ab a4 f8 d3 ea da 9b 8c | f4 ca e6 ce 27 89 42 43 e5 98 0b 98 85 e8 1a 2f | de 67 f5 4f 42 78 d1 e7 af 3a 9c bd 01 18 32 49 | 38 ca 61 76 0d 91 77 5e 7f 58 44 f7 9d 8e a9 69 | 1c 37 fe 3a 51 32 46 9f 41 84 ec 63 25 34 bd 19 | 57 2f f2 db 3a 43 75 0a 43 66 ff 96 d7 c2 87 81 | 65 e3 6c bf de 99 5a 4e 6b ac 58 6e 65 b1 c9 6b | c2 91 8d 02 26 2a 0c fb 00 17 bf e9 a2 dd 79 61 | 44 cd 00 ee ec 0e 77 01 15 f6 c1 37 92 3e 52 bf | 05 75 c6 2d c8 53 71 16 60 cf 0c c7 5e e6 2b b7 | a1 33 eb 32 7c a2 92 e6 26 d8 cd 16 5e 00 64 53 | 87 7a fa 53 e6 7a 28 e8 c0 97 f3 cd 50 d1 1d 5e | 1d 05 99 67 bd 62 e4 c5 9e 8c 10 ae 44 bb 2f 83 | 31 6f bd cc 6a 60 a5 0f fd 75 73 00 a0 d7 31 9e | aa c4 7e 6c 2b 8b bd 92 c7 68 aa 0a 97 c2 3d e8 | 09 34 da b0 91 8a da 37 ad 59 97 33 6b d0 40 06 | 1b 23 0c 4c e4 4a 85 67 1d 6d 3d 54 ec 92 29 70 | 1f 75 1a 30 0c 9d 6d 0b f9 48 2e 00 20 a6 88 df | 55 a8 7f 80 61 c4 b3 24 41 ed d7 75 36 8f b6 96 | 0d db 76 ea 96 5c 70 2c b5 04 96 1f 76 77 77 a2 | f0 b9 85 ad 14 15 1b cb 5c 50 76 a9 2f fb b2 f0 | 14 e6 b5 ed 65 f5 f3 76 61 1f dc 7c 6e f4 a7 e8 | 7a 97 5b 9e 91 52 d3 f5 af 0d e4 cc 48 7d 06 54 | 91 ff 52 20 61 18 3f 40 92 19 84 f7 f3 11 40 cf | d8 9c 86 46 db 7b 8a 8d a9 bd a6 dd 6f 3a 13 61 | 01 1d 20 c4 48 a5 8c e9 b6 79 4c ba | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 10 5e 9f 7c c0 6d e9 67 | responder cookie: | 0c 59 b4 31 23 61 09 c0 | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 2060 (0x80c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #1 in MAIN_R2 (find_state_ikev1) | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x20c0 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 207 (0xcf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 c4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 2a 30 28 06 03 55 04 03 0c 21 73 69 67 | obj: 6e 65 64 62 79 6f 74 68 65 72 2e 6f 74 68 65 72 | obj: 2e 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 31 37 | obj: 30 35 06 09 2a 86 48 86 f7 0d 01 09 01 16 28 75 | obj: 73 65 72 2d 73 69 67 6e 65 64 62 79 6f 74 68 65 | obj: 72 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | length: 1253 (0x4e5) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x80 (ISAKMP_NEXT_CR) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 180 (0xb4) | cert type: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 4 bytes of padding | message 'main_inI3_outR3' HASH payload not checked early | DER ASN1 DN: 30 81 c4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 2a 30 28 06 03 55 04 03 0c 21 73 69 67 | DER ASN1 DN: 6e 65 64 62 79 6f 74 68 65 72 2e 6f 74 68 65 72 | DER ASN1 DN: 2e 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 31 37 | DER ASN1 DN: 30 35 06 09 2a 86 48 86 f7 0d 01 09 01 16 28 75 | DER ASN1 DN: 73 65 72 2d 73 69 67 6e 65 64 62 79 6f 74 68 65 | DER ASN1 DN: 72 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "nss-cert" #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=signedbyother.other.libreswan.org, E=user-signedbyother@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds loading root certificate cache | spent 3.67 milliseconds in get_root_certs() calling PK11_ListCertsInSlot() | spent 0.0277 milliseconds in get_root_certs() filtering CAs | #1 spent 3.73 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-signedbyother@testing.libreswan.org,CN=signedbyother.other.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.174 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for otherca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.0376 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec "nss-cert" #1: Certificate E=user-signedbyother@testing.libreswan.org,CN=signedbyother.other.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA failed IPsec verification "nss-cert" #1: ERROR: Peer's Certificate issuer is not recognized. | #1 spent 0.206 milliseconds in find_and_verify_certs() calling verify_end_cert() "nss-cert" #1: X509: Certificate rejected for this connection "nss-cert" #1: X509: CERT payload bogus or revoked | Peer ID failed to decode | complete v1 state transition with INVALID_ID_INFORMATION | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle "nss-cert" #1: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.45:500 | **emit ISAKMP Message: | initiator cookie: | 10 5e 9f 7c c0 6d e9 67 | responder cookie: | 0c 59 b4 31 23 61 09 c0 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3255334614 (0xc20876d6) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'notification msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Notification Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 0 (0x0) | Notify Message Type: INVALID_ID_INFORMATION (0x12) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Notification Payload (11:ISAKMP_NEXT_N) | next payload chain: saving location 'ISAKMP Notification Payload'.'next payload type' in 'notification msg' | emitting length of ISAKMP Notification Payload: 12 | send notification HASH(1): | 97 45 22 f5 65 39 d8 31 27 08 57 5c 26 c3 a0 c8 | e3 98 32 36 57 de 8e 5a 61 ad 6f 3f 28 21 d1 dc | no IKEv1 message padding required | emitting length of ISAKMP Message: 76 | sending 76 bytes for notification packet through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) | 10 5e 9f 7c c0 6d e9 67 0c 59 b4 31 23 61 09 c0 | 08 10 05 01 c2 08 76 d6 00 00 00 4c 24 69 9e a8 | 8a 9f a0 61 80 f5 c3 28 fc fc 76 1c c9 10 77 11 | af 51 2e 4d e9 67 bd 96 c1 ae e0 7d 00 a9 25 2b | 44 91 53 8c 3d 86 f0 44 45 3b 7a 09 | state transition function for STATE_MAIN_R2 failed: INVALID_ID_INFORMATION | #1 spent 4.46 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 4.84 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.00409 milliseconds in global timer EVENT_SHUNT_SCAN | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn nss-cert | stop processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in for_each_state() at state.c:1577) | spent 0.0145 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.013 milliseconds in global timer EVENT_SHUNT_SCAN | processing global timer EVENT_PENDING_DDNS | FOR_EACH_CONNECTION_... in connection_check_ddns | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | elapsed time in connection_check_ddns for hostname lookup 0.000006 | spent 0.0112 milliseconds in global timer EVENT_PENDING_DDNS | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.00342 milliseconds in global timer EVENT_SHUNT_SCAN | timer_event_cb: processing event@0x5579652c1868 | handling event EVENT_RETRANSMIT for parent state #1 | start processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in timer_event_cb() at timer.c:250) | IKEv1 retransmit event | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in retransmit_v1_msg() at retry.c:61) | handling event EVENT_RETRANSMIT for 192.1.2.45 "nss-cert" #1 keying attempt 0 of 0; retransmit 1 | retransmits: current time 11475.929803; retransmit count 0 exceeds limit? NO; deltatime 60 exceeds limit? YES; monotime 60.002565 exceeds limit? YES "nss-cert" #1: STATE_MAIN_R2: 60 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our IKEv1 message | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in retransmit_v1_msg() at retry.c:124) | pstats #1 ikev1.isakmp failed too-many-retransmits | pstats #1 ikev1.isakmp deleted too-many-retransmits | [RE]START processing: state #1 connection "nss-cert" from 192.1.2.45:500 (in delete_state() at state.c:879) "nss-cert" #1: deleting state (STATE_MAIN_R2) aged 60.005s and NOT sending notification | parent state #1: MAIN_R2(open IKE SA) => delete | State DB: IKEv1 state not found (flush_incomplete_children) | in connection_discard for connection nss-cert | State DB: deleting IKEv1 state #1 in MAIN_R2 | parent state #1: MAIN_R2(open IKE SA) => UNDEFINED(ignore) | stop processing: state #1 from 192.1.2.45:500 (in delete_state() at state.c:1143) | libevent_free: release ptr-libevent@0x5579652c2138 | free_event_entry: release EVENT_RETRANSMIT-pe@0x5579652c1868 | in statetime_stop() and could not find #1 | processing: STOP state #0 (in timer_event_cb() at timer.c:557) | spent 0.00265 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 792 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | e8 72 3b 5d 51 e0 5b f4 00 00 00 00 00 00 00 00 | 01 10 02 00 00 00 00 00 00 00 03 18 0d 00 02 84 | 00 00 00 01 00 00 00 01 00 00 02 78 00 01 00 12 | 03 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 01 01 00 00 80 0b 00 01 | 80 0c 0e 10 80 01 00 07 80 02 00 04 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 02 01 00 00 | 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 06 | 80 03 00 03 80 04 00 0e 80 0e 01 00 03 00 00 24 | 03 01 00 00 80 0b 00 01 80 0c 0e 10 80 01 00 07 | 80 02 00 06 80 03 00 03 80 04 00 0e 80 0e 00 80 | 03 00 00 24 04 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 05 01 00 00 80 0b 00 01 | 80 0c 0e 10 80 01 00 07 80 02 00 02 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 06 01 00 00 | 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 04 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 07 01 00 00 80 0b 00 01 80 0c 0e 10 80 01 00 07 | 80 02 00 04 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 24 08 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 06 80 03 00 03 80 04 00 05 | 80 0e 01 00 03 00 00 24 09 01 00 00 80 0b 00 01 | 80 0c 0e 10 80 01 00 07 80 02 00 06 80 03 00 03 | 80 04 00 05 80 0e 00 80 03 00 00 24 0a 01 00 00 | 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 02 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 0b 01 00 00 80 0b 00 01 80 0c 0e 10 80 01 00 07 | 80 02 00 02 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 20 0c 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 0e | 03 00 00 20 0d 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 0e | 03 00 00 20 0e 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 0e | 03 00 00 20 0f 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 05 | 03 00 00 20 10 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 05 | 00 00 00 20 11 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 05 | 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de 7f | 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 c9 | 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c 81 | 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 | 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 | ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 f8 | 7c fd b2 fc 68 b6 a4 48 | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | e8 72 3b 5d 51 e0 5b f4 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 792 (0x318) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: IKEv1 state not found (find_state_ikev1_init) | #null state always idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x2 opt: 0x2080 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 644 (0x284) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | message 'main_inI1_outR1' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | in statetime_start() with no state | find_host_connection local=192.1.2.23:500 remote=192.1.2.45:500 policy=IKEV1_ALLOW but ignoring ports | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (nss-cert) | find_next_host_connection returns nss-cert | find_next_host_connection policy=IKEV1_ALLOW | find_next_host_connection returns empty | creating state object #2 at 0x5579652cc8c8 | State DB: adding IKEv1 state #2 in UNDEFINED | pstats #2 ikev1.isakmp started | #2 updating local interface from to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2669) | start processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in main_inI1_outR1() at ikev1_main.c:667) | parent state #2: UNDEFINED(ignore) => MAIN_R0(half-open IKE SA) | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) "nss-cert" #2: responding to Main Mode | **emit ISAKMP Message: | initiator cookie: | e8 72 3b 5d 51 e0 5b f4 | responder cookie: | 8e c5 ac 03 92 45 37 e5 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 632 (0x278) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 18 (0x12) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | OAKLEY proposal verified unconditionally; no alg_info to check against | Oakley Transform 0 accepted | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | emitting 28 raw bytes of attributes into ISAKMP Transform Payload (ISAKMP) | attributes 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 04 | attributes 80 03 00 03 80 04 00 0e 80 0e 01 00 | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | no IKEv1 message padding required | emitting length of ISAKMP Message: 144 | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1 | parent state #2: MAIN_R0(half-open IKE SA) => MAIN_R1(open IKE SA) | event_already_set, deleting event | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 144 bytes for STATE_MAIN_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | e8 72 3b 5d 51 e0 5b f4 8e c5 ac 03 92 45 37 e5 | 01 10 02 00 00 00 00 00 00 00 00 90 0d 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 0d 00 00 14 40 48 b7 d5 6e bc e8 85 | 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 00 00 00 14 | 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | !event_already_set at reschedule | event_schedule: new EVENT_SO_DISCARD-pe@0x5579652c1868 | inserting event EVENT_SO_DISCARD, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x5579652df448 size 128 "nss-cert" #2: STATE_MAIN_R1: sent MR1, expecting MI2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.465 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00268 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 396 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | e8 72 3b 5d 51 e0 5b f4 8e c5 ac 03 92 45 37 e5 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 59 9b b7 a4 41 ac f0 d3 b2 96 48 20 fd f0 c8 cb | 8b 15 3f 76 c2 33 36 55 4a 63 20 6b 1f ae 66 ee | c9 cd 97 47 10 5f d3 ad b0 75 a4 ca 77 5a 31 d6 | f9 d7 8a 51 72 aa fb 0d 6d 76 88 1d bf 56 e4 eb | e4 da 0f 79 3c 74 96 e4 31 fc d6 82 89 15 ac c3 | 82 66 4d f8 eb c6 d2 0a 33 ee 3f e1 c0 60 43 b1 | 2e 8e b6 0c 60 ff 7f 7a de 44 dd 65 91 46 f5 3f | d9 f6 85 34 4f 41 e2 47 78 d5 73 72 ce 16 3e 0d | 54 1b 9e 0e 9b e7 a6 f0 b5 1e 75 f9 fe fa 48 80 | e0 77 24 47 b0 4e 98 03 4c cf 85 fc 24 4e a9 bf | bf a6 dc 76 ab 61 0f 35 a6 ef 2a 01 33 f2 d8 3e | 70 56 2d 67 67 45 7a ab 31 f8 1f da 25 a8 ea 24 | 39 bc 30 bd d8 bf 79 45 9d db 5f 14 16 df cb 59 | af fd a5 e1 cf 35 ce 05 52 fc ab 8e c4 00 2d 4f | 53 36 cd b8 12 36 14 d9 0e 5c ae b7 7f cf 52 34 | 62 87 aa ff 8c 59 06 54 68 3c 71 74 39 35 55 90 | 14 00 00 24 c6 ee 81 f7 3f 84 b1 99 0d c7 3e 1c | 26 ca 03 6e a8 41 04 69 a9 9c 59 0d 83 61 c4 b4 | fd af 3c 66 14 00 00 24 f5 73 67 29 79 9c 8d 01 | 89 9e 67 73 8a 90 42 d7 0e b9 96 2b f0 6a 62 ff | f5 28 fe 8d 31 cd 16 29 00 00 00 24 0b 4a 0c 1e | cd 82 04 b8 32 9e 5e 35 81 57 81 f1 7f 6f ac 62 | 5f a5 91 ce ea 4e 16 07 8d db ab bc | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | e8 72 3b 5d 51 e0 5b f4 | responder cookie: | 8e c5 ac 03 92 45 37 e5 | next payload type: ISAKMP_NEXT_KE (0x4) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 396 (0x18c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #2 in MAIN_R1 (find_state_ikev1) | start processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1459) | #2 is idle | #2 idle | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x410 opt: 0x102080 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x102080 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | message 'main_inI2_outR2' HASH payload not checked early | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= e8 72 3b 5d 51 e0 5b f4 | natd_hash: rcookie= 8e c5 ac 03 92 45 37 e5 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= f5 73 67 29 79 9c 8d 01 89 9e 67 73 8a 90 42 d7 | natd_hash: hash= 0e b9 96 2b f0 6a 62 ff f5 28 fe 8d 31 cd 16 29 | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= e8 72 3b 5d 51 e0 5b f4 | natd_hash: rcookie= 8e c5 ac 03 92 45 37 e5 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 0b 4a 0c 1e cd 82 04 b8 32 9e 5e 35 81 57 81 f1 | natd_hash: hash= 7f 6f ac 62 5f a5 91 ce ea 4e 16 07 8d db ab bc | expected NAT-D(me): f5 73 67 29 79 9c 8d 01 89 9e 67 73 8a 90 42 d7 | expected NAT-D(me): 0e b9 96 2b f0 6a 62 ff f5 28 fe 8d 31 cd 16 29 | expected NAT-D(him): | 0b 4a 0c 1e cd 82 04 b8 32 9e 5e 35 81 57 81 f1 | 7f 6f ac 62 5f a5 91 ce ea 4e 16 07 8d db ab bc | received NAT-D: f5 73 67 29 79 9c 8d 01 89 9e 67 73 8a 90 42 d7 | received NAT-D: 0e b9 96 2b f0 6a 62 ff f5 28 fe 8d 31 cd 16 29 | received NAT-D: 0b 4a 0c 1e cd 82 04 b8 32 9e 5e 35 81 57 81 f1 | received NAT-D: 7f 6f ac 62 5f a5 91 ce ea 4e 16 07 8d db ab bc | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.45 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | adding inI2_outR2 KE work-order 3 for state #2 | state #2 requesting EVENT_SO_DISCARD to be deleted | libevent_free: release ptr-libevent@0x5579652df448 | free_event_entry: release EVENT_SO_DISCARD-pe@0x5579652c1868 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x5579652c2138 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #2 and saving MD | #2 is busy; has a suspended MD | crypto helper 2 resuming | #2 spent 0.118 milliseconds in process_packet_tail() | crypto helper 2 starting work-order 3 for state #2 | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | crypto helper 2 doing build KE and nonce (inI2_outR2 KE); request ID 3 | stop processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.298 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 2 finished build KE and nonce (inI2_outR2 KE); request ID 3 time elapsed 0.000651 seconds | (#2) spent 0.656 milliseconds in crypto helper computing work-order 3: inI2_outR2 KE (pcr) | crypto helper 2 sending results from work-order 3 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f28f0002888 size 128 | libevent_realloc: release ptr-libevent@0x557965255228 | libevent_realloc: new ptr-libevent@0x7f28f00027d8 size 128 | crypto helper 2 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 2 replies to request ID 3 | calling continuation function 0x557964f2ab50 | main_inI2_outR2_continue for #2: calculated ke+nonce, sending R2 | **emit ISAKMP Message: | initiator cookie: | e8 72 3b 5d 51 e0 5b f4 | responder cookie: | 8e c5 ac 03 92 45 37 e5 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value c2 dc 29 4b 4c 96 f0 f5 25 03 dd c4 66 dc 67 fa | keyex value b3 3c f7 ba c3 65 48 50 60 28 ef de d4 b7 01 7d | keyex value 03 98 53 13 3d 6b 19 ec 49 51 d3 d3 36 fe 70 2f | keyex value 05 8f d0 fe 20 8e 6c fd c1 69 33 37 ec 82 bb 23 | keyex value 5e b7 33 46 09 3f 26 37 4c 23 da 07 9d 2e 00 75 | keyex value 30 f2 20 e5 db 49 1e f8 89 59 2e 79 3a 6f d9 22 | keyex value 0a d2 35 4d 61 86 e8 ff 7f 64 5a de 32 2b 79 ed | keyex value 92 6b a8 79 bf 78 b7 6f 9e ad 25 76 a4 23 5c 84 | keyex value c0 d2 87 28 84 2b d5 37 9a ca 2b cc ad e6 b6 af | keyex value 7f 2d 48 1e e7 ae 7e 42 31 bf 9d 20 8f 5f 5f 12 | keyex value f6 59 d8 1f 75 23 1f d2 49 9b 10 3e 49 b0 12 44 | keyex value 6b 3c 9a 10 11 05 b8 c9 78 34 7b bb b4 c7 b6 d9 | keyex value a8 ee b7 c8 cc 4e 76 81 d5 10 59 48 8b bf 63 ac | keyex value 06 ff 05 72 c8 c6 9a b7 ed 61 5a 8d 00 e1 58 8c | keyex value 28 99 4a 5e 84 f5 a0 91 6a b7 83 8e 58 2a 07 6d | keyex value bc ef a2 ab b2 6b ba 09 c1 9d 25 d8 3b 5b 1b 04 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 96 48 ca e6 6c 93 fd 98 25 2f ec a5 1f 91 4d d8 | Nr 40 05 fe b3 b2 b3 59 26 fe cf fb 90 81 20 3d ed | emitting length of ISAKMP Nonce Payload: 36 | sending NAT-D payloads | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= e8 72 3b 5d 51 e0 5b f4 | natd_hash: rcookie= 8e c5 ac 03 92 45 37 e5 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 0b 4a 0c 1e cd 82 04 b8 32 9e 5e 35 81 57 81 f1 | natd_hash: hash= 7f 6f ac 62 5f a5 91 ce ea 4e 16 07 8d db ab bc | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D 0b 4a 0c 1e cd 82 04 b8 32 9e 5e 35 81 57 81 f1 | NAT-D 7f 6f ac 62 5f a5 91 ce ea 4e 16 07 8d db ab bc | emitting length of ISAKMP NAT-D Payload: 36 | natd_hash: hasher=0x557964fffca0(32) | natd_hash: icookie= e8 72 3b 5d 51 e0 5b f4 | natd_hash: rcookie= 8e c5 ac 03 92 45 37 e5 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= f5 73 67 29 79 9c 8d 01 89 9e 67 73 8a 90 42 d7 | natd_hash: hash= 0e b9 96 2b f0 6a 62 ff f5 28 fe 8d 31 cd 16 29 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D f5 73 67 29 79 9c 8d 01 89 9e 67 73 8a 90 42 d7 | NAT-D 0e b9 96 2b f0 6a 62 ff f5 28 fe 8d 31 cd 16 29 | emitting length of ISAKMP NAT-D Payload: 36 | no IKEv1 message padding required | emitting length of ISAKMP Message: 396 | main inI2_outR2: starting async DH calculation (group=14) | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=signedbyother.other.libreswan.org, E=user-signedbyother@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=signedbyother.other.libreswan.org, E=user-signedbyother@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding main_inI2_outR2_tail work-order 4 for state #2 | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5579652c2138 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x5579652deb08 size 128 | #2 main_inI2_outR2_continue1_tail:1165 st->st_calculating = FALSE; | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle; has background offloaded task | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2 | parent state #2: MAIN_R1(open IKE SA) => MAIN_R2(open IKE SA) | event_already_set, deleting event | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5579652deb08 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5579652c1868 | sending reply packet to 192.1.2.45:500 (from 192.1.2.23:500) | sending 396 bytes for STATE_MAIN_R1 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | e8 72 3b 5d 51 e0 5b f4 8e c5 ac 03 92 45 37 e5 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | c2 dc 29 4b 4c 96 f0 f5 25 03 dd c4 66 dc 67 fa | b3 3c f7 ba c3 65 48 50 60 28 ef de d4 b7 01 7d | 03 98 53 13 3d 6b 19 ec 49 51 d3 d3 36 fe 70 2f | 05 8f d0 fe 20 8e 6c fd c1 69 33 37 ec 82 bb 23 | 5e b7 33 46 09 3f 26 37 4c 23 da 07 9d 2e 00 75 | crypto helper 3 resuming | crypto helper 3 starting work-order 4 for state #2 | 30 f2 20 e5 db 49 1e f8 89 59 2e 79 3a 6f d9 22 | crypto helper 3 doing compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 4 | 0a d2 35 4d 61 86 e8 ff 7f 64 5a de 32 2b 79 ed | 92 6b a8 79 bf 78 b7 6f 9e ad 25 76 a4 23 5c 84 | c0 d2 87 28 84 2b d5 37 9a ca 2b cc ad e6 b6 af | 7f 2d 48 1e e7 ae 7e 42 31 bf 9d 20 8f 5f 5f 12 | f6 59 d8 1f 75 23 1f d2 49 9b 10 3e 49 b0 12 44 | 6b 3c 9a 10 11 05 b8 c9 78 34 7b bb b4 c7 b6 d9 | a8 ee b7 c8 cc 4e 76 81 d5 10 59 48 8b bf 63 ac | 06 ff 05 72 c8 c6 9a b7 ed 61 5a 8d 00 e1 58 8c | 28 99 4a 5e 84 f5 a0 91 6a b7 83 8e 58 2a 07 6d | bc ef a2 ab b2 6b ba 09 c1 9d 25 d8 3b 5b 1b 04 | 14 00 00 24 96 48 ca e6 6c 93 fd 98 25 2f ec a5 | 1f 91 4d d8 40 05 fe b3 b2 b3 59 26 fe cf fb 90 | 81 20 3d ed 14 00 00 24 0b 4a 0c 1e cd 82 04 b8 | 32 9e 5e 35 81 57 81 f1 7f 6f ac 62 5f a5 91 ce | ea 4e 16 07 8d db ab bc 00 00 00 24 f5 73 67 29 | 79 9c 8d 01 89 9e 67 73 8a 90 42 d7 0e b9 96 2b | f0 6a 62 ff f5 28 fe 8d 31 cd 16 29 | !event_already_set at reschedule "nss-cert" #2: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x5579652c1868 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x5579652deb08 size 128 | #2 STATE_MAIN_R2: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11475.934215 "nss-cert" #2: STATE_MAIN_R2: sent MR2, expecting MI3 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 0.288 milliseconds in resume sending helper answer | stop processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f28f0002888 | crypto helper 3 finished compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 4 time elapsed 0.00116 seconds | (#2) spent 1.16 milliseconds in crypto helper computing work-order 4: main_inI2_outR2_tail (pcr) | crypto helper 3 sending results from work-order 4 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f28e4000f48 size 128 | crypto helper 3 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in resume_handler() at server.c:797) | crypto helper 3 replies to request ID 4 | calling continuation function 0x557964f2ab50 | main_inI2_outR2_calcdone for #2: calculate DH finished | [RE]START processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1015) | stop processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1028) | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 0.015 milliseconds in resume sending helper answer | processing: STOP state #0 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f28e4000f48 | spent 0.00232 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 2060 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) | e8 72 3b 5d 51 e0 5b f4 8e c5 ac 03 92 45 37 e5 | 05 10 02 01 00 00 00 00 00 00 08 0c ac e4 fb 62 | 88 de 3c b1 7c 0a 24 5e 8b da 22 fc 03 8c c0 28 | 6a c3 5a 72 b2 25 30 5e ac df 03 65 c5 d6 cd 0c | 58 1a a0 fa f1 61 cf 04 20 61 e7 5d 8d 89 e7 a4 | 02 f7 2a 9e aa 97 0a 51 b0 d5 ee a5 07 11 0d 9d | d3 cf df 37 52 26 bf 19 8c e6 39 cf 6d f4 4e eb | 3a 04 78 92 87 80 17 73 f3 21 13 ca 96 cb 90 c3 | 98 5f b4 d3 a6 97 5f d2 84 46 c7 ea 43 81 f7 d4 | db 32 6e 70 3f a9 ca e9 80 05 00 38 44 0f 55 65 | 06 4c 9a f7 95 f4 00 4b 08 2a 73 1b f0 2e f3 02 | 34 e9 d2 4a 25 44 7a b2 b0 fd 7f c3 01 e0 06 a9 | 8f d2 b7 1d 3c 27 11 29 1f 51 0d 97 8f 15 e0 18 | c3 13 97 1e 33 60 c3 cc 94 c0 f1 df e5 7a d6 12 | 70 4e f4 dc 2d bc e0 1e 76 c3 ef 41 5e c7 b5 a9 | 35 7f ef 8e 58 78 a3 49 3c 46 e3 30 80 aa f7 c5 | 66 a1 62 4a 13 7e 93 a5 15 e3 fb 00 80 8e 84 09 | ea 43 98 4d d3 d3 5d 3a d3 91 56 87 c2 5a 9e 4a | 7a ff e9 ab 5e aa 1a bd 1d 36 eb f6 0d d3 cd 5c | 0b ef 8e 49 f6 94 f4 1d 3d 1b 82 9c f8 d7 bc 8c | 9a 2a 8d bc 9b ed af 51 ca bf fb 4b 27 4d 83 cc | 00 a3 66 eb 84 40 5d c7 5f b2 4a 57 70 eb a6 ab | 87 f4 14 01 42 6a 20 70 bc ae 85 66 d1 68 6e f4 | 20 52 2c 82 2b ad 61 4c a6 4f a8 f9 4e 8e 64 45 | cb d3 8c 78 c5 f7 4d 78 49 e7 3a c6 eb 2b 60 7c | 62 5a d7 0c 42 88 b0 90 20 f2 0f cb 23 18 e9 5c | 79 33 ac 77 b3 0b 79 37 7d e8 2a 31 01 01 ca 63 | 5d e2 28 ac 7b 30 04 0a 6c f2 de dc 1d 39 00 49 | dd 71 7d 04 fd cf 2a 11 4e 58 3b 5e 75 45 ea dc | b7 66 c3 10 d2 cf 37 6d 00 dc 9e 6b cc 61 4c 3c | 3b ab f1 08 d1 ee e4 4c a7 9e 49 2b c9 73 33 1e | c6 53 64 c2 ec 9f 13 eb 7e d4 71 86 c4 80 88 9e | 12 38 3d 7e 9d c5 31 ef 96 8a a7 c5 59 b5 f4 e3 | 40 47 9a 91 07 8f 78 76 9c b8 1f ad 20 6a 57 4f | d3 21 6a 54 d3 34 2f 90 d6 92 a5 fd 14 aa 2e 89 | 2e 24 d8 ba de ca b3 6f 5a b6 93 9c 94 a4 57 0b | 6a e6 dd 0b 77 30 d0 6f 78 32 37 15 6a 65 b4 16 | 1d a5 f8 9d e2 9a c5 ac 6a 09 d2 05 c5 32 c3 de | 59 9e 5f c1 d8 2b c3 e4 8a fb d2 e3 c5 ac d8 d9 | e7 53 56 a3 4e 38 1a f5 06 05 44 91 8e 51 8f 13 | 9b 95 6d 0c d4 aa 53 09 08 8c 41 a2 8f 50 0a 77 | 56 ed a4 57 40 ee 49 ef df 0c be ba 4d 08 d0 84 | 56 98 30 02 e1 17 8d d1 6d 9b 08 0a 73 43 4c 75 | 88 0e b2 d6 5f 04 17 34 cf aa b9 74 55 da 48 83 | 45 07 52 f3 c8 c6 b8 69 19 29 79 99 03 3c 84 30 | 8b ad 58 54 24 e7 b7 7e 57 dd bb 38 38 87 28 50 | 56 64 d9 15 0f 4f 6a e2 9b c4 60 0a 4e 69 f8 97 | e3 18 9c fb b8 d3 98 97 7a 22 70 6c 8c e3 61 8e | 47 f2 e2 8d 77 3c 71 a8 eb 12 9d 7e c9 19 c1 f5 | b3 de eb d1 2b b0 dc 2a 87 fe d1 1d d1 a1 ed 30 | 40 1f 81 a4 73 4e 4d 1d e5 97 88 5d 12 48 bb 3e | 68 b7 b4 3d 78 b4 26 85 03 a8 e2 97 5c 82 54 e8 | fc 3b 1a 4d 8e b2 26 3a a3 69 a0 35 48 4c 8b e5 | 8a b0 6d 9e e2 c3 32 ac d9 3d c4 53 f0 09 c1 83 | 95 4f b1 0a 0f b2 26 0f a4 55 fa 7b 97 e2 1e d8 | e8 16 6b 99 d4 8b 16 04 2a a1 87 6f 11 b0 de 3f | 93 89 e1 3e d8 ae c4 e8 ee d9 33 22 3c f8 dd 6e | b4 21 6e e3 f9 04 02 22 00 56 b2 45 6b 79 a0 78 | 77 87 a7 ac 82 28 b6 ff 68 84 0e 54 38 8a 3a 15 | c1 af 46 a0 ed 56 88 7a a9 af ec 83 af 9e 63 9f | 97 71 82 f9 3f 59 2d 36 6b 00 88 69 14 da 46 04 | df 98 1b 9b 1d 24 3a a3 04 1d ab ce a7 f8 2d cf | 62 a5 c1 eb ff 83 5e 38 e1 f4 34 b9 ee ea c4 db | ea d0 11 fc 19 49 5a d5 ed d0 9d c8 44 f5 40 73 | bd 68 08 43 07 2a 9a ef c6 a6 41 b5 4e 0f 98 68 | 00 db cd ca 52 56 78 62 9a 7d 0e 73 81 57 66 49 | 2b 8f ca ec 43 98 87 1e a9 fe 73 f5 d0 4b ec b6 | d1 ca 2c a0 80 da 15 6d 8d e8 e5 78 15 bb e3 17 | 9d ad 73 a8 9d d6 4d 2c d3 bd 42 e3 e2 1c a9 23 | da a4 bf 2b 6b a7 30 95 a2 46 b4 b1 93 2b bd 9c | cd cd f8 54 e4 bd 5a ba 43 6e cb 30 da b1 bd 95 | 82 16 e2 ed 4f a4 05 0e a2 db 86 a8 ac ba f9 0c | f9 87 f7 42 bb 88 c4 c9 ba f5 ab ee fe e3 0d 3c | 26 d9 95 fd 84 7b cb 98 e3 5d d1 68 d7 e2 c5 df | d4 30 92 e2 47 6a c4 1f 15 5a 24 aa dd 7e fc 05 | 1e fd 4a ff d5 9d 7a ee 33 c5 be bb 00 37 fb 65 | 64 1b 8b 88 76 d5 be 4c 1a c7 82 58 e3 08 e6 4f | 44 e7 8d a2 d3 34 48 53 b3 2c d3 d9 55 df 6d 3a | d0 3e d0 d5 9f 58 36 2f 56 5b d3 d7 4a ec b6 32 | 29 14 46 30 1b 97 f1 99 33 da b3 c2 df 4b c4 d4 | 2e 81 db f5 35 6d 0f 61 45 23 d7 df 93 d4 4d 6e | f7 c6 fa a9 9d 11 41 74 89 7d f8 1f 03 5f a0 e6 | e2 7c e0 d6 62 2d 18 93 5c 2b 0f 83 59 36 0e 04 | 96 11 38 83 c3 e7 35 c7 84 13 15 e6 7a 50 bf c1 | 85 f9 24 e0 b2 00 1e 25 1b f4 c3 fe 30 38 ec 24 | 5b 6f 51 46 48 28 2f 53 b3 4f 4a 7f 39 69 50 a9 | 56 7c c5 3a d1 16 f5 30 c1 8a 33 8a d8 2f 1d df | 4e 2c 54 27 96 27 1f 73 56 c7 f5 b1 52 3f 5d 26 | 10 9c 30 d0 d1 05 97 5e 07 fe ba f9 b3 64 da e7 | 8f 89 a7 c1 af 3a ec 70 b5 93 d5 15 c8 9a 4d 19 | e1 7a 3f 1f 61 a9 13 2d 74 b2 49 43 03 25 26 cd | 16 ba e0 bb d5 31 ff 2d d0 84 61 b1 cc 1a 54 a5 | 26 56 57 68 d6 ca 2b ad 88 03 37 07 8d a3 88 aa | 99 f6 37 73 9f 43 06 09 57 e6 48 66 8c 83 6d 4b | 24 df 78 0a d4 6d b6 45 8e 13 3c e5 31 b2 e5 62 | 0c 9a fd ad ec 05 ab 6b 45 c6 c6 da 2c 63 dc 60 | 90 db ae 5f 43 63 84 23 f4 c9 4c 94 d7 16 3e be | 3c a5 de 71 e9 ec 1d 85 ef 5f 4d 30 de f3 c8 cf | 9d 41 07 b3 3f d1 0c 7a cb 99 12 83 f7 00 7e ed | 0b c8 9e 66 9f 7e e9 16 7a 11 05 03 60 b5 1c 8b | 6e 86 64 dc e0 22 6a 40 c3 8d a7 54 04 a2 b3 cc | 9a 45 ba 81 31 d2 6d ba 7b 38 aa 72 ff a2 5f db | 15 60 5a 83 fd 51 98 d5 9f 80 11 f2 6d 56 c3 14 | f0 59 ef 97 d6 7e df 1f 5a 2d bb aa b6 ec f8 97 | 05 a3 97 e2 ac 20 1f 57 4f 5f e7 8c d7 b0 62 ec | 54 eb 3a 5d 9e 17 cc 52 70 3f 1d e4 35 3b 9d 36 | e8 21 0d 4f 82 9b e9 dd e5 48 65 80 43 d1 8d 43 | 1c 37 3b bb 40 03 40 7a 6a a0 6b f3 0d f7 1b c8 | 56 bc 20 c5 b3 7b 51 2a 94 7c 21 46 ee cf 0f 48 | 2e 89 52 2c 41 0a 08 e5 67 97 6b b3 f2 f6 f8 87 | e7 ec 30 ed dd fb e6 1b 52 71 9d 40 46 44 74 87 | 44 f2 0f 05 17 98 36 28 c4 7d 13 d6 7c 1b 56 22 | fc 9f e7 4e be db 75 0f f7 31 f5 02 66 6f 94 19 | 9c f9 34 03 63 8d 77 d7 2b d8 8a 4c df 0b 4c 52 | 61 d8 eb 49 c0 fb 98 60 80 52 43 ea bb a4 08 a4 | 0a 69 b8 3e e7 db c5 05 62 37 17 f8 64 98 49 45 | 61 f0 eb 07 86 7c 5e bb 82 f2 02 57 07 1f 5b 89 | bc 08 93 f4 27 c2 de aa 32 cb a0 77 1a b7 53 37 | ee f1 a7 8e cd 01 81 69 57 06 35 d0 2d ae f1 bf | 36 1b 87 42 58 71 d4 ae 14 a3 8a 44 af 65 3c ed | ef b2 cc 12 ec 0e f2 31 0a 5f bd f4 47 09 e8 07 | 87 2a 21 b7 26 a9 2e ba 26 09 98 02 b3 0b 39 27 | 94 ee ba ca d0 ea 46 40 c2 8d f3 60 ad 9d 2f 92 | 16 ea 4b 4e 19 65 a5 35 54 6c 6d 4a b1 cc 50 af | 56 dd f8 46 c0 40 b6 6f 2b a0 56 f4 87 6f 59 b3 | 7f 4f 5d 82 6a 13 cb d3 04 fe 24 25 8e 1d d2 14 | ea 01 3f 16 ce 1b de 96 76 2c 66 6f 4d 13 2c 42 | 27 47 fd 79 c1 9e 93 95 dc 62 ac 67 6c 65 4b d7 | 3c 3b f8 3a 48 f7 60 65 72 25 6a 9a | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | e8 72 3b 5d 51 e0 5b f4 | responder cookie: | 8e c5 ac 03 92 45 37 e5 | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 2060 (0x80c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #2 in MAIN_R2 (find_state_ikev1) | start processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in process_v1_packet() at ikev1.c:1459) | #2 is idle | #2 idle | received encrypted packet from 192.1.2.45:500 | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x20c0 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 207 (0xcf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 c4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 2a 30 28 06 03 55 04 03 0c 21 73 69 67 | obj: 6e 65 64 62 79 6f 74 68 65 72 2e 6f 74 68 65 72 | obj: 2e 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 31 37 | obj: 30 35 06 09 2a 86 48 86 f7 0d 01 09 01 16 28 75 | obj: 73 65 72 2d 73 69 67 6e 65 64 62 79 6f 74 68 65 | obj: 72 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | length: 1253 (0x4e5) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x80 (ISAKMP_NEXT_CR) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 180 (0xb4) | cert type: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 4 bytes of padding | message 'main_inI3_outR3' HASH payload not checked early | DER ASN1 DN: 30 81 c4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 2a 30 28 06 03 55 04 03 0c 21 73 69 67 | DER ASN1 DN: 6e 65 64 62 79 6f 74 68 65 72 2e 6f 74 68 65 72 | DER ASN1 DN: 2e 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 31 37 | DER ASN1 DN: 30 35 06 09 2a 86 48 86 f7 0d 01 09 01 16 28 75 | DER ASN1 DN: 73 65 72 2d 73 69 67 6e 65 64 62 79 6f 74 68 65 | DER ASN1 DN: 72 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "nss-cert" #2: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=signedbyother.other.libreswan.org, E=user-signedbyother@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds | #2 spent 0.00338 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-signedbyother@testing.libreswan.org,CN=signedbyother.other.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #2 spent 0.0423 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for otherca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #2 spent 0.0554 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec "nss-cert" #2: Certificate E=user-signedbyother@testing.libreswan.org,CN=signedbyother.other.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA failed IPsec verification "nss-cert" #2: ERROR: Peer's Certificate issuer is not recognized. | #2 spent 0.166 milliseconds in find_and_verify_certs() calling verify_end_cert() "nss-cert" #2: X509: Certificate rejected for this connection "nss-cert" #2: X509: CERT payload bogus or revoked | Peer ID failed to decode | complete v1 state transition with INVALID_ID_INFORMATION | [RE]START processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle "nss-cert" #2: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.45:500 | **emit ISAKMP Message: | initiator cookie: | e8 72 3b 5d 51 e0 5b f4 | responder cookie: | 8e c5 ac 03 92 45 37 e5 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 221042300 (0xd2cd67c) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'notification msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Notification Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 0 (0x0) | Notify Message Type: INVALID_ID_INFORMATION (0x12) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Notification Payload (11:ISAKMP_NEXT_N) | next payload chain: saving location 'ISAKMP Notification Payload'.'next payload type' in 'notification msg' | emitting length of ISAKMP Notification Payload: 12 | send notification HASH(1): | 55 1a c5 15 31 0b 76 1b 18 37 90 b9 8a 59 31 70 | a9 89 77 7c 34 a5 01 3d f2 aa 27 2b 0d 21 d2 c6 | no IKEv1 message padding required | emitting length of ISAKMP Message: 76 | sending 76 bytes for notification packet through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #2) | e8 72 3b 5d 51 e0 5b f4 8e c5 ac 03 92 45 37 e5 | 08 10 05 01 0d 2c d6 7c 00 00 00 4c 5a 25 fa db | a7 35 61 c6 81 8e 71 de a3 0c 02 12 d6 59 03 29 | 84 f4 5d 42 92 96 c3 cb 87 9a ac 4d e4 0e c2 1c | 51 86 9f 73 92 e0 f3 bf d8 1b 56 72 | state transition function for STATE_MAIN_R2 failed: INVALID_ID_INFORMATION | #2 spent 0.476 milliseconds in process_packet_tail() | stop processing: from 192.1.2.45:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.755 milliseconds in comm_handle_cb() reading and processing packet | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.503 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) shutting down | processing: RESET whack log_fd (was fd@16) (in exit_pluto() at plutomain.c:1825) destroying root certificate cache | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' | unreference key: 0x5579652c3478 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | unreference key: 0x5579652c2ff8 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x5579652c2ab8 @east.testing.libreswan.org cnt 1-- | unreference key: 0x5579652c2588 east@testing.libreswan.org cnt 1-- | unreference key: 0x5579652c1188 192.1.2.23 cnt 1-- | start processing: connection "nss-cert" (in delete_connection() at connections.c:189) | Deleting states for connection - including all other IPsec SA's of this IKE SA | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | suspend processing: connection "nss-cert" (in foreach_state_by_connection_func_delete() at state.c:1310) | start processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #2 ikev1.isakmp deleted other | [RE]START processing: state #2 connection "nss-cert" from 192.1.2.45:500 (in delete_state() at state.c:879) "nss-cert" #2: deleting state (STATE_MAIN_R2) aged 1.120s and NOT sending notification | parent state #2: MAIN_R2(open IKE SA) => delete | state #2 requesting EVENT_RETRANSMIT to be deleted | #2 STATE_MAIN_R2: retransmits: cleared | libevent_free: release ptr-libevent@0x5579652deb08 | free_event_entry: release EVENT_RETRANSMIT-pe@0x5579652c1868 | State DB: IKEv1 state not found (flush_incomplete_children) | stop processing: connection "nss-cert" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection nss-cert | State DB: deleting IKEv1 state #2 in MAIN_R2 | parent state #2: MAIN_R2(open IKE SA) => UNDEFINED(ignore) | stop processing: state #2 from 192.1.2.45:500 (in delete_state() at state.c:1143) | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | free hp@0x5579652c0d68 | flush revival: connection 'nss-cert' wasn't on the list | processing: STOP connection NULL (in discard_connection() at connections.c:249) | crl fetch request list locked by 'free_crl_fetch' | crl fetch request list unlocked by 'free_crl_fetch' shutting down interface lo/lo 127.0.0.1:4500 shutting down interface lo/lo 127.0.0.1:500 shutting down interface eth0/eth0 192.0.2.254:4500 shutting down interface eth0/eth0 192.0.2.254:500 shutting down interface eth1/eth1 192.1.2.23:4500 shutting down interface eth1/eth1 192.1.2.23:500 | FOR_EACH_STATE_... in delete_states_dead_interfaces | libevent_free: release ptr-libevent@0x5579652af778 | free_event_entry: release EVENT_NULL-pe@0x5579652bb668 | libevent_free: release ptr-libevent@0x557965255f88 | free_event_entry: release EVENT_NULL-pe@0x5579652bb718 | libevent_free: release ptr-libevent@0x5579652558a8 | free_event_entry: release EVENT_NULL-pe@0x5579652bb7c8 | libevent_free: release ptr-libevent@0x55796525d168 | free_event_entry: release EVENT_NULL-pe@0x5579652bb878 | libevent_free: release ptr-libevent@0x55796525d268 | free_event_entry: release EVENT_NULL-pe@0x5579652bb928 | libevent_free: release ptr-libevent@0x55796525d368 | free_event_entry: release EVENT_NULL-pe@0x5579652bb9d8 | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | libevent_free: release ptr-libevent@0x5579652af828 | free_event_entry: release EVENT_NULL-pe@0x5579652a3948 | libevent_free: release ptr-libevent@0x557965255ed8 | free_event_entry: release EVENT_NULL-pe@0x5579652a34a8 | libevent_free: release ptr-libevent@0x55796529c488 | free_event_entry: release EVENT_NULL-pe@0x55796525d418 | global timer EVENT_REINIT_SECRET uninitialized | global timer EVENT_SHUNT_SCAN uninitialized | global timer EVENT_PENDING_DDNS uninitialized | global timer EVENT_PENDING_PHASE2 uninitialized | global timer EVENT_CHECK_CRLS uninitialized | global timer EVENT_REVIVE_CONNS uninitialized | global timer EVENT_FREE_ROOT_CERTS uninitialized | global timer EVENT_RESET_LOG_RATE_LIMIT uninitialized | global timer EVENT_NAT_T_KEEPALIVE uninitialized | libevent_free: release ptr-libevent@0x5579652619e8 | signal event handler PLUTO_SIGCHLD uninstalled | libevent_free: release ptr-libevent@0x5579651df728 | signal event handler PLUTO_SIGTERM uninstalled | libevent_free: release ptr-libevent@0x5579652bae48 | signal event handler PLUTO_SIGHUP uninstalled | libevent_free: release ptr-libevent@0x5579652bb088 | signal event handler PLUTO_SIGSYS uninstalled | releasing event base | libevent_free: release ptr-libevent@0x5579652baf58 | libevent_free: release ptr-libevent@0x55796529dd68 | libevent_free: release ptr-libevent@0x55796529dd18 | libevent_free: release ptr-libevent@0x7f28f00027d8 | libevent_free: release ptr-libevent@0x55796529dcd8 | libevent_free: release ptr-libevent@0x5579652bab18 | libevent_free: release ptr-libevent@0x5579652bad88 | libevent_free: release ptr-libevent@0x55796529df18 | libevent_free: release ptr-libevent@0x5579652a3518 | libevent_free: release ptr-libevent@0x5579652a3178 | libevent_free: release ptr-libevent@0x5579652bba48 | libevent_free: release ptr-libevent@0x5579652bb998 | libevent_free: release ptr-libevent@0x5579652bb8e8 | libevent_free: release ptr-libevent@0x5579652bb838 | libevent_free: release ptr-libevent@0x5579652bb788 | libevent_free: release ptr-libevent@0x5579652bb6d8 | libevent_free: release ptr-libevent@0x5579651dea48 | libevent_free: release ptr-libevent@0x5579652bae08 | libevent_free: release ptr-libevent@0x5579652badc8 | libevent_free: release ptr-libevent@0x5579652bac88 | libevent_free: release ptr-libevent@0x5579652baf18 | libevent_free: release ptr-libevent@0x5579652bab58 | libevent_free: release ptr-libevent@0x557965263578 | libevent_free: release ptr-libevent@0x5579652634f8 | libevent_free: release ptr-libevent@0x5579651dedb8 | releasing global libevent data | libevent_free: release ptr-libevent@0x5579652636f8 | libevent_free: release ptr-libevent@0x557965263678 | libevent_free: release ptr-libevent@0x5579652635f8 leak detective found no leaks