/testing/guestbin/swan-prep road # ipsec start Redirecting to: [initsystem] road # /testing/pluto/bin/wait-until-pluto-started road # ipsec auto --add road-east 002 added connection description "road-east" road # echo "initdone" initdone road # ipsec whack --impair drop-xauth-r0 road # ipsec whack --xauthname 'use3' --xauthpass 'use1pass' --name road-east --initiate 003 "road-east": IKEv1 Aggressive Mode with PSK is vulnerable to dictionary attacks and is cracked on large scale by TLA's 003 "road-east" #1: multiple DH groups in aggressive mode can cause interop failure 003 "road-east" #1: Deleting previous proposal in the hopes of selecting DH 2 or DH 5 003 "road-east" #1: transform (OAKLEY_3DES_CBC,OAKLEY_SHA2_256,MODP2048 keylen 0) ignored. 003 "road-east" #1: transform (OAKLEY_3DES_CBC,OAKLEY_SHA2_512,MODP2048 keylen 0) ignored. 003 "road-east" #1: transform (OAKLEY_3DES_CBC,OAKLEY_SHA1,MODP2048 keylen 0) ignored. 002 "road-east" #1: initiating Aggressive Mode 003 "road-east" #1: multiple DH groups in aggressive mode can cause interop failure 003 "road-east" #1: Deleting previous proposal in the hopes of selecting DH 2 or DH 5 003 "road-east" #1: transform (OAKLEY_3DES_CBC,OAKLEY_SHA2_256,MODP2048 keylen 0) ignored. 003 "road-east" #1: transform (OAKLEY_3DES_CBC,OAKLEY_SHA2_512,MODP2048 keylen 0) ignored. 003 "road-east" #1: transform (OAKLEY_3DES_CBC,OAKLEY_SHA1,MODP2048 keylen 0) ignored. 1v1 "road-east" #1: STATE_AGGR_I1: initiate 002 "road-east" #1: Peer ID is ID_FQDN: '@east' 002 "road-east" #1: Peer ID is ID_FQDN: '@east' 004 "road-east" #1: STATE_AGGR_I2: sent AI2, ISAKMP SA established {auth=PRESHARED_KEY cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP1536} 002 "road-east" #1: IMPAIR: drop XAUTH R0 message 200 "road-east" #1: STATE_AGGR_I2: failed 002 "road-east" #1: IMPAIR: drop XAUTH R0 message 200 "road-east" #1: STATE_AGGR_I2: failed 002 "road-east" #1: IMPAIR: drop XAUTH R0 message 200 "road-east" #1: STATE_AGGR_I2: failed 003 "road-east" #1: received Delete SA payload: self-deleting ISAKMP State #1 002 "road-east" #1: deleting state (STATE_AGGR_I2) and sending notification road # echo done done road # grep -E '(inserting|handling) event (EVENT_v1_SEND_XAUTH|EVENT_RETRANSMIT)' /tmp/pluto.log | inserting event EVENT_RETRANSMIT, timeout in 2.5 seconds for #1 | inserting event EVENT_RETRANSMIT, timeout in 2.5 seconds for #2 road # road # ../bin/check-for-core.sh road # if [ -f /sbin/ausearch ]; then ausearch -r -m avc -ts recent ; fi