FIPS Product: YES FIPS Kernel: NO FIPS Mode: NO NSS DB directory: sql:/etc/ipsec.d Initializing NSS Opening NSS database "sql:/etc/ipsec.d" read-only NSS initialized NSS crypto library initialized FIPS HMAC integrity support [enabled] FIPS mode disabled for pluto daemon FIPS HMAC integrity verification self-test FAILED libcap-ng support [enabled] Linux audit support [enabled] Linux audit activated Starting Pluto (Libreswan Version v3.28-685-gbfd5aef521-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:23536 core dump dir: /run/pluto secrets file: /etc/ipsec.secrets leak-detective enabled NSS crypto [enabled] XAUTH PAM support [enabled] | libevent is using pluto's memory allocator Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) | libevent_malloc: new ptr-libevent@0x55613f0be6e8 size 40 | libevent_malloc: new ptr-libevent@0x55613f0be668 size 40 | libevent_malloc: new ptr-libevent@0x55613f0be5e8 size 40 | creating event base | libevent_malloc: new ptr-libevent@0x55613f0b0218 size 56 | libevent_malloc: new ptr-libevent@0x55613f039db8 size 664 | libevent_malloc: new ptr-libevent@0x55613f0f8d08 size 24 | libevent_malloc: new ptr-libevent@0x55613f0f8d58 size 384 | libevent_malloc: new ptr-libevent@0x55613f0f8cc8 size 16 | libevent_malloc: new ptr-libevent@0x55613f0be568 size 40 | libevent_malloc: new ptr-libevent@0x55613f0be4e8 size 48 | libevent_realloc: new ptr-libevent@0x55613f039a48 size 256 | libevent_malloc: new ptr-libevent@0x55613f0f8f08 size 16 | libevent_free: release ptr-libevent@0x55613f0b0218 | libevent initialized | libevent_realloc: new ptr-libevent@0x55613f0b0218 size 64 | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds | init_nat_traversal() initialized with keep_alive=0s NAT-Traversal support [enabled] | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized | global one-shot timer EVENT_FREE_ROOT_CERTS initialized | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds | global one-shot timer EVENT_REVIVE_CONNS initialized | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Encryption algorithms: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac NULL IKEv1: ESP IKEv2: ESP [] CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Hash algorithms: MD5 IKEv1: IKE IKEv2: SHA1 IKEv1: IKE IKEv2: FIPS sha SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 PRF algorithms: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Integrity algorithms: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac NONE IKEv1: ESP IKEv2: IKE ESP FIPS null DH algorithms: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 testing CAMELLIA_CBC: Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 256-bit key Camellia: 16 bytes with 256-bit key testing AES_GCM_16: empty string one block two blocks two blocks with associated data testing AES_CTR: Encrypting 16 octets using AES-CTR with 128-bit key Encrypting 32 octets using AES-CTR with 128-bit key Encrypting 36 octets using AES-CTR with 128-bit key Encrypting 16 octets using AES-CTR with 192-bit key Encrypting 32 octets using AES-CTR with 192-bit key Encrypting 36 octets using AES-CTR with 192-bit key Encrypting 16 octets using AES-CTR with 256-bit key Encrypting 32 octets using AES-CTR with 256-bit key Encrypting 36 octets using AES-CTR with 256-bit key testing AES_CBC: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key testing AES_XCBC: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) testing HMAC_MD5: RFC 2104: MD5_HMAC test 1 RFC 2104: MD5_HMAC test 2 RFC 2104: MD5_HMAC test 3 8 CPU cores online starting up 7 crypto helpers started thread for crypto helper 0 started thread for crypto helper 1 | starting up helper thread 1 started thread for crypto helper 2 | status value returned by setting the priority of this thread (crypto helper 1) 22 | starting up helper thread 2 | status value returned by setting the priority of this thread (crypto helper 2) 22 started thread for crypto helper 3 | crypto helper 1 waiting (nothing to do) | crypto helper 2 waiting (nothing to do) started thread for crypto helper 4 | starting up helper thread 4 | status value returned by setting the priority of this thread (crypto helper 4) 22 | crypto helper 4 waiting (nothing to do) started thread for crypto helper 5 | starting up helper thread 5 | status value returned by setting the priority of this thread (crypto helper 5) 22 | crypto helper 5 waiting (nothing to do) started thread for crypto helper 6 | starting up helper thread 6 | starting up helper thread 0 | status value returned by setting the priority of this thread (crypto helper 6) 22 | status value returned by setting the priority of this thread (crypto helper 0) 22 | crypto helper 6 waiting (nothing to do) | checking IKEv1 state table | starting up helper thread 3 | MAIN_R0: category: half-open IKE SA flags: 0: | crypto helper 0 waiting (nothing to do) | status value returned by setting the priority of this thread (crypto helper 3) 22 | crypto helper 3 waiting (nothing to do) | -> MAIN_R1 EVENT_SO_DISCARD | MAIN_I1: category: half-open IKE SA flags: 0: | -> MAIN_I2 EVENT_RETRANSMIT | MAIN_R1: category: open IKE SA flags: 200: | -> MAIN_R2 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_I2: category: open IKE SA flags: 0: | -> MAIN_I3 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_R2: category: open IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | -> MAIN_R3 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_I3: category: open IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | -> MAIN_I4 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_R3: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | MAIN_I4: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | AGGR_R0: category: half-open IKE SA flags: 0: | -> AGGR_R1 EVENT_SO_DISCARD | AGGR_I1: category: half-open IKE SA flags: 0: | -> AGGR_I2 EVENT_SA_REPLACE | -> AGGR_I2 EVENT_SA_REPLACE | AGGR_R1: category: open IKE SA flags: 200: | -> AGGR_R2 EVENT_SA_REPLACE | -> AGGR_R2 EVENT_SA_REPLACE | AGGR_I2: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | AGGR_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | QUICK_R0: category: established CHILD SA flags: 0: | -> QUICK_R1 EVENT_RETRANSMIT | QUICK_I1: category: established CHILD SA flags: 0: | -> QUICK_I2 EVENT_SA_REPLACE | QUICK_R1: category: established CHILD SA flags: 0: | -> QUICK_R2 EVENT_SA_REPLACE | QUICK_I2: category: established CHILD SA flags: 200: | -> UNDEFINED EVENT_NULL | QUICK_R2: category: established CHILD SA flags: 0: | -> UNDEFINED EVENT_NULL | INFO: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | INFO_PROTECTED: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | XAUTH_R0: category: established IKE SA flags: 0: | -> XAUTH_R1 EVENT_NULL | XAUTH_R1: category: established IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | MODE_CFG_R0: category: informational flags: 0: | -> MODE_CFG_R1 EVENT_SA_REPLACE | MODE_CFG_R1: category: established IKE SA flags: 0: | -> MODE_CFG_R2 EVENT_SA_REPLACE | MODE_CFG_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | MODE_CFG_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | XAUTH_I0: category: established IKE SA flags: 0: | -> XAUTH_I1 EVENT_RETRANSMIT | XAUTH_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_RETRANSMIT | checking IKEv2 state table | PARENT_I0: category: ignore flags: 0: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) | PARENT_I1: category: half-open IKE SA flags: 0: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) | PARENT_I2: category: open IKE SA flags: 0: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) | PARENT_I3: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) | PARENT_R0: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) | PARENT_R1: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) | PARENT_R2: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) | V2_CREATE_I0: category: established IKE SA flags: 0: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) | V2_CREATE_I: category: established IKE SA flags: 0: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) | V2_REKEY_IKE_I: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: | V2_CREATE_R: category: established IKE SA flags: 0: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) | V2_REKEY_IKE_R: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: | V2_IPSEC_I: category: established CHILD SA flags: 0: | V2_IPSEC_R: category: established CHILD SA flags: 0: | IKESA_DEL: category: established IKE SA flags: 0: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) | CHILDSA_DEL: category: informational flags: 0: Using Linux XFRM/NETKEY IPsec interface code on 5.1.18-200.fc29.x86_64 | Hard-wiring algorithms | adding AES_CCM_16 to kernel algorithm db | adding AES_CCM_12 to kernel algorithm db | adding AES_CCM_8 to kernel algorithm db | adding 3DES_CBC to kernel algorithm db | adding CAMELLIA_CBC to kernel algorithm db | adding AES_GCM_16 to kernel algorithm db | adding AES_GCM_12 to kernel algorithm db | adding AES_GCM_8 to kernel algorithm db | adding AES_CTR to kernel algorithm db | adding AES_CBC to kernel algorithm db | adding SERPENT_CBC to kernel algorithm db | adding TWOFISH_CBC to kernel algorithm db | adding NULL_AUTH_AES_GMAC to kernel algorithm db | adding NULL to kernel algorithm db | adding CHACHA20_POLY1305 to kernel algorithm db | adding HMAC_MD5_96 to kernel algorithm db | adding HMAC_SHA1_96 to kernel algorithm db | adding HMAC_SHA2_512_256 to kernel algorithm db | adding HMAC_SHA2_384_192 to kernel algorithm db | adding HMAC_SHA2_256_128 to kernel algorithm db | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db | adding AES_XCBC_96 to kernel algorithm db | adding AES_CMAC_96 to kernel algorithm db | adding NONE to kernel algorithm db | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds | setup kernel fd callback | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x55613f0b8408 | libevent_malloc: new ptr-libevent@0x55613f0f7478 size 128 | libevent_malloc: new ptr-libevent@0x55613f0fe508 size 16 | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x55613f0fe498 | libevent_malloc: new ptr-libevent@0x55613f0b0ec8 size 128 | libevent_malloc: new ptr-libevent@0x55613f0fe168 size 16 | global one-shot timer EVENT_CHECK_CRLS initialized selinux support is enabled. | unbound context created - setting debug level to 5 | /etc/hosts lookups activated | /etc/resolv.conf usage activated | outgoing-port-avoid set 0-65535 | outgoing-port-permit set 32768-60999 | Loading dnssec root key from:/var/lib/unbound/root.key | No additional dnssec trust anchors defined via dnssec-trusted= option | Setting up events, loop start | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x55613f0fe938 | libevent_malloc: new ptr-libevent@0x55613f10a818 size 128 | libevent_malloc: new ptr-libevent@0x55613f115b08 size 16 | libevent_realloc: new ptr-libevent@0x55613f115b48 size 256 | libevent_malloc: new ptr-libevent@0x55613f115c78 size 8 | libevent_realloc: new ptr-libevent@0x55613f115cb8 size 144 | libevent_malloc: new ptr-libevent@0x55613f0bc9d8 size 152 | libevent_malloc: new ptr-libevent@0x55613f115d78 size 16 | signal event handler PLUTO_SIGCHLD installed | libevent_malloc: new ptr-libevent@0x55613f115db8 size 8 | libevent_malloc: new ptr-libevent@0x55613f03a728 size 152 | signal event handler PLUTO_SIGTERM installed | libevent_malloc: new ptr-libevent@0x55613f115df8 size 8 | libevent_malloc: new ptr-libevent@0x55613f115e38 size 152 | signal event handler PLUTO_SIGHUP installed | libevent_malloc: new ptr-libevent@0x55613f115f08 size 8 | libevent_realloc: release ptr-libevent@0x55613f115cb8 | libevent_realloc: new ptr-libevent@0x55613f115f48 size 256 | libevent_malloc: new ptr-libevent@0x55613f116078 size 152 | signal event handler PLUTO_SIGSYS installed | created addconn helper (pid:23650) using fork+execve | forked child 23650 | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.2.254 | Inspecting interface eth1 | found eth1 with address 192.1.2.23 Kernel supports NIC esp-hw-offload adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.2.23:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth1/eth1 192.1.2.23:4500 adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.2.254:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0/eth0 192.0.2.254:4500 adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface lo/lo 127.0.0.1:4500 | no interfaces to sort | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | add_fd_read_event_handler: new ethX-pe@0x55613f116658 | libevent_malloc: new ptr-libevent@0x55613f10a768 size 128 | libevent_malloc: new ptr-libevent@0x55613f1166c8 size 16 | setup callback for interface lo 127.0.0.1:4500 fd 22 | add_fd_read_event_handler: new ethX-pe@0x55613f116708 | libevent_malloc: new ptr-libevent@0x55613f0b0f78 size 128 | libevent_malloc: new ptr-libevent@0x55613f116778 size 16 | setup callback for interface lo 127.0.0.1:500 fd 21 | add_fd_read_event_handler: new ethX-pe@0x55613f1167b8 | libevent_malloc: new ptr-libevent@0x55613f0b0898 size 128 | libevent_malloc: new ptr-libevent@0x55613f116828 size 16 | setup callback for interface eth0 192.0.2.254:4500 fd 20 | add_fd_read_event_handler: new ethX-pe@0x55613f116868 | libevent_malloc: new ptr-libevent@0x55613f0b8158 size 128 | libevent_malloc: new ptr-libevent@0x55613f1168d8 size 16 | setup callback for interface eth0 192.0.2.254:500 fd 19 | add_fd_read_event_handler: new ethX-pe@0x55613f116918 | libevent_malloc: new ptr-libevent@0x55613f0b8258 size 128 | libevent_malloc: new ptr-libevent@0x55613f116988 size 16 | setup callback for interface eth1 192.1.2.23:4500 fd 18 | add_fd_read_event_handler: new ethX-pe@0x55613f1169c8 | libevent_malloc: new ptr-libevent@0x55613f0b8358 size 128 | libevent_malloc: new ptr-libevent@0x55613f116a38 size 16 | setup callback for interface eth1 192.1.2.23:500 fd 17 | certs and keys locked by 'free_preshared_secrets' | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | id type added to secret(0x55613f006c48) PKK_PSK: @road | id type added to secret(0x55613f006c48) PKK_PSK: @east | Processing PSK at line 1: passed | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.543 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.2.254 | Inspecting interface eth1 | found eth1 with address 192.1.2.23 | no interfaces to sort | libevent_free: release ptr-libevent@0x55613f10a768 | free_event_entry: release EVENT_NULL-pe@0x55613f116658 | add_fd_read_event_handler: new ethX-pe@0x55613f116658 | libevent_malloc: new ptr-libevent@0x55613f10a768 size 128 | setup callback for interface lo 127.0.0.1:4500 fd 22 | libevent_free: release ptr-libevent@0x55613f0b0f78 | free_event_entry: release EVENT_NULL-pe@0x55613f116708 | add_fd_read_event_handler: new ethX-pe@0x55613f116708 | libevent_malloc: new ptr-libevent@0x55613f0b0f78 size 128 | setup callback for interface lo 127.0.0.1:500 fd 21 | libevent_free: release ptr-libevent@0x55613f0b0898 | free_event_entry: release EVENT_NULL-pe@0x55613f1167b8 | add_fd_read_event_handler: new ethX-pe@0x55613f1167b8 | libevent_malloc: new ptr-libevent@0x55613f0b0898 size 128 | setup callback for interface eth0 192.0.2.254:4500 fd 20 | libevent_free: release ptr-libevent@0x55613f0b8158 | free_event_entry: release EVENT_NULL-pe@0x55613f116868 | add_fd_read_event_handler: new ethX-pe@0x55613f116868 | libevent_malloc: new ptr-libevent@0x55613f0b8158 size 128 | setup callback for interface eth0 192.0.2.254:500 fd 19 | libevent_free: release ptr-libevent@0x55613f0b8258 | free_event_entry: release EVENT_NULL-pe@0x55613f116918 | add_fd_read_event_handler: new ethX-pe@0x55613f116918 | libevent_malloc: new ptr-libevent@0x55613f0b8258 size 128 | setup callback for interface eth1 192.1.2.23:4500 fd 18 | libevent_free: release ptr-libevent@0x55613f0b8358 | free_event_entry: release EVENT_NULL-pe@0x55613f1169c8 | add_fd_read_event_handler: new ethX-pe@0x55613f1169c8 | libevent_malloc: new ptr-libevent@0x55613f0b8358 size 128 | setup callback for interface eth1 192.1.2.23:500 fd 17 | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | id type added to secret(0x55613f006c48) PKK_PSK: @road | id type added to secret(0x55613f006c48) PKK_PSK: @east | Processing PSK at line 1: passed | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.282 milliseconds in whack | processing signal PLUTO_SIGCHLD | waitpid returned pid 23650 (exited with status 0) | reaped addconn helper child (status 0) | waitpid returned ECHILD (no child processes left) | spent 0.0178 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection north-east with policy RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | ike (phase1) algorithm values: AES_CBC_128-HMAC_SHA1-MODP2048 | from whack: got --esp=aes128-sha1 | ESP/AH string values: AES_CBC_128-HMAC_SHA1_96 | counting wild cards for %fromcert is 0 | setting ID to ID_DER_ASN1_DN: 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading right certificate 'east' pubkey | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f11bc78 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f11bc28 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f11bae8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f118d28 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f118c28 | unreference key: 0x55613f11bcc8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | certs and keys locked by 'lsw_add_rsa_secret' | certs and keys unlocked by 'lsw_add_rsa_secret' | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | based upon policy, the connection is a template. | connect_to_host_pair: 192.1.2.23:500 0.0.0.0:500 -> hp@(nil): none | new hp@0x55613f11bf88 added connection description "north-east" | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]...%any[%fromcert] | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.06 milliseconds in whack | spent 0.00305 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 876 bytes from 192.1.3.33:500 on eth1 (192.1.2.23:500) | 16 38 87 b3 8a 6a b1 69 00 00 00 00 00 00 00 00 | 01 10 04 00 00 00 00 00 00 00 03 6c 04 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 00 80 0a 00 01 04 4f 24 95 88 b7 8e aa 07 | 01 da 13 14 55 c3 0b fd 9e 59 38 1b de 17 9e dd | ce c4 87 99 cc fc fd 07 50 f8 4a f7 3a 85 7e 46 | 5e a2 70 e9 46 28 4b ed a9 92 a1 54 a7 a2 ec b1 | 74 2a 4d f0 ca 4c 24 39 51 69 a1 0c 08 e8 eb a7 | 92 9e ca af fb 72 8f bd 40 a9 2f a3 47 75 14 d6 | 9c 34 82 c9 c9 bf 74 5d d2 5b b2 4e a3 02 a3 41 | 00 00 6b d7 5f dd 2e c3 d4 ee 43 8e be 01 58 02 | a9 65 6a 51 53 3f b4 2e 2d 0f 44 9d ef 69 8f 22 | 08 35 37 73 28 92 ff 3f bb f5 44 06 48 4a 5a a0 | de ec 31 9c e4 b9 00 2c 7f d0 36 9d d8 0a d9 1d | 1f 94 08 fc 7c 8b 24 31 d1 ad e2 00 49 a1 42 f6 | ca 2b e5 30 f4 d8 cb 44 38 b0 37 b1 a7 60 a6 f3 | b3 29 41 d2 4b c7 e0 db 5a 5c 4f aa ea c9 54 7a | 58 1d 8d f8 42 14 22 a9 5f 50 8f 91 2a d9 49 01 | 2c 5c 00 2d f6 c9 75 52 b3 35 67 e8 33 c9 9c 4a | a2 c8 ac 2a a6 91 56 39 05 00 00 24 a7 58 a1 6e | d1 cb 09 aa c2 26 f8 60 0b 25 88 12 b5 a8 8e 8e | 87 73 7e 84 06 2d e7 5a f5 2a de a3 07 00 00 c1 | 09 00 00 00 30 81 b6 31 0b 30 09 06 03 55 04 06 | 13 02 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f | 6e 74 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c | 07 54 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 | 0a 0c 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 | 06 03 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 | 72 74 6d 65 6e 74 31 24 30 22 06 03 55 04 03 0c | 1b 6e 6f 72 74 68 2e 74 65 73 74 69 6e 67 2e 6c | 69 62 72 65 73 77 61 6e 2e 6f 72 67 31 2f 30 2d | 06 09 2a 86 48 86 f7 0d 01 09 01 16 20 75 73 65 | 72 2d 6e 6f 72 74 68 40 74 65 73 74 69 6e 67 2e | 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 0d 00 00 | b4 04 30 81 ac 31 0b 30 09 06 03 55 04 06 13 02 | 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | 6d 65 6e 74 31 25 30 23 06 03 55 04 03 0c 1c 4c | 69 62 72 65 73 77 61 6e 20 74 65 73 74 20 43 41 | 20 66 6f 72 20 6d 61 69 6e 63 61 31 24 30 22 06 | 09 2a 86 48 86 f7 0d 01 09 01 16 15 74 65 73 74 | 69 6e 67 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 | 67 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de | 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 | c9 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c | 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 | 14 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d | 56 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 | b5 ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 | f8 7c fd b2 fc 68 b6 a4 48 00 00 00 | start processing: from 192.1.3.33:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_AGGR (0x4) | flags: none (0x0) | Message ID: 0 (0x0) | length: 876 (0x36c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_AGGR (4) | State DB: IKEv1 state not found (find_state_ikev1_init) | #null state always idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x432 opt: 0x102000 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x430 opt: 0x102000 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x420 opt: 0x102000 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 36 (0x24) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x20 opt: 0x102000 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | length: 193 (0xc1) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e 6f 72 | obj: 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 | obj: 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 2a 86 | obj: 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d 6e 6f | obj: 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | obj: 65 73 77 61 6e 2e 6f 72 67 | got payload 0x80 (ISAKMP_NEXT_CR) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 180 (0xb4) | cert type: CERT_X509_SIGNATURE (0x4) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | removing 3 bytes of padding | message 'aggr_inI1_outR1' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | in statetime_start() with no state | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | find_host_connection local=192.1.2.23:500 remote=192.1.3.33:500 policy=RSASIG+AGGRESSIVE+IKEV1_ALLOW but ignoring ports | find_next_host_connection policy=RSASIG+AGGRESSIVE+IKEV1_ALLOW | find_next_host_connection returns empty | find_host_connection local=192.1.2.23:500 remote= policy=RSASIG+AGGRESSIVE+IKEV1_ALLOW but ignoring ports | find_host_pair: comparing 192.1.2.23:500 to 0.0.0.0:500 but ignoring ports | find_next_host_connection policy=RSASIG+AGGRESSIVE+IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (north-east) | find_next_host_connection returns north-east | find_next_host_connection policy=RSASIG+AGGRESSIVE+IKEV1_ALLOW | find_next_host_connection returns empty | connect_to_host_pair: 192.1.2.23:500 192.1.3.33:500 -> hp@(nil): none | new hp@0x55613f11d268 | rw_instantiate() instantiated "north-east"[1] 192.1.3.33 for 192.1.3.33 | creating state object #1 at 0x55613f120018 | State DB: adding IKEv1 state #1 in UNDEFINED | pstats #1 ikev1.isakmp started | #1 updating local interface from to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2669) | start processing: state #1 from 192.1.3.33:500 (in aggr_inI1_outR1() at ikev1_aggr.c:181) | parent state #1: UNDEFINED(ignore) => AGGR_R1(open IKE SA) | DER ASN1 DN: 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e 6f 72 | DER ASN1 DN: 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 | DER ASN1 DN: 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 2a 86 | DER ASN1 DN: 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d 6e 6f | DER ASN1 DN: 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | DER ASN1 DN: 65 73 77 61 6e 2e 6f 72 67 "north-east"[1] 192.1.3.33 #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' | X509: no CERT payloads to process | CR 30 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 | CR 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | CR 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | CR 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | CR 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | CR 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | CR 6e 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 | CR 72 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 | CR 6f 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a | CR 86 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e | CR 67 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 | requested CA: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' "north-east"[1] 192.1.3.33 #1: responding to Aggressive Mode, state #1, connection "north-east"[1] 192.1.3.33 from 192.1.3.33 | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | OAKLEY proposal verified; matching alg_info found | Oakley Transform 0 accepted | adding outI2 KE work-order 1 for state #1 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x55613f11e988 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x55613f118d78 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #1 and saving MD | crypto helper 1 resuming | crypto helper 1 starting work-order 1 for state #1 | #1 is busy; has a suspended MD | crypto helper 1 doing build KE and nonce (outI2 KE); request ID 1 | stop processing: from 192.1.3.33:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.658 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 1 finished build KE and nonce (outI2 KE); request ID 1 time elapsed 0.000915 seconds | (#1) spent 0.882 milliseconds in crypto helper computing work-order 1: outI2 KE (pcr) | crypto helper 1 sending results from work-order 1 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f2200002888 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 1 | calling continuation function 0x55613d288b50 | aggr inI1_outR1: calculated ke+nonce, calculating DH | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_PSK | 1: compared key @east to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org -> 000 | 2: compared key @road to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org -> 000 | line 1: match=000 | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding aggr outR1 DH work-order 2 for state #1 | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x55613f118d78 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x55613f11e988 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x55613f11e988 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x55613f118d78 size 128 | crypto helper 2 resuming | crypto helper 2 starting work-order 2 for state #1 | crypto helper 2 doing compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 2 | crypto helper 2 finished compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 2 time elapsed 0.001113 seconds | (#1) spent 1.12 milliseconds in crypto helper computing work-order 2: aggr outR1 DH (pcr) | crypto helper 2 sending results from work-order 2 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f21f8005088 size 128 | crypto helper 2 waiting (nothing to do) | suspending state #1 and saving MD | #1 is busy; has a suspended MD | resume sending helper answer for #1 suppresed complete_v1_state_transition() and stole MD | #1 spent 0.0932 milliseconds in resume sending helper answer | stop processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f2200002888 | processing resume sending helper answer for #1 | start processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:797) | crypto helper 2 replies to request ID 2 | calling continuation function 0x55613d288b50 | aggr_inI1_outR1_continue2 for #1: calculated ke+nonce+DH, sending R1 | CR 30 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 | CR 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | CR 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | CR 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | CR 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | CR 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | CR 6e 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 | CR 72 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 | CR 6f 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a | CR 86 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e | CR 67 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 | requested CA: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | thinking about whether to send my certificate: | I have RSA key: OAKLEY_RSA_SIG cert.type: CERT_X509_SIGNATURE | sendcert: CERT_ALWAYSSEND and I did get a certificate request | so send cert. | I am sending a certificate request | **emit ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_AGGR (0x4) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | OAKLEY proposal verified; matching alg_info found | Oakley Transform 0 accepted | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | emitting 28 raw bytes of attributes into ISAKMP Transform Payload (ISAKMP) | attributes 80 0b 00 01 80 0c 0e 10 80 01 00 07 80 02 00 02 | attributes 80 03 00 03 80 04 00 0e 80 0e 00 80 | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 15 d2 6c d0 82 65 65 5e cb de 6e 1e 9b 12 27 1d | keyex value 7b 42 70 eb 5e a2 0d de 08 fd 33 92 dc 83 f7 ea | keyex value c5 42 41 84 85 0c 95 58 8d 0b 8c 9e 8a 9c 79 25 | keyex value b6 9a 93 76 cc 47 3c 40 c3 89 40 de 9c 59 a0 18 | keyex value ef 5e 25 cf e9 b6 61 8c be 0f 87 91 29 a0 87 8a | keyex value c7 69 5d 76 7e 89 4b 39 c8 4a b2 a7 52 bf f5 b7 | keyex value b7 3c 9e 1a 00 8a 6a 21 3f 9b 6e 63 56 c5 8e f4 | keyex value 98 98 23 20 e1 4f a1 df da b5 9b 60 ac f0 c3 14 | keyex value c3 86 f3 76 c3 75 3d e2 00 2a b2 d2 82 e1 e2 ad | keyex value e8 ed 29 21 6e 26 48 c3 39 22 b4 df ad 27 72 b0 | keyex value 16 d0 d6 ed ac 4c b8 6b 39 0b 1a db 67 79 51 90 | keyex value ef 6d 7c 4d 82 d1 73 5e 28 34 0e 23 6b 2b 43 39 | keyex value a6 07 16 6c ea f4 b4 e7 76 f7 e3 21 9c 23 20 03 | keyex value 33 1e 3f 8c 7a f3 5f 4f af c6 9a c2 c4 eb 63 43 | keyex value cb 89 e6 0b 1f f5 39 27 85 7d b2 e8 be 58 56 b4 | keyex value 3b 33 08 03 77 e8 15 c8 b5 a5 f8 b3 99 5c 1b 23 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 4f 8e b6 ed 3c e1 4b 6a d1 5d 61 a0 0e a1 97 1a | Nr 6d 63 09 1a e1 74 aa cf 73 f8 32 23 2c be 4d d9 | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_CERT (0x6) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 6:ISAKMP_NEXT_CERT | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 183 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | my identity 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | my identity 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | my identity 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 191 "north-east"[1] 192.1.3.33 #1: I am sending my certificate | ***emit ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | cert encoding: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate Payload'.'next payload type' value 7:ISAKMP_NEXT_CR | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Certificate Payload (6:ISAKMP_NEXT_CERT) | next payload chain: saving location 'ISAKMP Certificate Payload'.'next payload type' in 'reply packet' | emitting 1260 raw bytes of CERT into ISAKMP Certificate Payload | CERT 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 03 | CERT 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | CERT 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | CERT 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | CERT 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | CERT 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | CERT 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | CERT 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | CERT 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | CERT 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | CERT 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | CERT 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | CERT 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | CERT 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | CERT 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | CERT 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | CERT 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | CERT 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | CERT 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | CERT 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | CERT 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | CERT 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 | CERT 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | CERT 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 | CERT 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | CERT 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | CERT 00 30 82 01 8a 02 82 01 81 00 b1 1e 7c b3 bf 11 | CERT 96 94 23 ca 97 5e c7 66 36 55 71 49 95 8d 0c 2a | CERT 5c 30 4d 58 29 a3 7b 4d 3b 3f 03 06 46 a6 04 63 | CERT 71 0d e1 59 4f 9c ec 3a 17 24 8d 91 6a a8 e2 da | CERT 57 41 de f4 ff 65 bf f6 11 34 d3 7d 5a 7f 6e 3a | CERT 3b 74 3c 51 2b e4 bf ce 6b b2 14 47 26 52 f5 57 | CERT 28 bc c5 fb f9 bc 2d 4e b9 f8 46 54 c7 95 41 a7 | CERT a4 b4 d3 b3 fe 55 4b df f5 c3 78 39 8b 4e 04 57 | CERT c0 1d 5b 17 3c 28 eb 40 9d 1d 7c b3 bb 0f f0 63 | CERT c7 c0 84 b0 4e e4 a9 7c c5 4b 08 43 a6 2d 00 22 | CERT fd 98 d4 03 d0 ad 97 85 d1 48 15 d3 e4 e5 2d 46 | CERT 7c ab 41 97 05 27 61 77 3d b6 b1 58 a0 5f e0 8d | CERT 26 84 9b 03 20 ce 5e 27 7f 7d 14 03 b6 9d 6b 9f | CERT fd 0c d4 c7 2d eb be ea 62 87 fa 99 e0 a6 1c 85 | CERT 4f 34 da 93 2e 5f db 03 10 58 a8 c4 99 17 2d b1 | CERT bc e5 7b bd af 0e 28 aa a5 74 ea 69 74 5e fa 2c | CERT c3 00 3c 2f 58 d0 20 cf e3 46 8d de aa f9 f7 30 | CERT 5c 16 05 04 89 4c 92 9b 8a 33 11 70 83 17 58 24 | CERT 2a 4b ab be b6 ec 84 9c 78 9c 11 04 2a 02 ce 27 | CERT 83 a1 1f 2b 38 3f 27 7d 46 94 63 ff 64 59 4e 6c | CERT 87 ca 3e e6 31 df 1e 7d 48 88 02 c7 9d fa 4a d7 | CERT f2 5b a5 fd 7f 1b c6 dc 1a bb a6 c4 f8 32 cd bf | CERT a7 0b 71 8b 2b 31 41 17 25 a4 18 52 7d 32 fc 0f | CERT 5f b8 bb ca e1 94 1a 42 4d 1f 37 16 67 84 ae b4 | CERT 32 42 9c 5a 91 71 62 b4 4b 07 02 03 01 00 01 a3 | CERT 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | CERT 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 65 | CERT 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 81 1a 65 61 73 74 40 | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 87 04 c0 01 02 17 30 0b 06 03 55 | CERT 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | CERT 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | CERT 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | CERT 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | CERT 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | CERT 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | CERT 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | CERT 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | CERT 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | CERT 86 f7 0d 01 01 0b 05 00 03 81 81 00 3a 56 a3 7d | CERT b1 4e 62 2f 82 0d e3 fe 74 40 ef cb eb 93 ea ad | CERT e4 74 8b 80 6f ae 8b 65 87 12 a6 24 0d 21 9c 5f | CERT 70 5c 6f d9 66 8d 98 8b ea 59 f8 96 52 6a 6c 86 | CERT d6 7d ba 37 a9 8c 33 8c 77 18 23 0b 1b 2a 66 47 | CERT e7 95 94 e6 75 84 30 d4 db b8 23 eb 89 82 a9 fd | CERT ed 46 8b ce 46 7f f9 19 8f 49 da 29 2e 1e 97 cd | CERT 12 42 86 c7 57 fc 4f 0a 19 26 8a a1 0d 26 81 4d | CERT 53 f4 5c 92 a1 03 03 8d 6c 51 33 cc | emitting length of ISAKMP Certificate Payload: 1265 "north-east"[1] 192.1.3.33 #1: I am sending a certificate request | ***emit ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | cert type: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate RequestPayload'.'next payload type' value 9:ISAKMP_NEXT_SIG | next payload chain: setting previous 'ISAKMP Certificate Payload'.'next payload type' to current ISAKMP Certificate RequestPayload (7:ISAKMP_NEXT_CR) | next payload chain: saving location 'ISAKMP Certificate RequestPayload'.'next payload type' in 'reply packet' | emitting length of ISAKMP Certificate RequestPayload: 5 | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAbEef vs PKK_RSA:AwEAAbEef | ***emit ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Signature Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Certificate RequestPayload'.'next payload type' to current ISAKMP Signature Payload (9:ISAKMP_NEXT_SIG) | next payload chain: saving location 'ISAKMP Signature Payload'.'next payload type' in 'reply packet' | emitting 384 raw bytes of SIG_R into ISAKMP Signature Payload | SIG_R 20 a8 7a 55 75 1d 05 7e 1b 6c cb d5 a7 c0 3a d1 | SIG_R 83 5f 6a 62 7c 4f 6d 45 83 51 da 6b 5f f6 56 ed | SIG_R 28 ee 2b 7d ac 5f 96 f3 4c 45 ea 06 bf a3 af e6 | SIG_R 7c 21 a1 53 8a 4c fd 98 3c 85 20 c6 3d 3f 7f c2 | SIG_R fb 58 06 d3 56 26 6c 6f af eb 0c 2d 52 b1 9c 66 | SIG_R cc 2b c6 fc c1 7b 4f a3 9c 6c 14 31 14 bc 2b d8 | SIG_R 89 cc 29 3c e5 56 a1 a1 11 38 d0 fd 6d 4a 8c 0c | SIG_R 82 02 79 f3 b0 c0 1c cb 44 1d a6 16 9b cc 83 57 | SIG_R 9b 8b 68 74 86 13 db e6 f9 73 2e 2c 73 b2 f2 0d | SIG_R 01 6d dd 63 83 21 65 30 18 e2 94 06 e1 57 65 cf | SIG_R bc 5c bf 91 71 37 20 06 6d 24 7f e4 2e 1d 32 b5 | SIG_R ef e8 72 ea b7 f8 a3 91 81 dd 94 e1 46 bc 45 45 | SIG_R af 1f c6 c2 88 f4 29 3c 78 ee ec 6e a0 6a 67 1d | SIG_R aa 11 27 72 11 79 de f6 ab 33 26 1f 4c 19 dd a1 | SIG_R 12 7d 67 bb dc af b8 3a 06 c7 7a c4 c8 0b 49 a8 | SIG_R e6 b0 a0 da b1 15 1a 2b 57 ea cc 16 83 e0 35 fb | SIG_R a0 bc 59 5a 50 83 3b 5d 9c b7 6e aa 07 1d 5f a5 | SIG_R c4 fb 27 48 6a c9 52 44 04 4f 3d cd c1 8f 95 dd | SIG_R 31 9a ad f3 1a a1 ed 44 1a 0c 35 6c 76 1f 05 4f | SIG_R 6a bf 84 d1 37 94 94 45 91 6d cc 72 1b 52 ce 6e | SIG_R 19 97 37 21 a0 9e 55 fb 5e 3a d9 17 2f 70 58 d7 | SIG_R 4d 0a 12 fc 05 23 6f 1c 5a b7 15 46 6a 92 e1 29 | SIG_R e2 27 91 c4 08 ab 3d a1 96 5d b0 d6 38 36 a4 68 | SIG_R 7b 1c 30 78 fb 64 24 f3 fd 26 5e d9 4c 1a 67 23 | emitting length of ISAKMP Signature Payload: 388 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Signature Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | sending NAT-D payloads | natd_hash: hasher=0x55613d35d800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 03 21 | natd_hash: port=500 | natd_hash: hash= ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | natd_hash: hash= ff 9d 6f 9e | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 20 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | NAT-D ff 9d 6f 9e | emitting length of ISAKMP NAT-D Payload: 24 | natd_hash: hasher=0x55613d35d800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | natd_hash: hash= 2d 31 22 d4 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 20 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | NAT-D 2d 31 22 d4 | emitting length of ISAKMP NAT-D Payload: 24 | padding IKEv1 message with 3 bytes | emitting 3 zero bytes of message padding into ISAKMP Message | emitting length of ISAKMP Message: 2340 | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_AGGR_R0 to state STATE_AGGR_R1 | event_already_set, deleting event | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x55613f118d78 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x55613f11e988 | sending reply packet to 192.1.3.33:500 (from 192.1.2.23:500) | sending 2340 bytes for STATE_AGGR_R0 through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 01 10 04 00 00 00 00 00 00 00 09 24 04 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 00 80 0a 00 01 04 15 d2 6c d0 82 65 65 5e | cb de 6e 1e 9b 12 27 1d 7b 42 70 eb 5e a2 0d de | 08 fd 33 92 dc 83 f7 ea c5 42 41 84 85 0c 95 58 | 8d 0b 8c 9e 8a 9c 79 25 b6 9a 93 76 cc 47 3c 40 | c3 89 40 de 9c 59 a0 18 ef 5e 25 cf e9 b6 61 8c | be 0f 87 91 29 a0 87 8a c7 69 5d 76 7e 89 4b 39 | c8 4a b2 a7 52 bf f5 b7 b7 3c 9e 1a 00 8a 6a 21 | 3f 9b 6e 63 56 c5 8e f4 98 98 23 20 e1 4f a1 df | da b5 9b 60 ac f0 c3 14 c3 86 f3 76 c3 75 3d e2 | 00 2a b2 d2 82 e1 e2 ad e8 ed 29 21 6e 26 48 c3 | 39 22 b4 df ad 27 72 b0 16 d0 d6 ed ac 4c b8 6b | 39 0b 1a db 67 79 51 90 ef 6d 7c 4d 82 d1 73 5e | 28 34 0e 23 6b 2b 43 39 a6 07 16 6c ea f4 b4 e7 | 76 f7 e3 21 9c 23 20 03 33 1e 3f 8c 7a f3 5f 4f | af c6 9a c2 c4 eb 63 43 cb 89 e6 0b 1f f5 39 27 | 85 7d b2 e8 be 58 56 b4 3b 33 08 03 77 e8 15 c8 | b5 a5 f8 b3 99 5c 1b 23 05 00 00 24 4f 8e b6 ed | 3c e1 4b 6a d1 5d 61 a0 0e a1 97 1a 6d 63 09 1a | e1 74 aa cf 73 f8 32 23 2c be 4d d9 06 00 00 bf | 09 00 00 00 30 81 b4 31 0b 30 09 06 03 55 04 06 | 13 02 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f | 6e 74 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c | 07 54 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 | 0a 0c 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 | 06 03 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 | 72 74 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c | 1a 65 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 | 62 72 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 | 09 2a 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 | 2d 65 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 | 62 72 65 73 77 61 6e 2e 6f 72 67 07 00 04 f1 04 | 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 03 | 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 | 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 | 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | 00 30 82 01 8a 02 82 01 81 00 b1 1e 7c b3 bf 11 | 96 94 23 ca 97 5e c7 66 36 55 71 49 95 8d 0c 2a | 5c 30 4d 58 29 a3 7b 4d 3b 3f 03 06 46 a6 04 63 | 71 0d e1 59 4f 9c ec 3a 17 24 8d 91 6a a8 e2 da | 57 41 de f4 ff 65 bf f6 11 34 d3 7d 5a 7f 6e 3a | 3b 74 3c 51 2b e4 bf ce 6b b2 14 47 26 52 f5 57 | 28 bc c5 fb f9 bc 2d 4e b9 f8 46 54 c7 95 41 a7 | a4 b4 d3 b3 fe 55 4b df f5 c3 78 39 8b 4e 04 57 | c0 1d 5b 17 3c 28 eb 40 9d 1d 7c b3 bb 0f f0 63 | c7 c0 84 b0 4e e4 a9 7c c5 4b 08 43 a6 2d 00 22 | fd 98 d4 03 d0 ad 97 85 d1 48 15 d3 e4 e5 2d 46 | 7c ab 41 97 05 27 61 77 3d b6 b1 58 a0 5f e0 8d | 26 84 9b 03 20 ce 5e 27 7f 7d 14 03 b6 9d 6b 9f | fd 0c d4 c7 2d eb be ea 62 87 fa 99 e0 a6 1c 85 | 4f 34 da 93 2e 5f db 03 10 58 a8 c4 99 17 2d b1 | bc e5 7b bd af 0e 28 aa a5 74 ea 69 74 5e fa 2c | c3 00 3c 2f 58 d0 20 cf e3 46 8d de aa f9 f7 30 | 5c 16 05 04 89 4c 92 9b 8a 33 11 70 83 17 58 24 | 2a 4b ab be b6 ec 84 9c 78 9c 11 04 2a 02 ce 27 | 83 a1 1f 2b 38 3f 27 7d 46 94 63 ff 64 59 4e 6c | 87 ca 3e e6 31 df 1e 7d 48 88 02 c7 9d fa 4a d7 | f2 5b a5 fd 7f 1b c6 dc 1a bb a6 c4 f8 32 cd bf | a7 0b 71 8b 2b 31 41 17 25 a4 18 52 7d 32 fc 0f | 5f b8 bb ca e1 94 1a 42 4d 1f 37 16 67 84 ae b4 | 32 42 9c 5a 91 71 62 b4 4b 07 02 03 01 00 01 a3 | 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 65 | 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | 65 73 77 61 6e 2e 6f 72 67 81 1a 65 61 73 74 40 | 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | 6e 2e 6f 72 67 87 04 c0 01 02 17 30 0b 06 03 55 | 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | 86 f7 0d 01 01 0b 05 00 03 81 81 00 3a 56 a3 7d | b1 4e 62 2f 82 0d e3 fe 74 40 ef cb eb 93 ea ad | e4 74 8b 80 6f ae 8b 65 87 12 a6 24 0d 21 9c 5f | 70 5c 6f d9 66 8d 98 8b ea 59 f8 96 52 6a 6c 86 | d6 7d ba 37 a9 8c 33 8c 77 18 23 0b 1b 2a 66 47 | e7 95 94 e6 75 84 30 d4 db b8 23 eb 89 82 a9 fd | ed 46 8b ce 46 7f f9 19 8f 49 da 29 2e 1e 97 cd | 12 42 86 c7 57 fc 4f 0a 19 26 8a a1 0d 26 81 4d | 53 f4 5c 92 a1 03 03 8d 6c 51 33 cc 09 00 00 05 | 04 0d 00 01 84 20 a8 7a 55 75 1d 05 7e 1b 6c cb | d5 a7 c0 3a d1 83 5f 6a 62 7c 4f 6d 45 83 51 da | 6b 5f f6 56 ed 28 ee 2b 7d ac 5f 96 f3 4c 45 ea | 06 bf a3 af e6 7c 21 a1 53 8a 4c fd 98 3c 85 20 | c6 3d 3f 7f c2 fb 58 06 d3 56 26 6c 6f af eb 0c | 2d 52 b1 9c 66 cc 2b c6 fc c1 7b 4f a3 9c 6c 14 | 31 14 bc 2b d8 89 cc 29 3c e5 56 a1 a1 11 38 d0 | fd 6d 4a 8c 0c 82 02 79 f3 b0 c0 1c cb 44 1d a6 | 16 9b cc 83 57 9b 8b 68 74 86 13 db e6 f9 73 2e | 2c 73 b2 f2 0d 01 6d dd 63 83 21 65 30 18 e2 94 | 06 e1 57 65 cf bc 5c bf 91 71 37 20 06 6d 24 7f | e4 2e 1d 32 b5 ef e8 72 ea b7 f8 a3 91 81 dd 94 | e1 46 bc 45 45 af 1f c6 c2 88 f4 29 3c 78 ee ec | 6e a0 6a 67 1d aa 11 27 72 11 79 de f6 ab 33 26 | 1f 4c 19 dd a1 12 7d 67 bb dc af b8 3a 06 c7 7a | c4 c8 0b 49 a8 e6 b0 a0 da b1 15 1a 2b 57 ea cc | 16 83 e0 35 fb a0 bc 59 5a 50 83 3b 5d 9c b7 6e | aa 07 1d 5f a5 c4 fb 27 48 6a c9 52 44 04 4f 3d | cd c1 8f 95 dd 31 9a ad f3 1a a1 ed 44 1a 0c 35 | 6c 76 1f 05 4f 6a bf 84 d1 37 94 94 45 91 6d cc | 72 1b 52 ce 6e 19 97 37 21 a0 9e 55 fb 5e 3a d9 | 17 2f 70 58 d7 4d 0a 12 fc 05 23 6f 1c 5a b7 15 | 46 6a 92 e1 29 e2 27 91 c4 08 ab 3d a1 96 5d b0 | d6 38 36 a4 68 7b 1c 30 78 fb 64 24 f3 fd 26 5e | d9 4c 1a 67 23 0d 00 00 14 40 48 b7 d5 6e bc e8 | 85 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 | 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 14 00 00 | 14 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 | 2f 14 00 00 18 ae 71 04 b4 74 f6 b2 d7 73 40 6b | e6 da 22 2e 2f ff 9d 6f 9e 00 00 00 18 4e 48 f5 | 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c 2d 31 22 | d4 00 00 00 | !event_already_set at reschedule | event_schedule: new EVENT_SO_DISCARD-pe@0x55613f11e988 | inserting event EVENT_SO_DISCARD, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x7f2200002888 size 128 "north-east"[1] 192.1.3.33 #1: STATE_AGGR_R1: sent AR1, expecting AI2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 10.8 milliseconds in resume sending helper answer | stop processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f21f8005088 | spent 0.00439 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 1708 bytes from 192.1.3.33:500 on eth1 (192.1.2.23:500) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 06 10 04 01 00 00 00 00 00 00 06 ac c2 1e fa e3 | 58 6b a9 88 9e 54 17 0a 88 cd dc 10 5d 59 a9 92 | 0f a4 3a a7 f7 54 36 f2 f4 6b 39 bd 51 31 f9 96 | 36 19 81 3d c8 ba d6 de 89 1a 75 28 f5 c4 7d f3 | 66 13 8f ea 32 07 fd 15 8d dc f8 ce e5 17 04 04 | 34 a7 44 c1 76 a6 53 5e 0a d4 df 16 42 99 1b ba | 2a ab f6 b3 fe b7 14 94 b3 13 5a fb 62 2a 98 c7 | 1e 8c 55 eb 0d 32 1a bf ca d6 c5 76 2c 55 f9 26 | fc 4d dc 50 22 56 48 a3 ec bf dc de 7d 29 da 52 | 70 04 ca 76 ab 8f 01 64 fe 61 62 7b 31 c4 5e d6 | 06 07 eb f3 a6 c5 1c 2b 4d e1 f8 78 a9 6c 20 3d | 66 79 90 cc 1f 81 ca 6f 50 03 48 ac a2 57 77 f0 | 08 84 84 44 4a d7 9a e4 e1 75 95 f8 db 5c 90 12 | 52 c9 15 7a a0 b2 13 a9 cc 98 0f 5b 4c 40 e3 30 | c1 ee 69 d5 c1 59 fd dd b2 4b 7b 2b 33 b8 51 b7 | e5 73 d6 aa ab ec 7a 4b 99 31 8c 9f 92 0e 31 52 | 5f ea e5 e6 3e 56 4d f3 f5 6b 5b 83 d0 b4 fa d0 | 24 54 85 63 ee 3d 92 ab 05 38 3e 90 8a c0 f0 16 | 48 70 bd bc 99 3e a2 40 79 b9 47 f2 0f b6 60 db | d5 6f 8f f3 bd d5 b5 f8 07 f9 32 15 22 cd 89 2e | ba 54 65 7f 7e f5 dd f9 26 94 21 78 79 fe 2e 5e | 34 88 0e 4b 35 28 0e 56 f8 8b 5a 3e 98 21 52 af | 87 90 7a 9d dd 46 de b7 b1 78 f3 b4 56 6e a6 04 | da 97 ff 4e d6 09 2d 3a 04 39 9f 6f 4e 0b f4 3f | 9b 81 50 69 53 ae 7a e7 67 8f 0d ed bc ac 15 1c | 9b 32 37 e8 fb c1 2e 2c 75 9a c1 0b 55 73 72 9f | 29 af b1 d8 47 3d 64 7c b3 96 94 b9 1b 90 1b 83 | 86 7b be 7c cd 09 f1 b4 25 d9 60 ef c6 2e 16 09 | d7 23 ec b5 88 49 f7 48 8a ca 15 0b 87 75 18 2c | d3 97 ff e6 d5 08 25 59 0c fb 40 83 dd 2e 1e 9d | e0 88 ac 50 70 c1 d5 ac a8 00 44 8f 9e 25 b0 0a | 25 82 62 3b 90 93 be d1 b8 d1 2d 81 a7 d4 b6 af | 29 63 48 5a 2d ac 84 9e 2d ae 40 90 5c 44 65 fc | 4c 65 3b 74 d7 2f 96 1f 1b 9b 39 ec 54 e2 78 98 | 81 23 16 79 7c 24 f8 e7 dd e7 76 fe 72 4e 0c 41 | 01 a9 74 0b 66 3e ea 8d ca bd 12 50 8f 26 45 d1 | 3d 4e df 1f 9d 75 1f 6c 27 48 87 7d f2 ed 58 30 | 8e 47 1a 60 58 6d a9 43 6a 39 67 e1 8d 48 fc 10 | 3a 57 b9 f2 c0 e6 99 67 11 c2 21 03 9c aa 99 cc | 1b d5 6f 01 b5 e6 ea 68 eb 6e 5b 03 b5 4f fb 05 | b5 8e a9 8b 2c bd e5 78 7d 24 c5 0b b5 3a f2 08 | d4 4f c9 7e 9e 61 a8 d4 00 53 ff 1b 81 92 f9 9c | cb 2a bb f2 5b ae 18 2d 77 88 9e f3 e8 62 2e eb | 04 bc 4f d7 86 05 4a f7 d2 dc 86 96 dd 74 52 10 | 87 f0 93 e6 eb ac 88 1c 34 64 53 38 41 80 8b 56 | 8f a3 e4 9e f2 e5 17 70 d4 b2 a9 82 e8 1f df fc | ff ef 47 27 f4 c2 f6 dc c7 30 b9 95 8a 65 89 35 | f8 ff 9c 6c ea b5 7a 5c ad 1b 9e b8 b5 89 50 b0 | 12 3d 31 74 75 a0 be 2a 61 26 fc 08 7c 89 10 85 | 4f 38 04 2d 5e 88 cc 4b eb d3 f8 cc 03 30 2e f7 | 76 c9 24 f1 59 1c 9c 8c 53 60 2c d0 4e b1 85 a0 | e9 18 1f 3c a6 27 fa a3 46 de b1 35 ec ca 4c a9 | a8 8d c5 d3 8c d7 a4 4b 43 68 ad 7a 18 f6 7e 6a | a8 6a 89 e7 02 f8 11 06 5f 5e b7 75 d4 e4 f1 09 | 8d 0f 81 69 48 12 cd 4d 21 d2 e7 1e 52 0a 35 66 | 77 8e 32 9c 77 78 1c cc 7d 51 b2 8e b5 19 ad ef | 68 dc a5 47 94 ad 50 ea af e4 42 db a5 2f 03 b9 | 53 b3 15 a0 f0 1f 86 1a 2d d6 4f 3e ee 6f 37 9d | ba 89 6c b7 78 c9 fe 4e e9 75 73 1b 15 49 0d 44 | 49 19 75 23 63 80 f0 0d 0d 70 08 bf 53 38 f9 a6 | af 43 38 de b7 64 6f 87 ef 64 35 9f e9 69 41 74 | 36 00 a9 c4 e7 ca 9c c5 a5 bb a2 be 03 77 8a 9a | 21 c2 5d c0 85 4f 33 14 13 0f 9a f6 62 fa d5 fe | 03 c1 9a 3f aa 8e 0c 90 ec fd 51 b2 87 c1 f5 f6 | 38 c3 99 3e fe ba 36 e6 ad cc 1f 25 91 b4 88 06 | 4f 37 69 ab fe 86 f1 ab ce b4 6b 36 b6 11 3e e4 | ca 60 d1 1e c1 56 45 1f 45 82 1c 96 93 be 19 b2 | 7a 48 7d d2 14 30 0b b7 0a 92 a8 23 8e cf aa 36 | 12 72 47 7f 87 f1 5e 2e 9f 7b c6 31 bc de b2 9b | ef 31 4b ad fb 58 cd 50 f9 e5 bd 24 3e 2d 1c 0b | 73 76 18 fd 78 65 56 b4 2f 5c e0 3b a3 c1 ae ed | 25 44 ff 79 15 89 98 a7 56 c1 56 40 41 c5 ec 52 | 0d 4f 50 87 00 1d 51 f7 c7 4c 19 05 2b ed bc 43 | 7f 1b 34 9f 04 a2 cf a6 d9 d0 0e 7c 93 98 d9 1e | 35 99 af a9 dd 60 eb a9 05 07 71 7b 29 f1 7a 44 | df 32 3e 0b 51 8b 60 ef 40 85 39 87 f6 70 a9 60 | 87 75 92 1f 3a 09 ab b4 05 27 34 f8 2f 99 60 bd | c6 61 93 c5 a9 43 62 08 31 ae 7f 52 d0 85 49 d9 | c8 7a d2 c3 e8 04 82 fc 7d 62 03 eb 91 a9 14 b3 | 18 12 64 f7 e8 60 06 f3 f5 1f 50 b9 2b 1b 33 8d | 16 1c 08 0f dd 92 11 a4 75 fa 70 aa 17 9f 7a 94 | 1a c7 88 33 77 2c 77 b6 4d 1b cc e2 cb 69 6b 02 | e8 c6 07 20 2e 58 ed 6a f3 7f 1b be 01 1e 92 8e | c4 aa 76 90 1b f9 57 c5 95 81 c5 45 6a 4f be 38 | ce 2a b7 27 85 bd 53 10 f7 7b 87 92 a4 9e 07 0f | e6 dd 47 81 15 83 38 e4 2f d9 58 ed 9a 37 00 30 | 4c e1 0f ea c0 9b 4e 8a 6d 2b b2 c9 ee a5 a5 e9 | 20 f8 b3 5c de 8c ca ea 7f 85 1f 7a 46 ff f3 56 | d7 f7 02 87 a7 d5 09 11 32 60 6b 85 ae 3b 67 c1 | bc e0 ae b3 e4 4c cf ce 8e 68 f9 c4 49 7f 59 82 | cd 68 ea d5 08 5e e2 4e 9e 4f 7a 61 a5 6a 27 85 | 76 0b d7 d9 43 01 3e c7 fe 33 08 4f d2 25 3d 40 | 55 55 2e a3 fc 85 e1 2b a5 d2 ca f5 4b 91 76 6f | 45 2f fb 02 ca 1c 99 32 32 7a 49 2b 22 4a 37 86 | 18 1c 1b 50 f5 59 3a e4 47 ac af e6 02 20 42 85 | e9 8d 3c eb 28 98 9d 43 d8 a9 63 a7 fc 8e 8d ef | 47 da 44 4d d6 02 c3 32 aa 00 2d 9d f4 e4 29 4c | 40 e4 1f e5 fc f0 b6 e0 73 c8 a9 87 39 30 e0 e8 | 8f 50 19 c7 ea 4e 9e d7 7f f4 42 5f 0f 6c 5d f6 | 96 fd e1 01 51 8a 9c aa d5 eb 1c f5 2c 18 1c 08 | cf ec 41 d7 90 da e5 8b 77 ad 57 eb 29 8d 20 20 | ce 48 b4 e0 2a c8 1d c8 9e 76 4d 64 1d 2e 27 18 | 3f 7a a4 9f 83 fd fc 94 a0 b1 9b 60 69 fe 47 0b | 99 58 c3 b0 33 25 a7 94 dd fb b7 40 4c 7d 4b 54 | 01 2b 52 f4 9f be 91 2c 42 30 a3 5f 69 7d ba 6c | 25 bd db cc 4a d5 27 27 32 3e 9d ce | start processing: from 192.1.3.33:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_CERT (0x6) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_AGGR (0x4) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 1708 (0x6ac) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_AGGR (4) | State DB: found IKEv1 state #1 in AGGR_R1 (find_state_ikev1) | start processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | received encrypted packet from 192.1.3.33:500 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x102000 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 1232 (0x4d0) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x200 opt: 0x102000 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 24 (0x18) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x200 opt: 0x102000 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 24 (0x18) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x102000 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 12 bytes of padding | message 'aggr_inI2' HASH payload not checked early | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x55613d35d800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | natd_hash: hash= 2d 31 22 d4 | natd_hash: hasher=0x55613d35d800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 03 21 | natd_hash: port=500 | natd_hash: hash= ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | natd_hash: hash= ff 9d 6f 9e | expected NAT-D(me): 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | expected NAT-D(me): 2d 31 22 d4 | expected NAT-D(him): | ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | ff 9d 6f 9e | received NAT-D: 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | received NAT-D: 2d 31 22 d4 | received NAT-D: ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | received NAT-D: ff 9d 6f 9e | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.3.33 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | next payload chain: creating a fake payload for hashing identity | **emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: no previous for current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID); assumed to be fake | emitting 185 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e 6f 72 | my identity 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 | my identity 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 2a 86 | my identity 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d 6e 6f | my identity 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | my identity 65 73 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 193 | ***parse ISAKMP Identification Payload: | next payload type: 250?? (0xfa) | length: 193 (0xc1) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | DER ASN1 DN: 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e 6f 72 | DER ASN1 DN: 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 | DER ASN1 DN: 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 2a 86 | DER ASN1 DN: 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d 6e 6f | DER ASN1 DN: 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | DER ASN1 DN: 65 73 77 61 6e 2e 6f 72 67 "north-east"[1] 192.1.3.33 #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds loading root certificate cache | spent 4.09 milliseconds in get_root_certs() calling PK11_ListCertsInSlot() | spent 0.0314 milliseconds in get_root_certs() filtering CAs | #1 spent 4.15 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-north@testing.libreswan.org,CN=north.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.671 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.0473 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #1 spent 0.133 milliseconds in find_and_verify_certs() calling verify_end_cert() "north-east"[1] 192.1.3.33 #1: certificate verified OK: E=user-north@testing.libreswan.org,CN=north.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f12bed8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f138e18 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x55613f138c68 | unreference key: 0x55613f13cd48 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org cnt 1-- | #1 spent 0.256 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #1 spent 5.3 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | required RSA CA is '%any' | checking RSA keyid 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' for match with 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | key issuer CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | an RSA Sig check passed with *AwEAAcBZv [remote certificates] | #1 spent 0.151 milliseconds in try_all_RSA_keys() trying a pubkey "north-east"[1] 192.1.3.33 #1: Authenticated using RSA | phase 1 complete | FOR_EACH_CONNECTION_... in ISAKMP_SA_established | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_AGGR_R1 to state STATE_AGGR_R2 | parent state #1: AGGR_R1(open IKE SA) => AGGR_R2(established IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_SO_DISCARD to be deleted | libevent_free: release ptr-libevent@0x7f2200002888 | free_event_entry: release EVENT_SO_DISCARD-pe@0x55613f11e988 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x55613f11e988 | inserting event EVENT_SA_REPLACE, timeout in 3330 seconds for #1 | libevent_malloc: new ptr-libevent@0x55613f121e68 size 128 | pstats #1 ikev1.isakmp established "north-east"[1] 192.1.3.33 #1: STATE_AGGR_R2: ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_128 integ=HMAC_SHA1 group=MODP2048} | DPD: dpd_init() called on ISAKMP SA | DPD: Peer supports Dead Peer Detection | DPD: not initializing DPD because DPD is disabled locally | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | unpending state #1 | #1 spent 5.85 milliseconds in process_packet_tail() | stop processing: from 192.1.3.33:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 6.19 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00229 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 412 bytes from 192.1.3.33:500 on eth1 (192.1.2.23:500) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 08 10 20 01 bb 1f b0 6a 00 00 01 9c 34 98 a1 19 | 45 e9 e0 be d3 fc c8 ea e7 3c c7 12 8f 35 bb 93 | f7 cd be f4 90 b6 c5 6b 11 42 43 bb 77 76 69 4e | 0d ed 1f a7 aa de 29 69 b1 21 1e 85 a9 84 95 e3 | 96 e4 53 5f e8 5c 58 79 22 11 f9 97 26 09 0e d0 | c1 45 5c ff 41 0c 20 8e 45 7c 8f 86 b1 f4 6d 67 | 1b 44 9d 02 1a 2f f3 41 17 ee 96 a9 d0 3c f0 ba | 1b 1d de 0a d7 06 01 17 34 2d bc b5 b0 af 01 e9 | 0f 33 8f 09 31 ac 09 f0 89 27 59 61 08 17 07 8d | f8 2c 32 f4 29 d1 4c 11 e0 b6 4c c3 35 12 71 8e | 07 7e d1 be 3f 18 95 a4 ed 43 8c ff a1 60 56 c7 | 9d 2c 36 51 6e 62 49 b9 71 64 f3 68 3d 4c 97 a7 | 82 d2 72 67 a5 f5 ce 33 eb 10 29 50 17 37 53 f1 | de 3f 20 bc 0f 81 0d b6 8c 28 90 3e b5 30 1a c0 | 9f 2f 1e 63 b0 0c 8e a9 6c ac 66 c8 04 d6 33 eb | b9 47 66 f4 63 a2 7d 63 73 53 19 e3 2c 8d cb 1b | 36 57 b0 6f 3b 39 1b 49 8b 9d ec 4d ec 51 cf f1 | b5 c7 de 2c c2 73 b3 b4 d6 54 b6 7c ea d3 b7 e9 | 23 e7 86 9f 8a 93 b3 80 86 83 74 96 4c b1 6c 18 | 04 86 81 1f 9a 56 21 7d c1 b2 62 5c 11 27 7d 24 | 02 ab f4 da 16 c9 31 72 4d 5d 57 74 c5 9e bb da | c6 da a3 d5 f4 d9 a3 9d 9e d7 db 82 cf 27 92 62 | b7 4d e1 7b b1 fa db c4 6b 09 de b6 99 26 51 f4 | d1 27 d0 ea 76 c1 f6 aa 6b 23 8a 03 4a ee a7 c5 | bf 5d a4 2e 4f a9 f4 e1 b9 89 a5 56 | start processing: from 192.1.3.33:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3139416170 (0xbb1fb06a) | length: 412 (0x19c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #1 in AGGR_R2 (find_state_ikev1) | start processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_v1_packet() at ikev1.c:1607) | #1 is idle | #1 idle | received encrypted packet from 192.1.3.33:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 24 (0x18) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 260 (0x104) | removing 8 bytes of padding | quick_inI1_outR1 HASH(1): | f1 92 f8 36 16 81 ec d3 c8 21 9a 5d 51 8b 5e 3e | 08 80 07 38 | received 'quick_inI1_outR1' message HASH(1) data ok "north-east"[1] 192.1.3.33 #1: the peer proposed: 192.1.2.23/32:0/0 -> 192.1.3.33/32:0/0 | find_client_connection starting with north-east | looking for 192.1.2.23/32:0/0 -> 192.1.3.33/32:0/0 | concrete checking against sr#0 192.1.2.23/32 -> 192.1.3.33/32 | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org | results matched | fc_try trying north-east:192.1.2.23/32:0/0 -> 192.1.3.33/32:0/0 vs north-east:192.1.2.23/32:0/0 -> 192.1.3.33/32:0/0 | fc_try concluding with north-east [129] | fc_try north-east gives north-east | concluding with d = north-east | client wildcard: no port wildcard: no virtual: no | creating state object #2 at 0x55613f124938 | State DB: adding IKEv1 state #2 in UNDEFINED | pstats #2 ikev1.ipsec started | duplicating state object #1 "north-east"[1] 192.1.3.33 as #2 for IPSEC SA | #2 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1484) | suspend processing: state #1 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | start processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in quick_inI1_outR1_tail() at ikev1_quick.c:1295) | child state #2: UNDEFINED(ignore) => QUICK_R0(established CHILD SA) | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI c0 b4 db 0c | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified; matches alg_info entry | adding quick_outI1 KE work-order 3 for state #2 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f2200002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x55613f1220d8 size 128 | libevent_realloc: release ptr-libevent@0x55613f0b0218 | libevent_realloc: new ptr-libevent@0x55613f118c78 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #2 and saving MD | crypto helper 4 resuming | crypto helper 4 starting work-order 3 for state #2 | crypto helper 4 doing build KE and nonce (quick_outI1 KE); request ID 3 | #2 is busy; has a suspended MD | #1 spent 0.204 milliseconds in process_packet_tail() | stop processing: from 192.1.3.33:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.401 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 4 finished build KE and nonce (quick_outI1 KE); request ID 3 time elapsed 0.000984 seconds | (#2) spent 0.973 milliseconds in crypto helper computing work-order 3: quick_outI1 KE (pcr) | crypto helper 4 sending results from work-order 3 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f21fc003f28 size 128 | crypto helper 4 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:797) | crypto helper 4 replies to request ID 3 | calling continuation function 0x55613d288b50 | quick_inI1_outR1_cryptocontinue1 for #2: calculated ke+nonce, calculating DH | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org) to type PKK_PSK | 1: compared key @east to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org -> 000 | 2: compared key @road to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org -> 000 | line 1: match=000 | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outR1 DH work-order 4 for state #2 | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x55613f1220d8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f2200002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f2200002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x55613f1220d8 size 128 | suspending state #2 and saving MD | #2 is busy; has a suspended MD | resume sending helper answer for #2 suppresed complete_v1_state_transition() and stole MD | crypto helper 5 resuming | crypto helper 5 starting work-order 4 for state #2 | crypto helper 5 doing compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 4 | crypto helper 5 finished compute dh (V1 Phase 2 PFS) (quick outR1 DH); request ID 4 time elapsed 0.000844 seconds | (#2) spent 0.851 milliseconds in crypto helper computing work-order 4: quick outR1 DH (pcr) | crypto helper 5 sending results from work-order 4 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f21f0003618 size 128 | crypto helper 5 waiting (nothing to do) | #2 spent 0.0927 milliseconds in resume sending helper answer | stop processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f21fc003f28 | processing resume sending helper answer for #2 | start processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:797) | crypto helper 5 replies to request ID 4 | calling continuation function 0x55613d288b50 | quick_inI1_outR1_cryptocontinue2 for #2: calculated DH, sending R1 | **emit ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3139416170 (0xbb1fb06a) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 20 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 24 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI c0 b4 db 0c | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified; matches alg_info entry | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0x3bd1c5cd for esp.0@192.1.2.23 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI 3b d1 c5 cd | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | emitting 24 raw bytes of attributes into ISAKMP Transform Payload (ESP) | attributes 80 03 00 0e 80 04 00 01 80 01 00 01 80 02 70 80 | attributes 80 05 00 02 80 06 00 80 | emitting length of ISAKMP Transform Payload (ESP): 32 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 "north-east"[1] 192.1.3.33 #2: responding to Quick Mode proposal {msgid:bb1fb06a} "north-east"[1] 192.1.3.33 #2: us: 192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org] "north-east"[1] 192.1.3.33 #2: them: 192.1.3.33[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org] | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 4e 7f e5 aa 72 21 11 8a 7d 25 75 8e 77 1a 12 60 | Nr d2 3a 4d c7 a5 4f 2f fc 9f 5d 72 f4 46 42 4e 2d | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value fb dd a6 6a 0c e4 04 47 f6 ed e0 e6 4d ae c5 aa | keyex value 41 d2 f3 bd 52 69 99 40 02 d9 5e 56 f4 16 9e 7f | keyex value ea 79 2c c1 b6 10 19 93 11 cb 58 91 cf f5 4a 61 | keyex value 2e 39 a7 94 58 8c b7 3b f7 cd ed 28 8a 9b db fa | keyex value 7e 37 6b e1 d7 ac 73 77 6c d9 50 d9 8b c6 91 e3 | keyex value cb 4c 59 f1 01 f4 85 07 5a f4 0b c5 0c 12 1a 2b | keyex value f8 50 64 2d 3a 2a 69 7b c8 9d 35 0a 42 db 54 c7 | keyex value 04 c3 be 49 61 64 8e bc 7d 3a dd 36 3d 59 19 57 | keyex value 7b eb b9 89 75 c5 96 2f 7b 16 fc 3d ee 1f ad f8 | keyex value 8d 72 99 35 37 6b 7c 9c 85 f9 75 be 45 ba 52 c5 | keyex value 73 1e 55 fa b2 af 77 0c de c8 23 a6 37 25 7b 8e | keyex value c5 33 d3 03 f8 b5 4f e8 fc 02 62 bb 1a 02 16 6f | keyex value 74 0c 9c 68 6f 87 c0 21 e5 a6 f8 7c 6a 88 14 d4 | keyex value b2 2c c9 9a c0 d8 64 ab f1 85 b7 02 a3 c9 ca 36 | keyex value 73 8b c8 34 f2 e3 6a 17 79 e2 f0 63 b6 9d 60 cc | keyex value d9 ac 90 e6 8a 4b e7 6e 4a 9a e5 27 41 ac c3 09 | emitting length of ISAKMP Key Exchange Payload: 260 | quick inR1 outI2 HASH(2): | 2d 56 80 f1 f9 2b 31 bc 46 0d 0f e0 9b c9 24 7c | 53 59 c3 c5 | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | install_inbound_ipsec_sa() checking if we can route | could_route called for north-east (kind=CK_INSTANCE) | FOR_EACH_CONNECTION_... in route_owner | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | route owner of "north-east"[1] 192.1.3.33 unrouted: NULL; eroute owner: NULL | routing is easy, or has resolvable near-conflict | checking if this is a replacement state | st=0x55613f124938 ost=(nil) st->serialno=#2 ost->serialno=#0 | installing outgoing SA now as refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'north-east' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.c0b4db0c@192.1.3.33 included non-error error | outgoing SA has refhim=0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'north-east' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.3bd1c5cd@192.1.2.23 included non-error error | priority calculation of connection "north-east" is 0xfdfdf | add inbound eroute 192.1.3.33/32:0 --0-> 192.1.2.23/32:0 => tun.10000@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | emitting 8 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 412 | finished processing quick inI1 | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R0 to state STATE_QUICK_R1 | child state #2: QUICK_R0(established CHILD SA) => QUICK_R1(established CHILD SA) | event_already_set, deleting event | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x55613f1220d8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f2200002b78 | sending reply packet to 192.1.3.33:500 (from 192.1.2.23:500) | sending 412 bytes for STATE_QUICK_R0 through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #2) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 08 10 20 01 bb 1f b0 6a 00 00 01 9c 7c 4d 5f 91 | ce 09 3e 76 d4 aa 10 54 67 da 6a 6f a9 b4 d5 ea | 37 37 24 e2 fe 3c 5d 14 ed 32 f0 63 48 60 20 00 | 2a f0 5e a1 5e 4f 80 15 de 5e 48 69 c1 1d 16 c3 | 4c 26 93 53 2b a4 b4 2b 13 8f 5d cc 1a c1 46 a7 | 06 b5 53 85 f4 15 e4 95 0c 25 c2 94 4d 3d 2c 55 | 47 44 ee 00 8a d4 7e 26 a5 43 f3 49 56 41 4c 49 | d2 65 8e 26 1d 29 54 55 c3 76 2c fa 96 f9 94 b0 | 64 9f c7 b5 7c f0 f8 4d da 8e f2 03 27 21 93 af | a7 41 df 10 44 c7 b4 86 dd 9f 08 54 a3 89 ce 6c | eb e6 27 ff 26 e5 23 a3 76 28 c5 28 cd 94 73 ee | 6d 25 dc bb 4d 3e 67 21 59 36 64 88 08 4d 69 25 | 70 ab 4c 25 22 e2 11 92 18 27 20 c3 0a db 9a 8d | 9f 7c e2 75 54 f4 c4 1a b3 b6 c0 d9 0a c2 4d 56 | 43 80 db ee 71 68 40 0c 0f 6a e9 7b c2 9d 1f 49 | 6d 80 b6 0b ee db 58 8c 51 8b 4f 58 96 c9 1f 03 | 0c f0 6a 3f b9 c0 23 41 c0 12 69 32 3b 3b 20 10 | 95 8b 88 7d 0b 75 91 8a 13 81 73 11 d1 00 13 89 | b4 a8 12 1e c6 68 b6 0b 20 50 4d 03 86 ad dc 56 | d8 5e 98 40 ed 55 7a 35 4f 73 ac d3 5a d5 69 55 | ba ff a8 03 d0 6c 93 2e 5e 11 ae a1 7a 7a 7f f0 | 98 c5 2c 12 ac 8d 68 41 b5 f7 9a 51 2d 7f 1f 63 | 30 56 23 cd e4 73 f8 80 a1 c3 24 6e 3b ad bb 7f | f3 a0 dd 56 28 3f 1c c2 4c 36 83 67 46 9e 1e f3 | d1 f8 ae 43 a3 ef 80 99 ca fe a7 5d | !event_already_set at reschedule | event_schedule: new EVENT_RETRANSMIT-pe@0x7f2200002b78 | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #2 | libevent_malloc: new ptr-libevent@0x55613f13a538 size 128 | #2 STATE_QUICK_R1: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 29863.327798 | pstats #2 ikev1.ipsec established | NAT-T: encaps is 'auto' "north-east"[1] 192.1.3.33 #2: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2 tunnel mode {ESP=>0xc0b4db0c <0x3bd1c5cd xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 0.842 milliseconds in resume sending helper answer | stop processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f21f0003618 | spent 0.00311 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 60 bytes from 192.1.3.33:500 on eth1 (192.1.2.23:500) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 08 10 20 01 bb 1f b0 6a 00 00 00 3c ac e6 97 7d | 4d 91 95 f8 16 56 45 b9 9f 3e aa 8c d5 0d 10 61 | d9 80 39 49 ac 6d 81 4c 7d e2 4a a5 | start processing: from 192.1.3.33:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3139416170 (0xbb1fb06a) | length: 60 (0x3c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #2 in QUICK_R1 (find_state_ikev1) | start processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_v1_packet() at ikev1.c:1633) | #2 is idle | #2 idle | received encrypted packet from 192.1.3.33:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 24 (0x18) | removing 8 bytes of padding | quick_inI2 HASH(3): | 27 15 de af 93 06 41 d6 d8 22 27 58 b3 0e 0c 67 | a2 36 e5 df | received 'quick_inI2' message HASH(3) data ok | install_ipsec_sa() for #2: outbound only | could_route called for north-east (kind=CK_INSTANCE) | FOR_EACH_CONNECTION_... in route_owner | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | route owner of "north-east"[1] 192.1.3.33 unrouted: NULL; eroute owner: NULL | sr for #2: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | route owner of "north-east"[1] 192.1.3.33 unrouted: NULL; eroute owner: NULL | route_and_eroute with c: north-east (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #2 | priority calculation of connection "north-east" is 0xfdfdf | eroute_connection add eroute 192.1.2.23/32:0 --0-> 192.1.3.33/32:0 => tun.0@192.1.3.33 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-host | executing up-host: PLUTO_VERB='up-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.2.23/32' PLUTO_MY_CLIENT_NET='192.1.2.23' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_PEER_CLIENT='192.1.3.33/32' PLUTO_PEER_CLIENT_NET='192.1.3.33' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_INSTANCE' PLUTO_CONN_ADD | popen cmd is 1289 chars long | cmd( 0):PLUTO_VERB='up-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libre: | cmd( 240):swan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.2.23/32' PLU: | cmd( 320):TO_MY_CLIENT_NET='192.1.2.23' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PO: | cmd( 400):RT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PE: | cmd( 480):ER='192.1.3.33' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test: | cmd( 560): Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.1.3.33/32' PLUTO_PEER_CLIENT_NET='192.1.3.33' PLUTO_PEER: | cmd( 720):_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO: | cmd( 800):_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENC: | cmd( 880):RYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_: | cmd( 960):CONN_KIND='CK_INSTANCE' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEE: | cmd(1040):R_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER=': | cmd(1120):' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='': | cmd(1200): VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xc0b4db0c SPI_OUT=0x3bd1c5cd ipsec _up: | cmd(1280):down 2>&1: | route_and_eroute: firewall_notified: true | running updown command "ipsec _updown" for verb prepare | command executing prepare-host | executing prepare-host: PLUTO_VERB='prepare-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.2.23/32' PLUTO_MY_CLIENT_NET='192.1.2.23' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_PEER_CLIENT='192.1.3.33/32' PLUTO_PEER_CLIENT_NET='192.1.3.33' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_INSTANCE' PLUT | popen cmd is 1294 chars long | cmd( 0):PLUTO_VERB='prepare-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.: | cmd( 240):libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.2.23/32: | cmd( 320):' PLUTO_MY_CLIENT_NET='192.1.2.23' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_: | cmd( 400):MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLU: | cmd( 480):TO_PEER='192.1.3.33' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU: | cmd( 560):=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan: | cmd( 640):.org' PLUTO_PEER_CLIENT='192.1.3.33/32' PLUTO_PEER_CLIENT_NET='192.1.3.33' PLUTO: | cmd( 720):_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' : | cmd( 800):PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASI: | cmd( 880):G+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' P: | cmd( 960):LUTO_CONN_KIND='CK_INSTANCE' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_I: | cmd(1040):S_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BAN: | cmd(1120):NER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFA: | cmd(1200):CE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xc0b4db0c SPI_OUT=0x3bd1c5cd ipse: | cmd(1280):c _updown 2>&1: | running updown command "ipsec _updown" for verb route | command executing route-host | executing route-host: PLUTO_VERB='route-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.2.23/32' PLUTO_MY_CLIENT_NET='192.1.2.23' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_PEER_CLIENT='192.1.3.33/32' PLUTO_PEER_CLIENT_NET='192.1.3.33' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_INSTANCE' PLUTO_CO | popen cmd is 1292 chars long | cmd( 0):PLUTO_VERB='route-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_: | cmd( 80):INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID=': | cmd( 160):C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.li: | cmd( 240):breswan.org, E=user-east@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.2.23/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.1.2.23' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY: | cmd( 400):_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO: | cmd( 480):_PEER='192.1.3.33' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=T: | cmd( 560):est Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.o: | cmd( 640):rg' PLUTO_PEER_CLIENT='192.1.3.33/32' PLUTO_PEER_CLIENT_NET='192.1.3.33' PLUTO_P: | cmd( 720):EER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PL: | cmd( 800):UTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+: | cmd( 880):ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLU: | cmd( 960):TO_CONN_KIND='CK_INSTANCE' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_: | cmd(1040):PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNE: | cmd(1120):R='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE: | cmd(1200):='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xc0b4db0c SPI_OUT=0x3bd1c5cd ipsec : | cmd(1280):_updown 2>&1: | route_and_eroute: instance "north-east"[1] 192.1.3.33, setting eroute_owner {spd=0x55613f11cc28,sr=0x55613f11cc28} to #2 (was #0) (newest_ipsec_sa=#0) | #1 spent 1.86 milliseconds in install_ipsec_sa() | inI2: instance north-east[1], setting IKEv1 newest_ipsec_sa to #2 (was #0) (spd.eroute=#2) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_R1 to state STATE_QUICK_R2 | child state #2: QUICK_R1(established CHILD SA) => QUICK_R2(established CHILD SA) | event_already_set, deleting event | state #2 requesting EVENT_RETRANSMIT to be deleted | #2 STATE_QUICK_R2: retransmits: cleared | libevent_free: release ptr-libevent@0x55613f13a538 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f2200002b78 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x7f2200002b78 | inserting event EVENT_SA_REPLACE, timeout in 28530 seconds for #2 | libevent_malloc: new ptr-libevent@0x7f21f0003618 size 128 | pstats #2 ikev1.ipsec established | NAT-T: encaps is 'auto' "north-east"[1] 192.1.3.33 #2: STATE_QUICK_R2: IPsec SA established tunnel mode {ESP=>0xc0b4db0c <0x3bd1c5cd xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | #2 spent 1.97 milliseconds in process_packet_tail() | stop processing: from 192.1.3.33:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "north-east"[1] 192.1.3.33 from 192.1.3.33:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 2.12 milliseconds in comm_handle_cb() reading and processing packet | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00547 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00296 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00298 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_STATE_... in show_traffic_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.3bd1c5cd@192.1.2.23 | get_sa_info esp.c0b4db0c@192.1.3.33 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.0983 milliseconds in whack