FIPS Product: YES FIPS Kernel: NO FIPS Mode: NO NSS DB directory: sql:/etc/ipsec.d Initializing NSS Opening NSS database "sql:/etc/ipsec.d" read-only NSS initialized NSS crypto library initialized FIPS HMAC integrity support [enabled] FIPS mode disabled for pluto daemon FIPS HMAC integrity verification self-test FAILED libcap-ng support [enabled] Linux audit support [enabled] Linux audit activated Starting Pluto (Libreswan Version v3.28-685-gbfd5aef521-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:29214 core dump dir: /tmp secrets file: /etc/ipsec.secrets leak-detective enabled NSS crypto [enabled] XAUTH PAM support [enabled] | libevent is using pluto's memory allocator Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) | libevent_malloc: new ptr-libevent@0x560e7407e6f8 size 40 | libevent_malloc: new ptr-libevent@0x560e7407e678 size 40 | libevent_malloc: new ptr-libevent@0x560e7407e5f8 size 40 | creating event base | libevent_malloc: new ptr-libevent@0x560e74070228 size 56 | libevent_malloc: new ptr-libevent@0x560e73ff9dc8 size 664 | libevent_malloc: new ptr-libevent@0x560e740b8d18 size 24 | libevent_malloc: new ptr-libevent@0x560e740b8d68 size 384 | libevent_malloc: new ptr-libevent@0x560e740b8cd8 size 16 | libevent_malloc: new ptr-libevent@0x560e7407e578 size 40 | libevent_malloc: new ptr-libevent@0x560e7407e4f8 size 48 | libevent_realloc: new ptr-libevent@0x560e73ff9a58 size 256 | libevent_malloc: new ptr-libevent@0x560e740b8f18 size 16 | libevent_free: release ptr-libevent@0x560e74070228 | libevent initialized | libevent_realloc: new ptr-libevent@0x560e74070228 size 64 | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds | init_nat_traversal() initialized with keep_alive=0s NAT-Traversal support [enabled] | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized | global one-shot timer EVENT_FREE_ROOT_CERTS initialized | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds | global one-shot timer EVENT_REVIVE_CONNS initialized | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Encryption algorithms: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac NULL IKEv1: ESP IKEv2: ESP [] CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Hash algorithms: MD5 IKEv1: IKE IKEv2: SHA1 IKEv1: IKE IKEv2: FIPS sha SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 PRF algorithms: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Integrity algorithms: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac NONE IKEv1: ESP IKEv2: IKE ESP FIPS null DH algorithms: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 testing CAMELLIA_CBC: Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 256-bit key Camellia: 16 bytes with 256-bit key testing AES_GCM_16: empty string one block two blocks two blocks with associated data testing AES_CTR: Encrypting 16 octets using AES-CTR with 128-bit key Encrypting 32 octets using AES-CTR with 128-bit key Encrypting 36 octets using AES-CTR with 128-bit key Encrypting 16 octets using AES-CTR with 192-bit key Encrypting 32 octets using AES-CTR with 192-bit key Encrypting 36 octets using AES-CTR with 192-bit key Encrypting 16 octets using AES-CTR with 256-bit key Encrypting 32 octets using AES-CTR with 256-bit key Encrypting 36 octets using AES-CTR with 256-bit key testing AES_CBC: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key testing AES_XCBC: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) testing HMAC_MD5: RFC 2104: MD5_HMAC test 1 RFC 2104: MD5_HMAC test 2 RFC 2104: MD5_HMAC test 3 8 CPU cores online starting up 7 crypto helpers started thread for crypto helper 0 | starting up helper thread 0 | status value returned by setting the priority of this thread (crypto helper 0) 22 | crypto helper 0 waiting (nothing to do) started thread for crypto helper 1 | starting up helper thread 1 | status value returned by setting the priority of this thread (crypto helper 1) 22 | crypto helper 1 waiting (nothing to do) started thread for crypto helper 2 | starting up helper thread 2 | status value returned by setting the priority of this thread (crypto helper 2) 22 | crypto helper 2 waiting (nothing to do) started thread for crypto helper 3 | starting up helper thread 3 | status value returned by setting the priority of this thread (crypto helper 3) 22 | crypto helper 3 waiting (nothing to do) started thread for crypto helper 4 | starting up helper thread 4 | status value returned by setting the priority of this thread (crypto helper 4) 22 | crypto helper 4 waiting (nothing to do) started thread for crypto helper 5 | starting up helper thread 5 | status value returned by setting the priority of this thread (crypto helper 5) 22 | crypto helper 5 waiting (nothing to do) started thread for crypto helper 6 | starting up helper thread 6 | status value returned by setting the priority of this thread (crypto helper 6) 22 | checking IKEv1 state table | MAIN_R0: category: half-open IKE SA flags: 0: | -> MAIN_R1 EVENT_SO_DISCARD | MAIN_I1: category: half-open IKE SA flags: 0: | -> MAIN_I2 EVENT_RETRANSMIT | MAIN_R1: category: open IKE SA flags: 200: | -> MAIN_R2 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_I2: category: open IKE SA flags: 0: | -> MAIN_I3 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_R2: category: open IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | -> MAIN_R3 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_I3: category: open IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | -> MAIN_I4 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_R3: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | MAIN_I4: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | AGGR_R0: category: half-open IKE SA flags: 0: | -> AGGR_R1 EVENT_SO_DISCARD | AGGR_I1: category: half-open IKE SA flags: 0: | -> AGGR_I2 EVENT_SA_REPLACE | -> AGGR_I2 EVENT_SA_REPLACE | AGGR_R1: category: open IKE SA flags: 200: | -> AGGR_R2 EVENT_SA_REPLACE | -> AGGR_R2 EVENT_SA_REPLACE | AGGR_I2: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | AGGR_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | QUICK_R0: category: established CHILD SA flags: 0: | -> QUICK_R1 EVENT_RETRANSMIT | QUICK_I1: category: established CHILD SA flags: 0: | -> QUICK_I2 EVENT_SA_REPLACE | QUICK_R1: category: established CHILD SA flags: 0: | -> QUICK_R2 EVENT_SA_REPLACE | QUICK_I2: category: established CHILD SA flags: 200: | -> UNDEFINED EVENT_NULL | QUICK_R2: category: established CHILD SA flags: 0: | -> UNDEFINED EVENT_NULL | INFO: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | INFO_PROTECTED: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | XAUTH_R0: category: established IKE SA flags: 0: | -> XAUTH_R1 EVENT_NULL | XAUTH_R1: category: established IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | MODE_CFG_R0: category: informational flags: 0: | -> MODE_CFG_R1 EVENT_SA_REPLACE | MODE_CFG_R1: category: established IKE SA flags: 0: | -> MODE_CFG_R2 EVENT_SA_REPLACE | MODE_CFG_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | MODE_CFG_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | XAUTH_I0: category: established IKE SA flags: 0: | -> XAUTH_I1 EVENT_RETRANSMIT | XAUTH_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_RETRANSMIT | checking IKEv2 state table | PARENT_I0: category: ignore flags: 0: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) | PARENT_I1: category: half-open IKE SA flags: 0: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) | PARENT_I2: category: open IKE SA flags: 0: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) | PARENT_I3: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) | PARENT_R0: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) | PARENT_R1: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) | PARENT_R2: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) | V2_CREATE_I0: category: established IKE SA flags: 0: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) | V2_CREATE_I: category: established IKE SA flags: 0: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) | V2_REKEY_IKE_I: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: | V2_CREATE_R: category: established IKE SA flags: 0: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) | V2_REKEY_IKE_R: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: | V2_IPSEC_I: category: established CHILD SA flags: 0: | V2_IPSEC_R: category: established CHILD SA flags: 0: | IKESA_DEL: category: established IKE SA flags: 0: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) | CHILDSA_DEL: category: informational flags: 0: Using Linux XFRM/NETKEY IPsec interface code on 5.1.18-200.fc29.x86_64 | Hard-wiring algorithms | adding AES_CCM_16 to kernel algorithm db | adding AES_CCM_12 to kernel algorithm db | adding AES_CCM_8 to kernel algorithm db | adding 3DES_CBC to kernel algorithm db | adding CAMELLIA_CBC to kernel algorithm db | adding AES_GCM_16 to kernel algorithm db | adding AES_GCM_12 to kernel algorithm db | adding AES_GCM_8 to kernel algorithm db | adding AES_CTR to kernel algorithm db | adding AES_CBC to kernel algorithm db | adding SERPENT_CBC to kernel algorithm db | adding TWOFISH_CBC to kernel algorithm db | adding NULL_AUTH_AES_GMAC to kernel algorithm db | adding NULL to kernel algorithm db | adding CHACHA20_POLY1305 to kernel algorithm db | adding HMAC_MD5_96 to kernel algorithm db | adding HMAC_SHA1_96 to kernel algorithm db | adding HMAC_SHA2_512_256 to kernel algorithm db | adding HMAC_SHA2_384_192 to kernel algorithm db | adding HMAC_SHA2_256_128 to kernel algorithm db | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db | adding AES_XCBC_96 to kernel algorithm db | adding AES_CMAC_96 to kernel algorithm db | adding NONE to kernel algorithm db | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds | setup kernel fd callback | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x560e74078418 | libevent_malloc: new ptr-libevent@0x560e740b7488 size 128 | libevent_malloc: new ptr-libevent@0x560e740be518 size 16 | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x560e740be4a8 | libevent_malloc: new ptr-libevent@0x560e74070ed8 size 128 | libevent_malloc: new ptr-libevent@0x560e740be178 size 16 | global one-shot timer EVENT_CHECK_CRLS initialized selinux support is enabled. | unbound context created - setting debug level to 5 | /etc/hosts lookups activated | /etc/resolv.conf usage activated | outgoing-port-avoid set 0-65535 | outgoing-port-permit set 32768-60999 | Loading dnssec root key from:/var/lib/unbound/root.key | No additional dnssec trust anchors defined via dnssec-trusted= option | Setting up events, loop start | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x560e740be948 | libevent_malloc: new ptr-libevent@0x560e740ca828 size 128 | libevent_malloc: new ptr-libevent@0x560e740d5b18 size 16 | libevent_realloc: new ptr-libevent@0x560e740d5b58 size 256 | libevent_malloc: new ptr-libevent@0x560e740d5c88 size 8 | libevent_realloc: new ptr-libevent@0x560e740d5cc8 size 144 | libevent_malloc: new ptr-libevent@0x560e7407c9e8 size 152 | libevent_malloc: new ptr-libevent@0x560e740d5d88 size 16 | signal event handler PLUTO_SIGCHLD installed | libevent_malloc: new ptr-libevent@0x560e740d5dc8 size 8 | libevent_malloc: new ptr-libevent@0x560e73ffa738 size 152 | signal event handler PLUTO_SIGTERM installed | libevent_malloc: new ptr-libevent@0x560e740d5e08 size 8 | libevent_malloc: new ptr-libevent@0x560e740d5e48 size 152 | signal event handler PLUTO_SIGHUP installed | libevent_malloc: new ptr-libevent@0x560e740d5f18 size 8 | libevent_realloc: release ptr-libevent@0x560e740d5cc8 | libevent_realloc: new ptr-libevent@0x560e740d5f58 size 256 | libevent_malloc: new ptr-libevent@0x560e740d6088 size 152 | signal event handler PLUTO_SIGSYS installed | created addconn helper (pid:29412) using fork+execve | forked child 29412 | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.3.254 | Inspecting interface eth1 | found eth1 with address 192.1.3.33 Kernel supports NIC esp-hw-offload adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.3.33:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth1/eth1 192.1.3.33:4500 adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.3.254:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0/eth0 192.0.3.254:4500 adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface lo/lo 127.0.0.1:4500 | no interfaces to sort | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | add_fd_read_event_handler: new ethX-pe@0x560e740d6668 | libevent_malloc: new ptr-libevent@0x560e740ca778 size 128 | libevent_malloc: new ptr-libevent@0x560e740d66d8 size 16 | setup callback for interface lo 127.0.0.1:4500 fd 22 | add_fd_read_event_handler: new ethX-pe@0x560e740d6718 | libevent_malloc: new ptr-libevent@0x560e74070f88 size 128 | libevent_malloc: new ptr-libevent@0x560e740d6788 size 16 | setup callback for interface lo 127.0.0.1:500 fd 21 | add_fd_read_event_handler: new ethX-pe@0x560e740d67c8 | libevent_malloc: new ptr-libevent@0x560e740708a8 size 128 | libevent_malloc: new ptr-libevent@0x560e740d6838 size 16 | setup callback for interface eth0 192.0.3.254:4500 fd 20 | add_fd_read_event_handler: new ethX-pe@0x560e740d6878 | libevent_malloc: new ptr-libevent@0x560e74078168 size 128 | libevent_malloc: new ptr-libevent@0x560e740d68e8 size 16 | setup callback for interface eth0 192.0.3.254:500 fd 19 | add_fd_read_event_handler: new ethX-pe@0x560e740d6928 | libevent_malloc: new ptr-libevent@0x560e74078268 size 128 | libevent_malloc: new ptr-libevent@0x560e740d6998 size 16 | setup callback for interface eth1 192.1.3.33:4500 fd 18 | add_fd_read_event_handler: new ethX-pe@0x560e740d69d8 | libevent_malloc: new ptr-libevent@0x560e74078368 size 128 | libevent_malloc: new ptr-libevent@0x560e740d6a48 size 16 | setup callback for interface eth1 192.1.3.33:500 fd 17 | certs and keys locked by 'free_preshared_secrets' | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | id type added to secret(0x560e73fc6c48) PKK_PSK: @east | id type added to secret(0x560e73fc6c48) PKK_PSK: @road | Processing PSK at line 1: passed | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.869 milliseconds in whack | crypto helper 6 waiting (nothing to do) | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.3.254 | Inspecting interface eth1 | found eth1 with address 192.1.3.33 | no interfaces to sort | libevent_free: release ptr-libevent@0x560e740ca778 | free_event_entry: release EVENT_NULL-pe@0x560e740d6668 | add_fd_read_event_handler: new ethX-pe@0x560e740d6668 | libevent_malloc: new ptr-libevent@0x560e740ca778 size 128 | setup callback for interface lo 127.0.0.1:4500 fd 22 | libevent_free: release ptr-libevent@0x560e74070f88 | free_event_entry: release EVENT_NULL-pe@0x560e740d6718 | add_fd_read_event_handler: new ethX-pe@0x560e740d6718 | libevent_malloc: new ptr-libevent@0x560e74070f88 size 128 | setup callback for interface lo 127.0.0.1:500 fd 21 | libevent_free: release ptr-libevent@0x560e740708a8 | free_event_entry: release EVENT_NULL-pe@0x560e740d67c8 | add_fd_read_event_handler: new ethX-pe@0x560e740d67c8 | libevent_malloc: new ptr-libevent@0x560e740708a8 size 128 | setup callback for interface eth0 192.0.3.254:4500 fd 20 | libevent_free: release ptr-libevent@0x560e74078168 | free_event_entry: release EVENT_NULL-pe@0x560e740d6878 | add_fd_read_event_handler: new ethX-pe@0x560e740d6878 | libevent_malloc: new ptr-libevent@0x560e74078168 size 128 | setup callback for interface eth0 192.0.3.254:500 fd 19 | libevent_free: release ptr-libevent@0x560e74078268 | free_event_entry: release EVENT_NULL-pe@0x560e740d6928 | add_fd_read_event_handler: new ethX-pe@0x560e740d6928 | libevent_malloc: new ptr-libevent@0x560e74078268 size 128 | setup callback for interface eth1 192.1.3.33:4500 fd 18 | libevent_free: release ptr-libevent@0x560e74078368 | free_event_entry: release EVENT_NULL-pe@0x560e740d69d8 | add_fd_read_event_handler: new ethX-pe@0x560e740d69d8 | libevent_malloc: new ptr-libevent@0x560e74078368 size 128 | setup callback for interface eth1 192.1.3.33:500 fd 17 | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | id type added to secret(0x560e73fc6c48) PKK_PSK: @east | id type added to secret(0x560e73fc6c48) PKK_PSK: @road | Processing PSK at line 1: passed | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.278 milliseconds in whack | processing signal PLUTO_SIGCHLD | waitpid returned pid 29412 (exited with status 0) | reaped addconn helper child (status 0) | waitpid returned ECHILD (no child processes left) | spent 0.0126 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection north-east with policy RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | ike (phase1) algorithm values: AES_CBC_128-HMAC_SHA1-MODP2048 | from whack: got --esp=aes128-sha1 | ESP/AH string values: AES_CBC_128-HMAC_SHA1_96 | setting ID to ID_DER_ASN1_DN: 'E=user-north@testing.libreswan.org,CN=north.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading left certificate 'north' pubkey | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dbc58 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dbc08 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dbac8 | unreference key: 0x560e740dbca8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org cnt 1-- | certs and keys locked by 'lsw_add_rsa_secret' | certs and keys unlocked by 'lsw_add_rsa_secret' | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org is 0 | setting ID to ID_DER_ASN1_DN: 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading right certificate 'east' pubkey | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dbc08 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dd1c8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dd138 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740dc068 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740d8d38 | unreference key: 0x560e740e1e18 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | warning: no secret key loaded for right certificate with nickname east: NSS: cert private key not found | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | connect_to_host_pair: 192.1.3.33:500 192.1.2.23:500 -> hp@(nil): none | new hp@0x560e740e1568 added connection description "north-east" | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.1.3.33[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org]---192.1.3.254...192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org] | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 2.47 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | old debugging base+cpu-usage + none | base debugging = base+cpu-usage | old impairing none + suppress-retransmits | base impairing = suppress-retransmits | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.0518 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | dup_any(fd@16) -> fd@23 (in whack_process() at rcv_whack.c:590) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "north-east" (in initiate_a_connection() at initiate.c:186) | kernel_alg_db_new() initial trans_cnt=135 | adding proposal: AES_CBC_128-HMAC_SHA1_96 | kernel_alg_db_new() will return p_new->protoid=3, p_new->trans_cnt=1 | kernel_alg_db_new() trans[0]: transid=12, attr_cnt=2, attrs[0].type=5, attrs[0].val=2 | returning new proposal from esp_info | connection 'north-east' +POLICY_UP | dup_any(fd@23) -> fd@24 (in initiate_a_connection() at initiate.c:342) | FOR_EACH_STATE_... in find_phase1_state | creating state object #1 at 0x560e740e3d88 | State DB: adding IKEv1 state #1 in UNDEFINED | pstats #1 ikev1.isakmp started | parent state #1: UNDEFINED(ignore) => AGGR_I1(half-open IKE SA) | suspend processing: connection "north-east" (in aggr_outI1() at ikev1_aggr.c:1015) | start processing: state #1 connection "north-east" from 192.1.2.23 (in aggr_outI1() at ikev1_aggr.c:1015) | oakley_alg_makedb() processing ealg=aes=7 halg=sha=2 modp=MODP2048=14 eklen=128 | oakley_alg_makedb() returning 0x560e740e1308 | initiating aggressive mode with IKE=E=7-H=2-M=14 | dup_any(fd@24) -> fd@25 (in aggr_outI1() at ikev1_aggr.c:1031) | Queuing pending IPsec SA negotiating with 192.1.2.23 "north-east" IKE SA #1 "north-east" "north-east" #1: initiating Aggressive Mode | adding aggr_outI1 KE + nonce work-order 1 for state #1 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x560e740dfde8 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x560e740e1d68 size 128 | #1 spent 0.13 milliseconds in aggr_outI1() | processing: RESET whack log_fd (was fd@16) (in aggr_outI1() at ikev1_aggr.c:1054) | crypto helper 0 resuming | crypto helper 0 starting work-order 1 for state #1 | crypto helper 0 doing build KE and nonce (aggr_outI1 KE + nonce); request ID 1 | crypto helper 0 finished build KE and nonce (aggr_outI1 KE + nonce); request ID 1 time elapsed 0.000987 seconds | (#1) spent 0.979 milliseconds in crypto helper computing work-order 1: aggr_outI1 KE + nonce (pcr) | crypto helper 0 sending results from work-order 1 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f852c002888 size 128 | crypto helper 0 waiting (nothing to do) | RESET processing: state #1 connection "north-east" from 192.1.2.23 (in aggr_outI1() at ikev1_aggr.c:1054) | RESET processing: connection "north-east" (in aggr_outI1() at ikev1_aggr.c:1054) | processing: STOP connection NULL (in initiate_a_connection() at initiate.c:349) | close_any(fd@23) (in initiate_connection() at initiate.c:372) | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.201 milliseconds in whack | processing resume sending helper answer for #1 | start processing: state #1 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 0 replies to request ID 1 | calling continuation function 0x560e7390db50 | aggr_outI1_continue for #1: calculated ke+nonce, sending I1 | aggr_outI1_tail for #1 | **emit ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_AGGR (0x4) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | oakley_alg_makedb() processing ealg=aes=7 halg=sha=2 modp=MODP2048=14 eklen=128 | oakley_alg_makedb() returning 0x560e740e2bb8 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 1 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 4f 24 95 88 b7 8e aa 07 01 da 13 14 55 c3 0b fd | keyex value 9e 59 38 1b de 17 9e dd ce c4 87 99 cc fc fd 07 | keyex value 50 f8 4a f7 3a 85 7e 46 5e a2 70 e9 46 28 4b ed | keyex value a9 92 a1 54 a7 a2 ec b1 74 2a 4d f0 ca 4c 24 39 | keyex value 51 69 a1 0c 08 e8 eb a7 92 9e ca af fb 72 8f bd | keyex value 40 a9 2f a3 47 75 14 d6 9c 34 82 c9 c9 bf 74 5d | keyex value d2 5b b2 4e a3 02 a3 41 00 00 6b d7 5f dd 2e c3 | keyex value d4 ee 43 8e be 01 58 02 a9 65 6a 51 53 3f b4 2e | keyex value 2d 0f 44 9d ef 69 8f 22 08 35 37 73 28 92 ff 3f | keyex value bb f5 44 06 48 4a 5a a0 de ec 31 9c e4 b9 00 2c | keyex value 7f d0 36 9d d8 0a d9 1d 1f 94 08 fc 7c 8b 24 31 | keyex value d1 ad e2 00 49 a1 42 f6 ca 2b e5 30 f4 d8 cb 44 | keyex value 38 b0 37 b1 a7 60 a6 f3 b3 29 41 d2 4b c7 e0 db | keyex value 5a 5c 4f aa ea c9 54 7a 58 1d 8d f8 42 14 22 a9 | keyex value 5f 50 8f 91 2a d9 49 01 2c 5c 00 2d f6 c9 75 52 | keyex value b3 35 67 e8 33 c9 9c 4a a2 c8 ac 2a a6 91 56 39 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni a7 58 a1 6e d1 cb 09 aa c2 26 f8 60 0b 25 88 12 | Ni b5 a8 8e 8e 87 73 7e 84 06 2d e7 5a f5 2a de a3 | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_CR (0x7) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 7:ISAKMP_NEXT_CR | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 185 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e 6f 72 | my identity 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 | my identity 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 2a 86 | my identity 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d 6e 6f | my identity 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | my identity 65 73 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 193 "north-east" #1: I am sending a certificate request | ***emit ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_VID (0xd) | cert type: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate RequestPayload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Certificate RequestPayload (7:ISAKMP_NEXT_CR) | next payload chain: saving location 'ISAKMP Certificate RequestPayload'.'next payload type' in 'reply packet' | emitting 175 raw bytes of CA into ISAKMP Certificate RequestPayload | CA 30 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 | CA 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | CA 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | CA 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | CA 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | CA 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | CA 6e 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 | CA 72 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 | CA 6f 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a | CA 86 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e | CA 67 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Certificate RequestPayload: 180 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Certificate RequestPayload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | nat add vid | sending draft and RFC NATT VIDs | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | skipping VID_NATT_RFC | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-03] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-02_n] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 90 cb 80 91 3e bb 69 6e 08 63 81 b5 ec 42 7b 1f | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-02] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID cd 60 46 43 35 df 21 f8 7c fd b2 fc 68 b6 a4 48 | emitting length of ISAKMP Vendor ID Payload: 20 | padding IKEv1 message with 3 bytes | emitting 3 zero bytes of message padding into ISAKMP Message | emitting length of ISAKMP Message: 876 | sending 876 bytes for aggr_outI1 through eth1 from 192.1.3.33:500 to 192.1.2.23:500 (using #1) | 16 38 87 b3 8a 6a b1 69 00 00 00 00 00 00 00 00 | 01 10 04 00 00 00 00 00 00 00 03 6c 04 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 00 80 0a 00 01 04 4f 24 95 88 b7 8e aa 07 | 01 da 13 14 55 c3 0b fd 9e 59 38 1b de 17 9e dd | ce c4 87 99 cc fc fd 07 50 f8 4a f7 3a 85 7e 46 | 5e a2 70 e9 46 28 4b ed a9 92 a1 54 a7 a2 ec b1 | 74 2a 4d f0 ca 4c 24 39 51 69 a1 0c 08 e8 eb a7 | 92 9e ca af fb 72 8f bd 40 a9 2f a3 47 75 14 d6 | 9c 34 82 c9 c9 bf 74 5d d2 5b b2 4e a3 02 a3 41 | 00 00 6b d7 5f dd 2e c3 d4 ee 43 8e be 01 58 02 | a9 65 6a 51 53 3f b4 2e 2d 0f 44 9d ef 69 8f 22 | 08 35 37 73 28 92 ff 3f bb f5 44 06 48 4a 5a a0 | de ec 31 9c e4 b9 00 2c 7f d0 36 9d d8 0a d9 1d | 1f 94 08 fc 7c 8b 24 31 d1 ad e2 00 49 a1 42 f6 | ca 2b e5 30 f4 d8 cb 44 38 b0 37 b1 a7 60 a6 f3 | b3 29 41 d2 4b c7 e0 db 5a 5c 4f aa ea c9 54 7a | 58 1d 8d f8 42 14 22 a9 5f 50 8f 91 2a d9 49 01 | 2c 5c 00 2d f6 c9 75 52 b3 35 67 e8 33 c9 9c 4a | a2 c8 ac 2a a6 91 56 39 05 00 00 24 a7 58 a1 6e | d1 cb 09 aa c2 26 f8 60 0b 25 88 12 b5 a8 8e 8e | 87 73 7e 84 06 2d e7 5a f5 2a de a3 07 00 00 c1 | 09 00 00 00 30 81 b6 31 0b 30 09 06 03 55 04 06 | 13 02 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f | 6e 74 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c | 07 54 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 | 0a 0c 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 | 06 03 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 | 72 74 6d 65 6e 74 31 24 30 22 06 03 55 04 03 0c | 1b 6e 6f 72 74 68 2e 74 65 73 74 69 6e 67 2e 6c | 69 62 72 65 73 77 61 6e 2e 6f 72 67 31 2f 30 2d | 06 09 2a 86 48 86 f7 0d 01 09 01 16 20 75 73 65 | 72 2d 6e 6f 72 74 68 40 74 65 73 74 69 6e 67 2e | 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 0d 00 00 | b4 04 30 81 ac 31 0b 30 09 06 03 55 04 06 13 02 | 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | 6d 65 6e 74 31 25 30 23 06 03 55 04 03 0c 1c 4c | 69 62 72 65 73 77 61 6e 20 74 65 73 74 20 43 41 | 20 66 6f 72 20 6d 61 69 6e 63 61 31 24 30 22 06 | 09 2a 86 48 86 f7 0d 01 09 01 16 15 74 65 73 74 | 69 6e 67 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 | 67 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de | 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 | c9 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c | 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 | 14 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d | 56 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 | b5 ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 | f8 7c fd b2 fc 68 b6 a4 48 00 00 00 | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x560e740e1d68 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x560e740dfde8 "north-east" #1: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x560e740dfde8 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x560e740e1d68 size 128 | #1 STATE_AGGR_I1: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 29863.268033 | stop processing: state #1 connection "north-east" from 192.1.2.23 (in aggr_outI1_tail() at ikev1_aggr.c:1199) | complete v1 state transition with STF_IGNORE | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 0.573 milliseconds in resume sending helper answer | processing: STOP state #0 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f852c002888 | spent 0.00304 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 2340 bytes from 192.1.2.23:500 on eth1 (192.1.3.33:500) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 01 10 04 00 00 00 00 00 00 00 09 24 04 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 0e 10 | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 00 80 0a 00 01 04 15 d2 6c d0 82 65 65 5e | cb de 6e 1e 9b 12 27 1d 7b 42 70 eb 5e a2 0d de | 08 fd 33 92 dc 83 f7 ea c5 42 41 84 85 0c 95 58 | 8d 0b 8c 9e 8a 9c 79 25 b6 9a 93 76 cc 47 3c 40 | c3 89 40 de 9c 59 a0 18 ef 5e 25 cf e9 b6 61 8c | be 0f 87 91 29 a0 87 8a c7 69 5d 76 7e 89 4b 39 | c8 4a b2 a7 52 bf f5 b7 b7 3c 9e 1a 00 8a 6a 21 | 3f 9b 6e 63 56 c5 8e f4 98 98 23 20 e1 4f a1 df | da b5 9b 60 ac f0 c3 14 c3 86 f3 76 c3 75 3d e2 | 00 2a b2 d2 82 e1 e2 ad e8 ed 29 21 6e 26 48 c3 | 39 22 b4 df ad 27 72 b0 16 d0 d6 ed ac 4c b8 6b | 39 0b 1a db 67 79 51 90 ef 6d 7c 4d 82 d1 73 5e | 28 34 0e 23 6b 2b 43 39 a6 07 16 6c ea f4 b4 e7 | 76 f7 e3 21 9c 23 20 03 33 1e 3f 8c 7a f3 5f 4f | af c6 9a c2 c4 eb 63 43 cb 89 e6 0b 1f f5 39 27 | 85 7d b2 e8 be 58 56 b4 3b 33 08 03 77 e8 15 c8 | b5 a5 f8 b3 99 5c 1b 23 05 00 00 24 4f 8e b6 ed | 3c e1 4b 6a d1 5d 61 a0 0e a1 97 1a 6d 63 09 1a | e1 74 aa cf 73 f8 32 23 2c be 4d d9 06 00 00 bf | 09 00 00 00 30 81 b4 31 0b 30 09 06 03 55 04 06 | 13 02 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f | 6e 74 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c | 07 54 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 | 0a 0c 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 | 06 03 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 | 72 74 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c | 1a 65 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 | 62 72 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 | 09 2a 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 | 2d 65 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 | 62 72 65 73 77 61 6e 2e 6f 72 67 07 00 04 f1 04 | 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 03 | 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 | 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 | 61 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | 00 30 82 01 8a 02 82 01 81 00 b1 1e 7c b3 bf 11 | 96 94 23 ca 97 5e c7 66 36 55 71 49 95 8d 0c 2a | 5c 30 4d 58 29 a3 7b 4d 3b 3f 03 06 46 a6 04 63 | 71 0d e1 59 4f 9c ec 3a 17 24 8d 91 6a a8 e2 da | 57 41 de f4 ff 65 bf f6 11 34 d3 7d 5a 7f 6e 3a | 3b 74 3c 51 2b e4 bf ce 6b b2 14 47 26 52 f5 57 | 28 bc c5 fb f9 bc 2d 4e b9 f8 46 54 c7 95 41 a7 | a4 b4 d3 b3 fe 55 4b df f5 c3 78 39 8b 4e 04 57 | c0 1d 5b 17 3c 28 eb 40 9d 1d 7c b3 bb 0f f0 63 | c7 c0 84 b0 4e e4 a9 7c c5 4b 08 43 a6 2d 00 22 | fd 98 d4 03 d0 ad 97 85 d1 48 15 d3 e4 e5 2d 46 | 7c ab 41 97 05 27 61 77 3d b6 b1 58 a0 5f e0 8d | 26 84 9b 03 20 ce 5e 27 7f 7d 14 03 b6 9d 6b 9f | fd 0c d4 c7 2d eb be ea 62 87 fa 99 e0 a6 1c 85 | 4f 34 da 93 2e 5f db 03 10 58 a8 c4 99 17 2d b1 | bc e5 7b bd af 0e 28 aa a5 74 ea 69 74 5e fa 2c | c3 00 3c 2f 58 d0 20 cf e3 46 8d de aa f9 f7 30 | 5c 16 05 04 89 4c 92 9b 8a 33 11 70 83 17 58 24 | 2a 4b ab be b6 ec 84 9c 78 9c 11 04 2a 02 ce 27 | 83 a1 1f 2b 38 3f 27 7d 46 94 63 ff 64 59 4e 6c | 87 ca 3e e6 31 df 1e 7d 48 88 02 c7 9d fa 4a d7 | f2 5b a5 fd 7f 1b c6 dc 1a bb a6 c4 f8 32 cd bf | a7 0b 71 8b 2b 31 41 17 25 a4 18 52 7d 32 fc 0f | 5f b8 bb ca e1 94 1a 42 4d 1f 37 16 67 84 ae b4 | 32 42 9c 5a 91 71 62 b4 4b 07 02 03 01 00 01 a3 | 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 65 | 61 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | 65 73 77 61 6e 2e 6f 72 67 81 1a 65 61 73 74 40 | 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | 6e 2e 6f 72 67 87 04 c0 01 02 17 30 0b 06 03 55 | 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | 86 f7 0d 01 01 0b 05 00 03 81 81 00 3a 56 a3 7d | b1 4e 62 2f 82 0d e3 fe 74 40 ef cb eb 93 ea ad | e4 74 8b 80 6f ae 8b 65 87 12 a6 24 0d 21 9c 5f | 70 5c 6f d9 66 8d 98 8b ea 59 f8 96 52 6a 6c 86 | d6 7d ba 37 a9 8c 33 8c 77 18 23 0b 1b 2a 66 47 | e7 95 94 e6 75 84 30 d4 db b8 23 eb 89 82 a9 fd | ed 46 8b ce 46 7f f9 19 8f 49 da 29 2e 1e 97 cd | 12 42 86 c7 57 fc 4f 0a 19 26 8a a1 0d 26 81 4d | 53 f4 5c 92 a1 03 03 8d 6c 51 33 cc 09 00 00 05 | 04 0d 00 01 84 20 a8 7a 55 75 1d 05 7e 1b 6c cb | d5 a7 c0 3a d1 83 5f 6a 62 7c 4f 6d 45 83 51 da | 6b 5f f6 56 ed 28 ee 2b 7d ac 5f 96 f3 4c 45 ea | 06 bf a3 af e6 7c 21 a1 53 8a 4c fd 98 3c 85 20 | c6 3d 3f 7f c2 fb 58 06 d3 56 26 6c 6f af eb 0c | 2d 52 b1 9c 66 cc 2b c6 fc c1 7b 4f a3 9c 6c 14 | 31 14 bc 2b d8 89 cc 29 3c e5 56 a1 a1 11 38 d0 | fd 6d 4a 8c 0c 82 02 79 f3 b0 c0 1c cb 44 1d a6 | 16 9b cc 83 57 9b 8b 68 74 86 13 db e6 f9 73 2e | 2c 73 b2 f2 0d 01 6d dd 63 83 21 65 30 18 e2 94 | 06 e1 57 65 cf bc 5c bf 91 71 37 20 06 6d 24 7f | e4 2e 1d 32 b5 ef e8 72 ea b7 f8 a3 91 81 dd 94 | e1 46 bc 45 45 af 1f c6 c2 88 f4 29 3c 78 ee ec | 6e a0 6a 67 1d aa 11 27 72 11 79 de f6 ab 33 26 | 1f 4c 19 dd a1 12 7d 67 bb dc af b8 3a 06 c7 7a | c4 c8 0b 49 a8 e6 b0 a0 da b1 15 1a 2b 57 ea cc | 16 83 e0 35 fb a0 bc 59 5a 50 83 3b 5d 9c b7 6e | aa 07 1d 5f a5 c4 fb 27 48 6a c9 52 44 04 4f 3d | cd c1 8f 95 dd 31 9a ad f3 1a a1 ed 44 1a 0c 35 | 6c 76 1f 05 4f 6a bf 84 d1 37 94 94 45 91 6d cc | 72 1b 52 ce 6e 19 97 37 21 a0 9e 55 fb 5e 3a d9 | 17 2f 70 58 d7 4d 0a 12 fc 05 23 6f 1c 5a b7 15 | 46 6a 92 e1 29 e2 27 91 c4 08 ab 3d a1 96 5d b0 | d6 38 36 a4 68 7b 1c 30 78 fb 64 24 f3 fd 26 5e | d9 4c 1a 67 23 0d 00 00 14 40 48 b7 d5 6e bc e8 | 85 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 | 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 14 00 00 | 14 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 | 2f 14 00 00 18 ae 71 04 b4 74 f6 b2 d7 73 40 6b | e6 da 22 2e 2f ff 9d 6f 9e 00 00 00 18 4e 48 f5 | 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c 2d 31 22 | d4 00 00 00 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_AGGR (0x4) | flags: none (0x0) | Message ID: 0 (0x0) | length: 2340 (0x924) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_AGGR (4) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #1 in AGGR_I1 (find_state_ikev1_init) | start processing: state #1 connection "north-east" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x632 opt: 0x102000 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x630 opt: 0x102000 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x620 opt: 0x102000 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 36 (0x24) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x102000 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 191 (0xbf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | obj: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | obj: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | obj: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x102000 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | length: 1265 (0x4f1) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x80 (ISAKMP_NEXT_CR) needed: 0x200 opt: 0x102000 | ***parse ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 5 (0x5) | cert type: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x102000 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 388 (0x184) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x102000 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 20 (0x14) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102000 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 24 (0x18) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102000 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 24 (0x18) | removing 3 bytes of padding | message 'aggr_inR1_outI2' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | DER ASN1 DN: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | DER ASN1 DN: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | DER ASN1 DN: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | DER ASN1 DN: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "north-east" #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds loading root certificate cache | spent 4.23 milliseconds in get_root_certs() calling PK11_ListCertsInSlot() | spent 0.0338 milliseconds in get_root_certs() filtering CAs | #1 spent 4.3 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.0659 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.0599 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #1 spent 0.151 milliseconds in find_and_verify_certs() calling verify_end_cert() "north-east" #1: certificate verified OK: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740f5cc8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740f5308 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740b2c98 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740fc238 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x560e740b2eb8 | unreference key: 0x560e740fd0a8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | #1 spent 0.312 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #1 spent 4.94 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | CR | requested CA: '%any' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 3600 (0xe10) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | OAKLEY proposal verified; matching alg_info found | Oakley Transform 0 accepted | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) | State DB: re-hashing IKEv1 state #1 IKE SPIi and SPI[ir] | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x560e739e2800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 03 21 | natd_hash: port=500 | natd_hash: hash= ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | natd_hash: hash= ff 9d 6f 9e | natd_hash: hasher=0x560e739e2800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | natd_hash: hash= 2d 31 22 d4 | expected NAT-D(me): ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | expected NAT-D(me): ff 9d 6f 9e | expected NAT-D(him): | 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | 2d 31 22 d4 | received NAT-D: ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | received NAT-D: ff 9d 6f 9e | received NAT-D: 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | received NAT-D: 2d 31 22 d4 | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.23 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org) to type PKK_PSK | 1: compared key @road to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org -> 000 | 2: compared key @east to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org -> 000 | line 1: match=000 | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding aggr outR1 DH work-order 2 for state #1 | state #1 requesting EVENT_RETRANSMIT to be deleted | #1 STATE_AGGR_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x560e740e1d68 | free_event_entry: release EVENT_RETRANSMIT-pe@0x560e740dfde8 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x560e740dfde8 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x560e740fece8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #1 connection "north-east" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #1 and saving MD | #1 is busy; has a suspended MD | #1 spent 5.26 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "north-east" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 5.74 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 1 resuming | crypto helper 1 starting work-order 2 for state #1 | crypto helper 1 doing compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 2 | crypto helper 1 finished compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 2 time elapsed 0.001137 seconds | (#1) spent 1.15 milliseconds in crypto helper computing work-order 2: aggr outR1 DH (pcr) | crypto helper 1 sending results from work-order 2 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f8524005088 size 128 | libevent_realloc: release ptr-libevent@0x560e74070228 | libevent_realloc: new ptr-libevent@0x7f8524000f48 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 2 | calling continuation function 0x560e7390db50 | aggr inR1_outI2: calculated DH, sending I2 | required RSA CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | checking RSA keyid 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' for match with 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | trusted_ca_nss: trustor B = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | key issuer CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | an RSA Sig check passed with *AwEAAbEef [remote certificates] | #1 spent 0.146 milliseconds in try_all_RSA_keys() trying a pubkey "north-east" #1: Authenticated using RSA | CR | requested CA: '%any' | thinking about whether to send my certificate: | I have RSA key: OAKLEY_RSA_SIG cert.type: CERT_X509_SIGNATURE | sendcert: CERT_ALWAYSSEND and I did not get a certificate request | so send cert. | **emit ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_AGGR (0x4) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' "north-east" #1: I am sending my cert | ***emit ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | cert encoding: CERT_X509_SIGNATURE (0x4) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Certificate Payload (6:ISAKMP_NEXT_CERT) | next payload chain: saving location 'ISAKMP Certificate Payload'.'next payload type' in 'reply packet' | emitting 1227 raw bytes of CERT into ISAKMP Certificate Payload | CERT 30 82 04 c7 30 82 04 30 a0 03 02 01 02 02 01 06 | CERT 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | CERT 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | CERT 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | CERT 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | CERT 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | CERT 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | CERT 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | CERT 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | CERT 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | CERT 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | CERT 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | CERT 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | CERT 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | CERT 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | CERT 33 5a 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 | CERT 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | CERT 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | CERT 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | CERT 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | CERT 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | CERT 6d 65 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e | CERT 6f 72 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 | CERT 72 65 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 | CERT 2a 86 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d | CERT 6e 6f 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 | CERT 62 72 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 | CERT 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 | CERT 01 8f 00 30 82 01 8a 02 82 01 81 00 c0 59 bd 4b | CERT 40 fd f4 2c e7 cf 9e f3 29 e6 61 73 de ab 42 3d | CERT cc 51 1a e8 79 d6 53 46 a1 fd 66 d1 9e ab b4 65 | CERT 76 51 ad 3f 6f 8f ef d2 73 f9 fd 8f 44 b0 6c 36 | CERT 4b 95 c3 b2 45 0f 31 0c e9 df 35 95 44 c0 19 53 | CERT 8d df 6a 4b b2 af d6 d3 e8 dd f5 20 df 9c cd 8a | CERT f7 6a 09 92 60 00 45 44 39 4c 17 6c 06 02 91 37 | CERT 4b f5 6a c3 5e 21 c6 64 32 32 98 1d b7 99 1f 3c | CERT 13 fe ec c7 a4 a5 3b 37 30 df e4 31 95 47 91 b1 | CERT ca 96 66 b7 9e 49 65 a2 4c 79 54 17 ed 68 19 34 | CERT 9d 7e 67 91 27 51 f0 ee cb b3 90 68 7c 1d fd 83 | CERT 32 06 2e e6 6f d5 f0 62 00 4d ef 11 90 b6 ad 61 | CERT 83 0b 21 94 18 d9 2b 88 09 0d 33 2e 3b 71 18 f4 | CERT ce 4a 45 f3 37 f4 db c0 d6 ab c2 da da cd 6d e0 | CERT a3 9d 21 53 19 34 b1 0c d9 63 7c 45 b7 26 a4 d9 | CERT d6 93 25 1e 1f 74 3c 07 32 69 9b bc 0f db ba 3e | CERT 30 85 a4 3d ec 5c 70 fe fe 7d 64 3c 2c 48 b3 8a | CERT eb 26 bf 05 d4 33 1e c3 f7 1c 24 c9 99 e3 d1 99 | CERT 91 df 32 10 d5 7c 31 7e 9e 6f 70 01 dc 0d d7 21 | CERT 03 76 4d f5 b2 e3 87 30 94 8c b2 0a c0 b4 d9 0b | CERT d4 d9 37 e0 7a 73 13 50 8d 6f 93 9a 7c 5a 1a b2 | CERT 87 7e 0c 64 60 cb 4b 2c ef 22 75 b1 7c 60 3e e3 | CERT e5 f1 94 38 51 8f 00 e8 35 7b b5 01 ed c1 c4 fd | CERT a3 4b 56 42 d6 8b 64 38 74 95 c4 13 70 f0 f0 23 | CERT 29 57 2b ef 74 97 97 76 8d 30 48 91 02 03 01 00 | CERT 01 a3 81 e4 30 81 e1 30 09 06 03 55 1d 13 04 02 | CERT 30 00 30 26 06 03 55 1d 11 04 1f 30 1d 82 1b 6e | CERT 6f 72 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 | CERT 72 65 73 77 61 6e 2e 6f 72 67 30 0b 06 03 55 1d | CERT 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 16 | CERT 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b 06 | CERT 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 07 | CERT 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 07 | CERT 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e 74 | CERT 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 6e | CERT 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d 1f | CERT 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 70 | CERT 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e 6c | CERT 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 76 | CERT 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 86 | CERT f7 0d 01 01 0b 05 00 03 81 81 00 9e e9 26 57 73 | CERT c2 4c 64 c6 ab d6 d3 1a 13 4f 6b 48 e3 17 b2 3d | CERT fb 30 93 2d 15 92 6e a3 60 29 10 1d 3e a7 93 48 | CERT 3c 40 5b af 9e e5 93 b7 2f d5 4b 9f db bd ab 5d | CERT 03 57 3a 1a f9 81 87 13 dd 32 e7 93 b5 9e 3b 40 | CERT 3c c6 c9 d5 ce c6 c7 5d da 89 36 3d d0 36 82 fd | CERT b2 ab 00 2a 7c 0e a7 ad 3e e2 b1 5a 0d 88 45 26 | CERT 48 51 b3 c7 79 d7 04 e7 47 5f 28 f8 63 fb ae 58 | CERT 52 8b ba 60 ce 19 ac fa 4e 65 7d | emitting length of ISAKMP Certificate Payload: 1232 | sending NAT-D payloads | natd_hash: hasher=0x560e739e2800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | natd_hash: hash= 2d 31 22 d4 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Certificate Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 20 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D 4e 48 f5 1b be 3d ca a3 a8 e7 c6 72 b1 10 fa 4c | NAT-D 2d 31 22 d4 | emitting length of ISAKMP NAT-D Payload: 24 | natd_hash: hasher=0x560e739e2800(20) | natd_hash: icookie= 16 38 87 b3 8a 6a b1 69 | natd_hash: rcookie= c6 1e 2c db ca 22 d3 5a | natd_hash: ip= c0 01 03 21 | natd_hash: port=500 | natd_hash: hash= ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | natd_hash: hash= ff 9d 6f 9e | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_SIG (0x9) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 9:ISAKMP_NEXT_SIG | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 20 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D ae 71 04 b4 74 f6 b2 d7 73 40 6b e6 da 22 2e 2f | NAT-D ff 9d 6f 9e | emitting length of ISAKMP NAT-D Payload: 24 | next payload chain: creating a fake payload for hashing identity | **emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: no previous for current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID); assumed to be fake | emitting 185 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b6 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 24 30 22 06 03 55 04 03 0c 1b 6e 6f 72 | my identity 74 68 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 | my identity 73 77 61 6e 2e 6f 72 67 31 2f 30 2d 06 09 2a 86 | my identity 48 86 f7 0d 01 09 01 16 20 75 73 65 72 2d 6e 6f | my identity 72 74 68 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | my identity 65 73 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 193 | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAcBZv vs PKK_RSA:AwEAAcBZv | ***emit ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP Signature Payload (9:ISAKMP_NEXT_SIG) | next payload chain: saving location 'ISAKMP Signature Payload'.'next payload type' in 'reply packet' | emitting 384 raw bytes of SIG_I into ISAKMP Signature Payload | SIG_I 81 6f 14 f3 c4 bb d7 41 58 60 0c 07 89 33 8a 6f | SIG_I a4 1b 1e 2f df d8 5a b6 31 6c a0 86 2c 22 c9 62 | SIG_I 92 46 a9 0f f2 2e 62 f4 92 fd 29 10 64 a0 79 de | SIG_I 8c ae 0c 68 dc 26 e4 c9 37 ff be 2c c3 eb 29 3d | SIG_I 44 e2 91 5e c1 5e bb d2 74 81 5f 23 b1 96 5e 7e | SIG_I 72 f6 66 25 2e 7a 18 4d db 8e 30 b0 e3 6c e8 46 | SIG_I 38 d3 eb 66 a6 b7 2a af 1f 35 00 39 a3 34 5a 1a | SIG_I 45 47 e2 a2 c6 33 34 64 91 f9 34 52 54 52 51 39 | SIG_I 43 1a c5 6a 8b 3f c8 1d 92 d7 27 b7 f0 26 ec 4f | SIG_I 13 93 09 07 f9 1a ff a6 d5 af 84 48 ca 03 98 2f | SIG_I c3 f8 c4 06 e8 23 6a 74 a1 9b ae 43 6f 43 35 07 | SIG_I 16 33 a5 f1 2d be 71 7d db 14 9c 8a c0 1c 7d e7 | SIG_I cc 29 a4 12 3d c7 04 85 0b 3f 80 b7 dc 7a 2c 80 | SIG_I e6 e8 25 56 fe 65 1d 1b 25 48 21 92 18 79 23 c4 | SIG_I 31 c5 f4 86 66 ff a1 cc 83 cd 7b da a9 92 1d 92 | SIG_I 76 c0 e0 6c 12 b6 09 ed a9 b7 03 82 b8 90 08 88 | SIG_I e3 1f 0a ef 41 1a 2d 23 37 86 0b 6b 25 a8 63 c4 | SIG_I 54 dc 69 60 e7 65 d3 91 15 75 d9 68 e3 fc 58 95 | SIG_I e7 33 75 1e 6f 0c aa cc f8 e6 b3 01 6d a5 f7 c1 | SIG_I 28 9b da 9e 42 01 15 ed 03 6e 66 2b ff d2 85 ef | SIG_I f9 19 43 f7 e3 2f 12 9b 4d f1 69 d8 78 6b 7a df | SIG_I 77 46 04 b1 a8 47 0b 53 6a 9a cc 6d 8a 4d 12 13 | SIG_I ff c9 10 c7 53 31 13 38 2a c8 74 10 1e 14 bf 51 | SIG_I 52 3d 73 0e e0 2e ad 9f 90 f9 c2 92 ee 44 30 c8 | emitting length of ISAKMP Signature Payload: 388 | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 1708 | phase 1 complete | FOR_EACH_CONNECTION_... in ISAKMP_SA_established | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "north-east" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_AGGR_I1 to state STATE_AGGR_I2 | parent state #1: AGGR_I1(half-open IKE SA) => AGGR_I2(established IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x560e740fece8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x560e740dfde8 | sending reply packet to 192.1.2.23:500 (from 192.1.3.33:500) | sending 1708 bytes for STATE_AGGR_I1 through eth1 from 192.1.3.33:500 to 192.1.2.23:500 (using #1) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 06 10 04 01 00 00 00 00 00 00 06 ac c2 1e fa e3 | 58 6b a9 88 9e 54 17 0a 88 cd dc 10 5d 59 a9 92 | 0f a4 3a a7 f7 54 36 f2 f4 6b 39 bd 51 31 f9 96 | 36 19 81 3d c8 ba d6 de 89 1a 75 28 f5 c4 7d f3 | 66 13 8f ea 32 07 fd 15 8d dc f8 ce e5 17 04 04 | 34 a7 44 c1 76 a6 53 5e 0a d4 df 16 42 99 1b ba | 2a ab f6 b3 fe b7 14 94 b3 13 5a fb 62 2a 98 c7 | 1e 8c 55 eb 0d 32 1a bf ca d6 c5 76 2c 55 f9 26 | fc 4d dc 50 22 56 48 a3 ec bf dc de 7d 29 da 52 | 70 04 ca 76 ab 8f 01 64 fe 61 62 7b 31 c4 5e d6 | 06 07 eb f3 a6 c5 1c 2b 4d e1 f8 78 a9 6c 20 3d | 66 79 90 cc 1f 81 ca 6f 50 03 48 ac a2 57 77 f0 | 08 84 84 44 4a d7 9a e4 e1 75 95 f8 db 5c 90 12 | 52 c9 15 7a a0 b2 13 a9 cc 98 0f 5b 4c 40 e3 30 | c1 ee 69 d5 c1 59 fd dd b2 4b 7b 2b 33 b8 51 b7 | e5 73 d6 aa ab ec 7a 4b 99 31 8c 9f 92 0e 31 52 | 5f ea e5 e6 3e 56 4d f3 f5 6b 5b 83 d0 b4 fa d0 | 24 54 85 63 ee 3d 92 ab 05 38 3e 90 8a c0 f0 16 | 48 70 bd bc 99 3e a2 40 79 b9 47 f2 0f b6 60 db | d5 6f 8f f3 bd d5 b5 f8 07 f9 32 15 22 cd 89 2e | ba 54 65 7f 7e f5 dd f9 26 94 21 78 79 fe 2e 5e | 34 88 0e 4b 35 28 0e 56 f8 8b 5a 3e 98 21 52 af | 87 90 7a 9d dd 46 de b7 b1 78 f3 b4 56 6e a6 04 | da 97 ff 4e d6 09 2d 3a 04 39 9f 6f 4e 0b f4 3f | 9b 81 50 69 53 ae 7a e7 67 8f 0d ed bc ac 15 1c | 9b 32 37 e8 fb c1 2e 2c 75 9a c1 0b 55 73 72 9f | 29 af b1 d8 47 3d 64 7c b3 96 94 b9 1b 90 1b 83 | 86 7b be 7c cd 09 f1 b4 25 d9 60 ef c6 2e 16 09 | d7 23 ec b5 88 49 f7 48 8a ca 15 0b 87 75 18 2c | d3 97 ff e6 d5 08 25 59 0c fb 40 83 dd 2e 1e 9d | e0 88 ac 50 70 c1 d5 ac a8 00 44 8f 9e 25 b0 0a | 25 82 62 3b 90 93 be d1 b8 d1 2d 81 a7 d4 b6 af | 29 63 48 5a 2d ac 84 9e 2d ae 40 90 5c 44 65 fc | 4c 65 3b 74 d7 2f 96 1f 1b 9b 39 ec 54 e2 78 98 | 81 23 16 79 7c 24 f8 e7 dd e7 76 fe 72 4e 0c 41 | 01 a9 74 0b 66 3e ea 8d ca bd 12 50 8f 26 45 d1 | 3d 4e df 1f 9d 75 1f 6c 27 48 87 7d f2 ed 58 30 | 8e 47 1a 60 58 6d a9 43 6a 39 67 e1 8d 48 fc 10 | 3a 57 b9 f2 c0 e6 99 67 11 c2 21 03 9c aa 99 cc | 1b d5 6f 01 b5 e6 ea 68 eb 6e 5b 03 b5 4f fb 05 | b5 8e a9 8b 2c bd e5 78 7d 24 c5 0b b5 3a f2 08 | d4 4f c9 7e 9e 61 a8 d4 00 53 ff 1b 81 92 f9 9c | cb 2a bb f2 5b ae 18 2d 77 88 9e f3 e8 62 2e eb | 04 bc 4f d7 86 05 4a f7 d2 dc 86 96 dd 74 52 10 | 87 f0 93 e6 eb ac 88 1c 34 64 53 38 41 80 8b 56 | 8f a3 e4 9e f2 e5 17 70 d4 b2 a9 82 e8 1f df fc | ff ef 47 27 f4 c2 f6 dc c7 30 b9 95 8a 65 89 35 | f8 ff 9c 6c ea b5 7a 5c ad 1b 9e b8 b5 89 50 b0 | 12 3d 31 74 75 a0 be 2a 61 26 fc 08 7c 89 10 85 | 4f 38 04 2d 5e 88 cc 4b eb d3 f8 cc 03 30 2e f7 | 76 c9 24 f1 59 1c 9c 8c 53 60 2c d0 4e b1 85 a0 | e9 18 1f 3c a6 27 fa a3 46 de b1 35 ec ca 4c a9 | a8 8d c5 d3 8c d7 a4 4b 43 68 ad 7a 18 f6 7e 6a | a8 6a 89 e7 02 f8 11 06 5f 5e b7 75 d4 e4 f1 09 | 8d 0f 81 69 48 12 cd 4d 21 d2 e7 1e 52 0a 35 66 | 77 8e 32 9c 77 78 1c cc 7d 51 b2 8e b5 19 ad ef | 68 dc a5 47 94 ad 50 ea af e4 42 db a5 2f 03 b9 | 53 b3 15 a0 f0 1f 86 1a 2d d6 4f 3e ee 6f 37 9d | ba 89 6c b7 78 c9 fe 4e e9 75 73 1b 15 49 0d 44 | 49 19 75 23 63 80 f0 0d 0d 70 08 bf 53 38 f9 a6 | af 43 38 de b7 64 6f 87 ef 64 35 9f e9 69 41 74 | 36 00 a9 c4 e7 ca 9c c5 a5 bb a2 be 03 77 8a 9a | 21 c2 5d c0 85 4f 33 14 13 0f 9a f6 62 fa d5 fe | 03 c1 9a 3f aa 8e 0c 90 ec fd 51 b2 87 c1 f5 f6 | 38 c3 99 3e fe ba 36 e6 ad cc 1f 25 91 b4 88 06 | 4f 37 69 ab fe 86 f1 ab ce b4 6b 36 b6 11 3e e4 | ca 60 d1 1e c1 56 45 1f 45 82 1c 96 93 be 19 b2 | 7a 48 7d d2 14 30 0b b7 0a 92 a8 23 8e cf aa 36 | 12 72 47 7f 87 f1 5e 2e 9f 7b c6 31 bc de b2 9b | ef 31 4b ad fb 58 cd 50 f9 e5 bd 24 3e 2d 1c 0b | 73 76 18 fd 78 65 56 b4 2f 5c e0 3b a3 c1 ae ed | 25 44 ff 79 15 89 98 a7 56 c1 56 40 41 c5 ec 52 | 0d 4f 50 87 00 1d 51 f7 c7 4c 19 05 2b ed bc 43 | 7f 1b 34 9f 04 a2 cf a6 d9 d0 0e 7c 93 98 d9 1e | 35 99 af a9 dd 60 eb a9 05 07 71 7b 29 f1 7a 44 | df 32 3e 0b 51 8b 60 ef 40 85 39 87 f6 70 a9 60 | 87 75 92 1f 3a 09 ab b4 05 27 34 f8 2f 99 60 bd | c6 61 93 c5 a9 43 62 08 31 ae 7f 52 d0 85 49 d9 | c8 7a d2 c3 e8 04 82 fc 7d 62 03 eb 91 a9 14 b3 | 18 12 64 f7 e8 60 06 f3 f5 1f 50 b9 2b 1b 33 8d | 16 1c 08 0f dd 92 11 a4 75 fa 70 aa 17 9f 7a 94 | 1a c7 88 33 77 2c 77 b6 4d 1b cc e2 cb 69 6b 02 | e8 c6 07 20 2e 58 ed 6a f3 7f 1b be 01 1e 92 8e | c4 aa 76 90 1b f9 57 c5 95 81 c5 45 6a 4f be 38 | ce 2a b7 27 85 bd 53 10 f7 7b 87 92 a4 9e 07 0f | e6 dd 47 81 15 83 38 e4 2f d9 58 ed 9a 37 00 30 | 4c e1 0f ea c0 9b 4e 8a 6d 2b b2 c9 ee a5 a5 e9 | 20 f8 b3 5c de 8c ca ea 7f 85 1f 7a 46 ff f3 56 | d7 f7 02 87 a7 d5 09 11 32 60 6b 85 ae 3b 67 c1 | bc e0 ae b3 e4 4c cf ce 8e 68 f9 c4 49 7f 59 82 | cd 68 ea d5 08 5e e2 4e 9e 4f 7a 61 a5 6a 27 85 | 76 0b d7 d9 43 01 3e c7 fe 33 08 4f d2 25 3d 40 | 55 55 2e a3 fc 85 e1 2b a5 d2 ca f5 4b 91 76 6f | 45 2f fb 02 ca 1c 99 32 32 7a 49 2b 22 4a 37 86 | 18 1c 1b 50 f5 59 3a e4 47 ac af e6 02 20 42 85 | e9 8d 3c eb 28 98 9d 43 d8 a9 63 a7 fc 8e 8d ef | 47 da 44 4d d6 02 c3 32 aa 00 2d 9d f4 e4 29 4c | 40 e4 1f e5 fc f0 b6 e0 73 c8 a9 87 39 30 e0 e8 | 8f 50 19 c7 ea 4e 9e d7 7f f4 42 5f 0f 6c 5d f6 | 96 fd e1 01 51 8a 9c aa d5 eb 1c f5 2c 18 1c 08 | cf ec 41 d7 90 da e5 8b 77 ad 57 eb 29 8d 20 20 | ce 48 b4 e0 2a c8 1d c8 9e 76 4d 64 1d 2e 27 18 | 3f 7a a4 9f 83 fd fc 94 a0 b1 9b 60 69 fe 47 0b | 99 58 c3 b0 33 25 a7 94 dd fb b7 40 4c 7d 4b 54 | 01 2b 52 f4 9f be 91 2c 42 30 a3 5f 69 7d ba 6c | 25 bd db cc 4a d5 27 27 32 3e 9d ce | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x560e740dfde8 | inserting event EVENT_SA_REPLACE, timeout in 2607 seconds for #1 | libevent_malloc: new ptr-libevent@0x560e740fbcd8 size 128 | pstats #1 ikev1.isakmp established "north-east" #1: STATE_AGGR_I2: sent AI2, ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_128 integ=HMAC_SHA1 group=MODP2048} | DPD: dpd_init() called on ISAKMP SA | DPD: Peer supports Dead Peer Detection | DPD: not initializing DPD because DPD is disabled locally | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | unpending state #1 | creating state object #2 at 0x560e740eb4b8 | State DB: adding IKEv1 state #2 in UNDEFINED | pstats #2 ikev1.ipsec started | duplicating state object #1 "north-east" as #2 for IPSEC SA | #2 setting local endpoint to 192.1.3.33:500 from #1.st_localport (in duplicate_state() at state.c:1484) | suspend processing: state #1 connection "north-east" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:685) | start processing: state #2 connection "north-east" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:685) | child state #2: UNDEFINED(ignore) => QUICK_I1(established CHILD SA) "north-east" #2: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+UP+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO {using isakmp#1 msgid:bb1fb06a proposal=AES_CBC_128-HMAC_SHA1_96 pfsgroup=MODP2048} | adding quick_outI1 KE work-order 3 for state #2 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x560e740e8c88 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x560e740d8c88 size 128 | crypto helper 2 resuming | crypto helper 2 starting work-order 3 for state #2 | crypto helper 2 doing build KE and nonce (quick_outI1 KE); request ID 3 | crypto helper 2 finished build KE and nonce (quick_outI1 KE); request ID 3 time elapsed 0.000917 seconds | (#2) spent 0.926 milliseconds in crypto helper computing work-order 3: quick_outI1 KE (pcr) | crypto helper 2 sending results from work-order 3 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f8528003f28 size 128 | crypto helper 2 waiting (nothing to do) | stop processing: state #2 connection "north-east" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:764) | resume processing: state #1 connection "north-east" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:764) | unqueuing pending Quick Mode with 192.1.2.23 "north-east" | removing pending policy for no connection {0x560e740c3968} | close_any(fd@24) (in release_whack() at state.c:654) | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 9.23 milliseconds | #1 spent 9.44 milliseconds in resume sending helper answer | stop processing: state #1 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8524005088 | processing resume sending helper answer for #2 | start processing: state #2 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 2 replies to request ID 3 | calling continuation function 0x560e7390db50 | quick_outI1_continue for #2: calculated ke+nonce, sending I1 | **emit ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3139416170 (0xbb1fb06a) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 20 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 24 | emitting quick defaults using policy none | kernel_alg_db_new() initial trans_cnt=135 | adding proposal: AES_CBC_128-HMAC_SHA1_96 | kernel_alg_db_new() will return p_new->protoid=3, p_new->trans_cnt=1 | kernel_alg_db_new() trans[0]: transid=12, attr_cnt=2, attrs[0].type=5, attrs[0].val=2 | returning new proposal from esp_info | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 1 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0xc0b4db0c for esp.0@192.1.3.33 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI c0 b4 db 0c | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ESP): 32 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni fc fb 85 8a 77 bf d5 40 11 59 4a 36 9e 08 17 a1 | Ni 4c aa 74 cc 41 6d e0 6b 2a 74 c1 08 7b 8f 5f 13 | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 52 90 b4 96 03 10 56 c7 f0 62 21 ea 8a aa ba 08 | keyex value 43 c1 2c f1 92 46 fb a4 6f 2e 9e 91 e7 8c 78 ad | keyex value 1a 0d 9f 5e 80 c7 83 d6 3b e3 5f de cd 33 f4 a1 | keyex value bd a7 40 53 d7 3b c6 b4 30 e7 fb d2 af ff 81 e0 | keyex value 1b fd c1 91 62 83 96 81 d6 8e d6 81 93 ac 62 f7 | keyex value e3 61 23 42 47 bd a4 00 4d dc ea f7 d7 ab 4d b0 | keyex value 82 33 e9 c6 d0 13 6d aa 63 5a d6 af b8 fe a4 24 | keyex value ea 60 42 1a 0e d5 03 cf 4f 24 59 01 6f 15 a0 ab | keyex value 5a f3 9c 6b 4f 22 32 ec 57 a8 84 7d cf 7a 7e 80 | keyex value d7 81 4e d4 e3 61 fe 8f 4f ec a6 5f ac b9 e4 33 | keyex value 3f 06 23 7d da 98 2e e4 86 e9 59 25 4d c4 8a f4 | keyex value 1f 09 fa f9 aa a1 a1 cb 58 97 c7 de cb 2d 92 50 | keyex value ff c6 54 76 a3 87 33 6a b2 29 1a 11 84 ce 9f 24 | keyex value f8 2b 05 3a 92 28 8a 1c 48 dc fe 8d d5 15 08 e8 | keyex value 89 92 6c 2a 42 a7 57 0b 75 06 32 c7 3a 35 6d d3 | keyex value 3b 2d d0 ff 71 10 61 22 12 22 e7 b4 e2 f0 d0 70 | emitting length of ISAKMP Key Exchange Payload: 260 | outI1 HASH(1): | f1 92 f8 36 16 81 ec d3 c8 21 9a 5d 51 8b 5e 3e | 08 80 07 38 | emitting 8 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 412 | sending 412 bytes for reply packet from quick_outI1 through eth1 from 192.1.3.33:500 to 192.1.2.23:500 (using #2) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 08 10 20 01 bb 1f b0 6a 00 00 01 9c 34 98 a1 19 | 45 e9 e0 be d3 fc c8 ea e7 3c c7 12 8f 35 bb 93 | f7 cd be f4 90 b6 c5 6b 11 42 43 bb 77 76 69 4e | 0d ed 1f a7 aa de 29 69 b1 21 1e 85 a9 84 95 e3 | 96 e4 53 5f e8 5c 58 79 22 11 f9 97 26 09 0e d0 | c1 45 5c ff 41 0c 20 8e 45 7c 8f 86 b1 f4 6d 67 | 1b 44 9d 02 1a 2f f3 41 17 ee 96 a9 d0 3c f0 ba | 1b 1d de 0a d7 06 01 17 34 2d bc b5 b0 af 01 e9 | 0f 33 8f 09 31 ac 09 f0 89 27 59 61 08 17 07 8d | f8 2c 32 f4 29 d1 4c 11 e0 b6 4c c3 35 12 71 8e | 07 7e d1 be 3f 18 95 a4 ed 43 8c ff a1 60 56 c7 | 9d 2c 36 51 6e 62 49 b9 71 64 f3 68 3d 4c 97 a7 | 82 d2 72 67 a5 f5 ce 33 eb 10 29 50 17 37 53 f1 | de 3f 20 bc 0f 81 0d b6 8c 28 90 3e b5 30 1a c0 | 9f 2f 1e 63 b0 0c 8e a9 6c ac 66 c8 04 d6 33 eb | b9 47 66 f4 63 a2 7d 63 73 53 19 e3 2c 8d cb 1b | 36 57 b0 6f 3b 39 1b 49 8b 9d ec 4d ec 51 cf f1 | b5 c7 de 2c c2 73 b3 b4 d6 54 b6 7c ea d3 b7 e9 | 23 e7 86 9f 8a 93 b3 80 86 83 74 96 4c b1 6c 18 | 04 86 81 1f 9a 56 21 7d c1 b2 62 5c 11 27 7d 24 | 02 ab f4 da 16 c9 31 72 4d 5d 57 74 c5 9e bb da | c6 da a3 d5 f4 d9 a3 9d 9e d7 db 82 cf 27 92 62 | b7 4d e1 7b b1 fa db c4 6b 09 de b6 99 26 51 f4 | d1 27 d0 ea 76 c1 f6 aa 6b 23 8a 03 4a ee a7 c5 | bf 5d a4 2e 4f a9 f4 e1 b9 89 a5 56 | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x560e740d8c88 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x560e740e8c88 "north-east" #2: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x560e740e8c88 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x560e740e9708 size 128 | #2 STATE_QUICK_I1: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 29863.316254 | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 0.41 milliseconds in resume sending helper answer | stop processing: state #2 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f8528003f28 | spent 0.00274 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 412 bytes from 192.1.2.23:500 on eth1 (192.1.3.33:500) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 08 10 20 01 bb 1f b0 6a 00 00 01 9c 7c 4d 5f 91 | ce 09 3e 76 d4 aa 10 54 67 da 6a 6f a9 b4 d5 ea | 37 37 24 e2 fe 3c 5d 14 ed 32 f0 63 48 60 20 00 | 2a f0 5e a1 5e 4f 80 15 de 5e 48 69 c1 1d 16 c3 | 4c 26 93 53 2b a4 b4 2b 13 8f 5d cc 1a c1 46 a7 | 06 b5 53 85 f4 15 e4 95 0c 25 c2 94 4d 3d 2c 55 | 47 44 ee 00 8a d4 7e 26 a5 43 f3 49 56 41 4c 49 | d2 65 8e 26 1d 29 54 55 c3 76 2c fa 96 f9 94 b0 | 64 9f c7 b5 7c f0 f8 4d da 8e f2 03 27 21 93 af | a7 41 df 10 44 c7 b4 86 dd 9f 08 54 a3 89 ce 6c | eb e6 27 ff 26 e5 23 a3 76 28 c5 28 cd 94 73 ee | 6d 25 dc bb 4d 3e 67 21 59 36 64 88 08 4d 69 25 | 70 ab 4c 25 22 e2 11 92 18 27 20 c3 0a db 9a 8d | 9f 7c e2 75 54 f4 c4 1a b3 b6 c0 d9 0a c2 4d 56 | 43 80 db ee 71 68 40 0c 0f 6a e9 7b c2 9d 1f 49 | 6d 80 b6 0b ee db 58 8c 51 8b 4f 58 96 c9 1f 03 | 0c f0 6a 3f b9 c0 23 41 c0 12 69 32 3b 3b 20 10 | 95 8b 88 7d 0b 75 91 8a 13 81 73 11 d1 00 13 89 | b4 a8 12 1e c6 68 b6 0b 20 50 4d 03 86 ad dc 56 | d8 5e 98 40 ed 55 7a 35 4f 73 ac d3 5a d5 69 55 | ba ff a8 03 d0 6c 93 2e 5e 11 ae a1 7a 7a 7f f0 | 98 c5 2c 12 ac 8d 68 41 b5 f7 9a 51 2d 7f 1f 63 | 30 56 23 cd e4 73 f8 80 a1 c3 24 6e 3b ad bb 7f | f3 a0 dd 56 28 3f 1c c2 4c 36 83 67 46 9e 1e f3 | d1 f8 ae 43 a3 ef 80 99 ca fe a7 5d | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3139416170 (0xbb1fb06a) | length: 412 (0x19c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #2 in QUICK_I1 (find_state_ikev1) | start processing: state #2 connection "north-east" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1633) | #2 is idle | #2 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 24 (0x18) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 260 (0x104) | removing 8 bytes of padding | quick_inR1_outI2 HASH(2): | 2d 56 80 f1 f9 2b 31 bc 46 0d 0f e0 9b c9 24 7c | 53 59 c3 c5 | received 'quick_inR1_outI2' message HASH(2) data ok | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI 3b d1 c5 cd | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified; matches alg_info entry | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org) to type PKK_PSK | 1: compared key @road to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org -> 000 | 2: compared key @east to C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org / C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org -> 000 | line 1: match=000 | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outI2 DH work-order 4 for state #2 | state #2 requesting EVENT_RETRANSMIT to be deleted | #2 STATE_QUICK_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x560e740e9708 | free_event_entry: release EVENT_RETRANSMIT-pe@0x560e740e8c88 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x560e740e8c88 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x7f8528003f28 size 128 | crypto helper 3 resuming | crypto helper 3 starting work-order 4 for state #2 | crypto helper 3 doing compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 4 | crypto helper 3 finished compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 4 time elapsed 0.00095 seconds | (#2) spent 0.955 milliseconds in crypto helper computing work-order 4: quick outI2 DH (pcr) | crypto helper 3 sending results from work-order 4 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f851c001f78 size 128 | crypto helper 3 waiting (nothing to do) | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #2 connection "north-east" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #2 and saving MD | #2 is busy; has a suspended MD | #2 spent 0.163 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "north-east" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.349 milliseconds in comm_handle_cb() reading and processing packet | processing resume sending helper answer for #2 | start processing: state #2 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 3 replies to request ID 4 | calling continuation function 0x560e7390db50 | quick_inR1_outI2_continue for #2: calculated ke+nonce, calculating DH | **emit ISAKMP Message: | initiator cookie: | 16 38 87 b3 8a 6a b1 69 | responder cookie: | c6 1e 2c db ca 22 d3 5a | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3139416170 (0xbb1fb06a) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 20 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 24 | quick_inR1_outI2 HASH(3): | 27 15 de af 93 06 41 d6 d8 22 27 58 b3 0e 0c 67 | a2 36 e5 df | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | install_ipsec_sa() for #2: inbound and outbound | could_route called for north-east (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | route owner of "north-east" unrouted: NULL; eroute owner: NULL | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'north-east' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.3bd1c5cd@192.1.2.23 included non-error error | set up outgoing SA, ref=0/0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'north-east' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.c0b4db0c@192.1.3.33 included non-error error | priority calculation of connection "north-east" is 0xfdfdf | add inbound eroute 192.1.2.23/32:0 --0-> 192.1.3.33/32:0 => tun.10000@192.1.3.33 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | set up incoming SA, ref=0/0 | sr for #2: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn north-east mark 0/00000000, 0/00000000 vs | conn north-east mark 0/00000000, 0/00000000 | route owner of "north-east" unrouted: NULL; eroute owner: NULL | route_and_eroute with c: north-east (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #2 | priority calculation of connection "north-east" is 0xfdfdf | eroute_connection add eroute 192.1.3.33/32:0 --0-> 192.1.2.23/32:0 => tun.0@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-host | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | trusted_ca_nss: trustor B = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | executing up-host: PLUTO_VERB='up-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.254' PLUTO_ME='192.1.3.33' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.3.33/32' PLUTO_MY_CLIENT_NET='192.1.3.33' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.1.2.23/32' PLUTO_PEER_CLIENT_NET='192.1.2.23' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+EN | popen cmd is 1412 chars long | cmd( 0):PLUTO_VERB='up-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.254' PLUTO_ME='192.1.3.33' PLUTO_MY_ID='C=: | cmd( 160):CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.lib: | cmd( 240):reswan.org, E=user-north@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.3.33/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.1.3.33' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY: | cmd( 400):_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO: | cmd( 480):_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=T: | cmd( 560):est Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org: | cmd( 640):' PLUTO_PEER_CLIENT='192.1.2.23/32' PLUTO_PEER_CLIENT_NET='192.1.2.23' PLUTO_PEE: | cmd( 720):R_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUT: | cmd( 800):O_PEER_CA='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libr: | cmd( 880):eswan test CA for mainca, E=testing@libreswan.org' PLUTO_STACK='netkey' PLUTO_AD: | cmd( 960):DTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+UP+AGGRESSIVE+IKEV1_ALLOW: | cmd(1040):+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_AD: | cmd(1120):DRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PL: | cmd(1200):UTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIE: | cmd(1280):NT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI: | cmd(1360):_IN=0x3bd1c5cd SPI_OUT=0xc0b4db0c ipsec _updown 2>&1: | route_and_eroute: firewall_notified: true | running updown command "ipsec _updown" for verb prepare | command executing prepare-host | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | trusted_ca_nss: trustor B = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | executing prepare-host: PLUTO_VERB='prepare-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.254' PLUTO_ME='192.1.3.33' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.3.33/32' PLUTO_MY_CLIENT_NET='192.1.3.33' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.1.2.23/32' PLUTO_PEER_CLIENT_NET='192.1.2.23' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY= | popen cmd is 1417 chars long | cmd( 0):PLUTO_VERB='prepare-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.254' PLUTO_ME='192.1.3.33' PLUTO_MY_I: | cmd( 160):D='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testin: | cmd( 240):g.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.3.33: | cmd( 320):/32' PLUTO_MY_CLIENT_NET='192.1.3.33' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLU: | cmd( 400):TO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' : | cmd( 480):PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan,: | cmd( 560): OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswa: | cmd( 640):n.org' PLUTO_PEER_CLIENT='192.1.2.23/32' PLUTO_PEER_CLIENT_NET='192.1.2.23' PLUT: | cmd( 720):O_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0': | cmd( 800): PLUTO_PEER_CA='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN: | cmd( 880):=Libreswan test CA for mainca, E=testing@libreswan.org' PLUTO_STACK='netkey' PLU: | cmd( 960):TO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+UP+AGGRESSIVE+IKEV1_: | cmd(1040):ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CO: | cmd(1120):NN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO=: | cmd(1200):'' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG: | cmd(1280):_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no: | cmd(1360):' SPI_IN=0x3bd1c5cd SPI_OUT=0xc0b4db0c ipsec _updown 2>&1: | running updown command "ipsec _updown" for verb route | command executing route-host | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | trusted_ca_nss: trustor B = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | executing route-host: PLUTO_VERB='route-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.254' PLUTO_ME='192.1.3.33' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.3.33/32' PLUTO_MY_CLIENT_NET='192.1.3.33' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.1.2.23/32' PLUTO_PEER_CLIENT_NET='192.1.2.23' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSA | popen cmd is 1415 chars long | cmd( 0):PLUTO_VERB='route-host' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-east' PLUTO_: | cmd( 80):INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.254' PLUTO_ME='192.1.3.33' PLUTO_MY_ID=: | cmd( 160):'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.: | cmd( 240):libreswan.org, E=user-north@testing.libreswan.org' PLUTO_MY_CLIENT='192.1.3.33/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.1.3.33' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO: | cmd( 400):_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PL: | cmd( 480):UTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, O: | cmd( 560):U=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.: | cmd( 640):org' PLUTO_PEER_CLIENT='192.1.2.23/32' PLUTO_PEER_CLIENT_NET='192.1.2.23' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=L: | cmd( 880):ibreswan test CA for mainca, E=testing@libreswan.org' PLUTO_STACK='netkey' PLUTO: | cmd( 960):_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+UP+AGGRESSIVE+IKEV1_AL: | cmd(1040):LOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN: | cmd(1120):_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='': | cmd(1200): PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_C: | cmd(1280):LIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' : | cmd(1360):SPI_IN=0x3bd1c5cd SPI_OUT=0xc0b4db0c ipsec _updown 2>&1: | route_and_eroute: instance "north-east", setting eroute_owner {spd=0x560e740d7088,sr=0x560e740d7088} to #2 (was #0) (newest_ipsec_sa=#0) | #1 spent 1.98 milliseconds in install_ipsec_sa() | emitting 8 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 60 | inR1_outI2: instance north-east[0], setting IKEv1 newest_ipsec_sa to #2 (was #0) (spd.eroute=#2) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "north-east" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_I1 to state STATE_QUICK_I2 | child state #2: QUICK_I1(established CHILD SA) => QUICK_I2(established CHILD SA) | event_already_set, deleting event | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f8528003f28 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x560e740e8c88 | sending reply packet to 192.1.2.23:500 (from 192.1.3.33:500) | sending 60 bytes for STATE_QUICK_I1 through eth1 from 192.1.3.33:500 to 192.1.2.23:500 (using #2) | 16 38 87 b3 8a 6a b1 69 c6 1e 2c db ca 22 d3 5a | 08 10 20 01 bb 1f b0 6a 00 00 00 3c ac e6 97 7d | 4d 91 95 f8 16 56 45 b9 9f 3e aa 8c d5 0d 10 61 | d9 80 39 49 ac 6d 81 4c 7d e2 4a a5 | !event_already_set at reschedule | event_schedule: new EVENT_SA_REPLACE-pe@0x7f8528004218 | inserting event EVENT_SA_REPLACE, timeout in 28048 seconds for #2 | libevent_malloc: new ptr-libevent@0x560e740f6e48 size 128 | pstats #2 ikev1.ipsec established | NAT-T: encaps is 'auto' "north-east" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0x3bd1c5cd <0xc0b4db0c xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | close_any(fd@25) (in release_whack() at state.c:654) | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 2.37 milliseconds in resume sending helper answer | stop processing: state #2 connection "north-east" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f851c001f78 | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00501 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00311 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00282 milliseconds in signal handler PLUTO_SIGCHLD