Sep 21 07:25:33.242441: FIPS Product: YES Sep 21 07:25:33.242476: FIPS Kernel: NO Sep 21 07:25:33.242479: FIPS Mode: NO Sep 21 07:25:33.242481: NSS DB directory: sql:/etc/ipsec.d Sep 21 07:25:33.244251: Initializing NSS Sep 21 07:25:33.244263: Opening NSS database "sql:/etc/ipsec.d" read-only Sep 21 07:25:33.277221: NSS initialized Sep 21 07:25:33.277244: NSS crypto library initialized Sep 21 07:25:33.277248: FIPS HMAC integrity support [enabled] Sep 21 07:25:33.277251: FIPS mode disabled for pluto daemon Sep 21 07:25:33.348067: FIPS HMAC integrity verification self-test FAILED Sep 21 07:25:33.348152: libcap-ng support [enabled] Sep 21 07:25:33.348158: Linux audit support [enabled] Sep 21 07:25:33.348180: Linux audit activated Sep 21 07:25:33.348191: Starting Pluto (Libreswan Version v3.28-827-gc9aa82b8a6-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC SYSTEMD_WATCHDOG FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:11027 Sep 21 07:25:33.348193: core dump dir: /tmp Sep 21 07:25:33.348195: secrets file: /etc/ipsec.secrets Sep 21 07:25:33.348196: leak-detective disabled Sep 21 07:25:33.348197: NSS crypto [enabled] Sep 21 07:25:33.348198: XAUTH PAM support [enabled] Sep 21 07:25:33.348257: | libevent is using pluto's memory allocator Sep 21 07:25:33.348262: Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) Sep 21 07:25:33.348275: | libevent_malloc: new ptr-libevent@0x55d7e7369020 size 40 Sep 21 07:25:33.348277: | libevent_malloc: new ptr-libevent@0x55d7e736a2d0 size 40 Sep 21 07:25:33.348279: | libevent_malloc: new ptr-libevent@0x55d7e736a300 size 40 Sep 21 07:25:33.348281: | creating event base Sep 21 07:25:33.348283: | libevent_malloc: new ptr-libevent@0x55d7e736a290 size 56 Sep 21 07:25:33.348285: | libevent_malloc: new ptr-libevent@0x55d7e736a330 size 664 Sep 21 07:25:33.348293: | libevent_malloc: new ptr-libevent@0x55d7e736a5d0 size 24 Sep 21 07:25:33.348296: | libevent_malloc: new ptr-libevent@0x55d7e735beb0 size 384 Sep 21 07:25:33.348303: | libevent_malloc: new ptr-libevent@0x55d7e736a5f0 size 16 Sep 21 07:25:33.348305: | libevent_malloc: new ptr-libevent@0x55d7e736a610 size 40 Sep 21 07:25:33.348307: | libevent_malloc: new ptr-libevent@0x55d7e736a640 size 48 Sep 21 07:25:33.348312: | libevent_realloc: new ptr-libevent@0x55d7e72ec370 size 256 Sep 21 07:25:33.348314: | libevent_malloc: new ptr-libevent@0x55d7e736a680 size 16 Sep 21 07:25:33.348317: | libevent_free: release ptr-libevent@0x55d7e736a290 Sep 21 07:25:33.348320: | libevent initialized Sep 21 07:25:33.348322: | libevent_realloc: new ptr-libevent@0x55d7e736a6a0 size 64 Sep 21 07:25:33.348327: | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds Sep 21 07:25:33.348338: | init_nat_traversal() initialized with keep_alive=0s Sep 21 07:25:33.348340: NAT-Traversal support [enabled] Sep 21 07:25:33.348341: | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized Sep 21 07:25:33.348346: | global one-shot timer EVENT_FREE_ROOT_CERTS initialized Sep 21 07:25:33.348348: | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds Sep 21 07:25:33.348375: | global one-shot timer EVENT_REVIVE_CONNS initialized Sep 21 07:25:33.348377: | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds Sep 21 07:25:33.348379: | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Sep 21 07:25:33.348413: Encryption algorithms: Sep 21 07:25:33.348420: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c Sep 21 07:25:33.348422: AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b Sep 21 07:25:33.348424: AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a Sep 21 07:25:33.348426: 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des Sep 21 07:25:33.348428: CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} Sep 21 07:25:33.348435: CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia Sep 21 07:25:33.348437: AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c Sep 21 07:25:33.348439: AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b Sep 21 07:25:33.348441: AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a Sep 21 07:25:33.348443: AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr Sep 21 07:25:33.348445: AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes Sep 21 07:25:33.348447: SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent Sep 21 07:25:33.348449: TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish Sep 21 07:25:33.348452: TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh Sep 21 07:25:33.348454: NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac Sep 21 07:25:33.348455: NULL IKEv1: ESP IKEv2: ESP [] Sep 21 07:25:33.348457: CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Sep 21 07:25:33.348462: Hash algorithms: Sep 21 07:25:33.348464: MD5 IKEv1: IKE IKEv2: Sep 21 07:25:33.348466: SHA1 IKEv1: IKE IKEv2: FIPS sha Sep 21 07:25:33.348468: SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 Sep 21 07:25:33.348469: SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 Sep 21 07:25:33.348471: SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 Sep 21 07:25:33.348479: PRF algorithms: Sep 21 07:25:33.348481: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 Sep 21 07:25:33.348483: HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 Sep 21 07:25:33.348485: HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 Sep 21 07:25:33.348487: HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 Sep 21 07:25:33.348489: HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 Sep 21 07:25:33.348490: AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Sep 21 07:25:33.348505: Integrity algorithms: Sep 21 07:25:33.348507: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 Sep 21 07:25:33.348509: HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 Sep 21 07:25:33.348512: HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 Sep 21 07:25:33.348514: HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 Sep 21 07:25:33.348516: HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 Sep 21 07:25:33.348518: HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH Sep 21 07:25:33.348520: AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 Sep 21 07:25:33.348522: AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac Sep 21 07:25:33.348523: NONE IKEv1: ESP IKEv2: IKE ESP FIPS null Sep 21 07:25:33.348531: DH algorithms: Sep 21 07:25:33.348533: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 Sep 21 07:25:33.348535: MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 Sep 21 07:25:33.348536: MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 Sep 21 07:25:33.348540: MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 Sep 21 07:25:33.348541: MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 Sep 21 07:25:33.348543: MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 Sep 21 07:25:33.348545: MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 Sep 21 07:25:33.348547: DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 Sep 21 07:25:33.348548: DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 Sep 21 07:25:33.348550: DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 Sep 21 07:25:33.348552: DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 Sep 21 07:25:33.348553: testing CAMELLIA_CBC: Sep 21 07:25:33.348555: Camellia: 16 bytes with 128-bit key Sep 21 07:25:33.348644: Camellia: 16 bytes with 128-bit key Sep 21 07:25:33.348662: Camellia: 16 bytes with 256-bit key Sep 21 07:25:33.348680: Camellia: 16 bytes with 256-bit key Sep 21 07:25:33.348697: testing AES_GCM_16: Sep 21 07:25:33.348699: empty string Sep 21 07:25:33.348716: one block Sep 21 07:25:33.348731: two blocks Sep 21 07:25:33.348746: two blocks with associated data Sep 21 07:25:33.348761: testing AES_CTR: Sep 21 07:25:33.348763: Encrypting 16 octets using AES-CTR with 128-bit key Sep 21 07:25:33.348779: Encrypting 32 octets using AES-CTR with 128-bit key Sep 21 07:25:33.348816: Encrypting 36 octets using AES-CTR with 128-bit key Sep 21 07:25:33.348835: Encrypting 16 octets using AES-CTR with 192-bit key Sep 21 07:25:33.348864: Encrypting 32 octets using AES-CTR with 192-bit key Sep 21 07:25:33.348879: Encrypting 36 octets using AES-CTR with 192-bit key Sep 21 07:25:33.348895: Encrypting 16 octets using AES-CTR with 256-bit key Sep 21 07:25:33.348911: Encrypting 32 octets using AES-CTR with 256-bit key Sep 21 07:25:33.348927: Encrypting 36 octets using AES-CTR with 256-bit key Sep 21 07:25:33.348943: testing AES_CBC: Sep 21 07:25:33.348945: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Sep 21 07:25:33.348960: Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Sep 21 07:25:33.348977: Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Sep 21 07:25:33.348994: Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key Sep 21 07:25:33.349014: testing AES_XCBC: Sep 21 07:25:33.349015: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input Sep 21 07:25:33.349089: RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input Sep 21 07:25:33.349170: RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input Sep 21 07:25:33.349250: RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input Sep 21 07:25:33.349331: RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input Sep 21 07:25:33.349412: RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input Sep 21 07:25:33.349487: RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input Sep 21 07:25:33.349655: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) Sep 21 07:25:33.349728: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) Sep 21 07:25:33.349844: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) Sep 21 07:25:33.350015: testing HMAC_MD5: Sep 21 07:25:33.350017: RFC 2104: MD5_HMAC test 1 Sep 21 07:25:33.350139: RFC 2104: MD5_HMAC test 2 Sep 21 07:25:33.350234: RFC 2104: MD5_HMAC test 3 Sep 21 07:25:33.350366: 8 CPU cores online Sep 21 07:25:33.350370: starting up 7 crypto helpers Sep 21 07:25:33.350403: started thread for crypto helper 0 Sep 21 07:25:33.350409: | starting up helper thread 0 Sep 21 07:25:33.350428: | status value returned by setting the priority of this thread (crypto helper 0) 22 Sep 21 07:25:33.350432: | crypto helper 0 waiting (nothing to do) Sep 21 07:25:33.350442: started thread for crypto helper 1 Sep 21 07:25:33.350445: | starting up helper thread 1 Sep 21 07:25:33.350463: | status value returned by setting the priority of this thread (crypto helper 1) 22 Sep 21 07:25:33.350465: started thread for crypto helper 2 Sep 21 07:25:33.350465: | crypto helper 1 waiting (nothing to do) Sep 21 07:25:33.350472: | starting up helper thread 2 Sep 21 07:25:33.350481: started thread for crypto helper 3 Sep 21 07:25:33.350484: | status value returned by setting the priority of this thread (crypto helper 2) 22 Sep 21 07:25:33.350487: | crypto helper 2 waiting (nothing to do) Sep 21 07:25:33.350496: started thread for crypto helper 4 Sep 21 07:25:33.350502: | starting up helper thread 4 Sep 21 07:25:33.350510: | status value returned by setting the priority of this thread (crypto helper 4) 22 Sep 21 07:25:33.350514: | starting up helper thread 5 Sep 21 07:25:33.350525: | status value returned by setting the priority of this thread (crypto helper 5) 22 Sep 21 07:25:33.350514: | starting up helper thread 3 Sep 21 07:25:33.350516: | crypto helper 4 waiting (nothing to do) Sep 21 07:25:33.350544: | crypto helper 5 waiting (nothing to do) Sep 21 07:25:33.350537: | status value returned by setting the priority of this thread (crypto helper 3) 22 Sep 21 07:25:33.350511: started thread for crypto helper 5 Sep 21 07:25:33.350555: | crypto helper 3 waiting (nothing to do) Sep 21 07:25:33.350575: started thread for crypto helper 6 Sep 21 07:25:33.350577: | starting up helper thread 6 Sep 21 07:25:33.350585: | checking IKEv1 state table Sep 21 07:25:33.350589: | status value returned by setting the priority of this thread (crypto helper 6) 22 Sep 21 07:25:33.350595: | crypto helper 6 waiting (nothing to do) Sep 21 07:25:33.350598: | MAIN_R0: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350600: | -> MAIN_R1 EVENT_SO_DISCARD Sep 21 07:25:33.350602: | MAIN_I1: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350604: | -> MAIN_I2 EVENT_RETRANSMIT Sep 21 07:25:33.350606: | MAIN_R1: category: open IKE SA flags: 200: Sep 21 07:25:33.350608: | -> MAIN_R2 EVENT_RETRANSMIT Sep 21 07:25:33.350610: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:33.350612: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:33.350614: | MAIN_I2: category: open IKE SA flags: 0: Sep 21 07:25:33.350615: | -> MAIN_I3 EVENT_RETRANSMIT Sep 21 07:25:33.350618: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:33.350619: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:33.350621: | MAIN_R2: category: open IKE SA flags: 0: Sep 21 07:25:33.350622: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:25:33.350623: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:25:33.350625: | -> UNDEFINED EVENT_SA_REPLACE Sep 21 07:25:33.350626: | MAIN_I3: category: open IKE SA flags: 0: Sep 21 07:25:33.350628: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:25:33.350629: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:25:33.350631: | -> UNDEFINED EVENT_SA_REPLACE Sep 21 07:25:33.350632: | MAIN_R3: category: established IKE SA flags: 200: Sep 21 07:25:33.350634: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350635: | MAIN_I4: category: established IKE SA flags: 0: Sep 21 07:25:33.350637: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350638: | AGGR_R0: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350640: | -> AGGR_R1 EVENT_SO_DISCARD Sep 21 07:25:33.350641: | AGGR_I1: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350643: | -> AGGR_I2 EVENT_SA_REPLACE Sep 21 07:25:33.350644: | -> AGGR_I2 EVENT_SA_REPLACE Sep 21 07:25:33.350646: | AGGR_R1: category: open IKE SA flags: 200: Sep 21 07:25:33.350647: | -> AGGR_R2 EVENT_SA_REPLACE Sep 21 07:25:33.350649: | -> AGGR_R2 EVENT_SA_REPLACE Sep 21 07:25:33.350650: | AGGR_I2: category: established IKE SA flags: 200: Sep 21 07:25:33.350652: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350653: | AGGR_R2: category: established IKE SA flags: 0: Sep 21 07:25:33.350655: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350656: | QUICK_R0: category: established CHILD SA flags: 0: Sep 21 07:25:33.350660: | -> QUICK_R1 EVENT_RETRANSMIT Sep 21 07:25:33.350662: | QUICK_I1: category: established CHILD SA flags: 0: Sep 21 07:25:33.350663: | -> QUICK_I2 EVENT_SA_REPLACE Sep 21 07:25:33.350665: | QUICK_R1: category: established CHILD SA flags: 0: Sep 21 07:25:33.350666: | -> QUICK_R2 EVENT_SA_REPLACE Sep 21 07:25:33.350668: | QUICK_I2: category: established CHILD SA flags: 200: Sep 21 07:25:33.350669: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350671: | QUICK_R2: category: established CHILD SA flags: 0: Sep 21 07:25:33.350672: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350674: | INFO: category: informational flags: 0: Sep 21 07:25:33.350675: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350677: | INFO_PROTECTED: category: informational flags: 0: Sep 21 07:25:33.350678: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350680: | XAUTH_R0: category: established IKE SA flags: 0: Sep 21 07:25:33.350681: | -> XAUTH_R1 EVENT_NULL Sep 21 07:25:33.350683: | XAUTH_R1: category: established IKE SA flags: 0: Sep 21 07:25:33.350684: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:25:33.350686: | MODE_CFG_R0: category: informational flags: 0: Sep 21 07:25:33.350687: | -> MODE_CFG_R1 EVENT_SA_REPLACE Sep 21 07:25:33.350689: | MODE_CFG_R1: category: established IKE SA flags: 0: Sep 21 07:25:33.350690: | -> MODE_CFG_R2 EVENT_SA_REPLACE Sep 21 07:25:33.350692: | MODE_CFG_R2: category: established IKE SA flags: 0: Sep 21 07:25:33.350693: | -> UNDEFINED EVENT_NULL Sep 21 07:25:33.350695: | MODE_CFG_I1: category: established IKE SA flags: 0: Sep 21 07:25:33.350696: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:25:33.350698: | XAUTH_I0: category: established IKE SA flags: 0: Sep 21 07:25:33.350699: | -> XAUTH_I1 EVENT_RETRANSMIT Sep 21 07:25:33.350701: | XAUTH_I1: category: established IKE SA flags: 0: Sep 21 07:25:33.350702: | -> MAIN_I4 EVENT_RETRANSMIT Sep 21 07:25:33.350707: | checking IKEv2 state table Sep 21 07:25:33.350711: | PARENT_I0: category: ignore flags: 0: Sep 21 07:25:33.350713: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) Sep 21 07:25:33.350715: | PARENT_I1: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350717: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) Sep 21 07:25:33.350718: | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) Sep 21 07:25:33.350720: | PARENT_I2: category: open IKE SA flags: 0: Sep 21 07:25:33.350722: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) Sep 21 07:25:33.350723: | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) Sep 21 07:25:33.350725: | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) Sep 21 07:25:33.350727: | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) Sep 21 07:25:33.350728: | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) Sep 21 07:25:33.350730: | PARENT_I3: category: established IKE SA flags: 0: Sep 21 07:25:33.350732: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) Sep 21 07:25:33.350733: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) Sep 21 07:25:33.350735: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) Sep 21 07:25:33.350736: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) Sep 21 07:25:33.350738: | PARENT_R0: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350740: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) Sep 21 07:25:33.350741: | PARENT_R1: category: half-open IKE SA flags: 0: Sep 21 07:25:33.350743: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) Sep 21 07:25:33.350745: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) Sep 21 07:25:33.350747: | PARENT_R2: category: established IKE SA flags: 0: Sep 21 07:25:33.350749: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) Sep 21 07:25:33.350751: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) Sep 21 07:25:33.350752: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) Sep 21 07:25:33.350754: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) Sep 21 07:25:33.350756: | V2_CREATE_I0: category: established IKE SA flags: 0: Sep 21 07:25:33.350757: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) Sep 21 07:25:33.350759: | V2_CREATE_I: category: established IKE SA flags: 0: Sep 21 07:25:33.350761: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) Sep 21 07:25:33.350762: | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: Sep 21 07:25:33.350764: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) Sep 21 07:25:33.350766: | V2_REKEY_IKE_I: category: established IKE SA flags: 0: Sep 21 07:25:33.350767: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) Sep 21 07:25:33.350769: | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: Sep 21 07:25:33.350771: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) Sep 21 07:25:33.350773: | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: Sep 21 07:25:33.350774: | V2_CREATE_R: category: established IKE SA flags: 0: Sep 21 07:25:33.350776: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) Sep 21 07:25:33.350778: | V2_REKEY_IKE_R: category: established IKE SA flags: 0: Sep 21 07:25:33.350779: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) Sep 21 07:25:33.350781: | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: Sep 21 07:25:33.350797: | V2_IPSEC_I: category: established CHILD SA flags: 0: Sep 21 07:25:33.350802: | V2_IPSEC_R: category: established CHILD SA flags: 0: Sep 21 07:25:33.350804: | IKESA_DEL: category: established IKE SA flags: 0: Sep 21 07:25:33.350806: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) Sep 21 07:25:33.350820: | CHILDSA_DEL: category: informational flags: 0: Sep 21 07:25:33.350829: Using Linux XFRM/NETKEY IPsec interface code on 5.2.11+ Sep 21 07:25:33.350878: | Hard-wiring algorithms Sep 21 07:25:33.350880: | adding AES_CCM_16 to kernel algorithm db Sep 21 07:25:33.350883: | adding AES_CCM_12 to kernel algorithm db Sep 21 07:25:33.350885: | adding AES_CCM_8 to kernel algorithm db Sep 21 07:25:33.350886: | adding 3DES_CBC to kernel algorithm db Sep 21 07:25:33.350888: | adding CAMELLIA_CBC to kernel algorithm db Sep 21 07:25:33.350889: | adding AES_GCM_16 to kernel algorithm db Sep 21 07:25:33.350891: | adding AES_GCM_12 to kernel algorithm db Sep 21 07:25:33.350892: | adding AES_GCM_8 to kernel algorithm db Sep 21 07:25:33.350894: | adding AES_CTR to kernel algorithm db Sep 21 07:25:33.350895: | adding AES_CBC to kernel algorithm db Sep 21 07:25:33.350897: | adding SERPENT_CBC to kernel algorithm db Sep 21 07:25:33.350898: | adding TWOFISH_CBC to kernel algorithm db Sep 21 07:25:33.350900: | adding NULL_AUTH_AES_GMAC to kernel algorithm db Sep 21 07:25:33.350901: | adding NULL to kernel algorithm db Sep 21 07:25:33.350903: | adding CHACHA20_POLY1305 to kernel algorithm db Sep 21 07:25:33.350904: | adding HMAC_MD5_96 to kernel algorithm db Sep 21 07:25:33.350906: | adding HMAC_SHA1_96 to kernel algorithm db Sep 21 07:25:33.350907: | adding HMAC_SHA2_512_256 to kernel algorithm db Sep 21 07:25:33.350909: | adding HMAC_SHA2_384_192 to kernel algorithm db Sep 21 07:25:33.350910: | adding HMAC_SHA2_256_128 to kernel algorithm db Sep 21 07:25:33.350912: | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db Sep 21 07:25:33.350913: | adding AES_XCBC_96 to kernel algorithm db Sep 21 07:25:33.350915: | adding AES_CMAC_96 to kernel algorithm db Sep 21 07:25:33.350916: | adding NONE to kernel algorithm db Sep 21 07:25:33.350934: | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes Sep 21 07:25:33.350938: | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds Sep 21 07:25:33.350939: | setup kernel fd callback Sep 21 07:25:33.350941: | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x55d7e736fcb0 Sep 21 07:25:33.350944: | libevent_malloc: new ptr-libevent@0x55d7e737bdd0 size 128 Sep 21 07:25:33.350945: | libevent_malloc: new ptr-libevent@0x55d7e736ef90 size 16 Sep 21 07:25:33.350950: | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x55d7e736fc70 Sep 21 07:25:33.350951: | libevent_malloc: new ptr-libevent@0x55d7e737be60 size 128 Sep 21 07:25:33.350953: | libevent_malloc: new ptr-libevent@0x55d7e736efb0 size 16 Sep 21 07:25:33.351087: | global one-shot timer EVENT_CHECK_CRLS initialized Sep 21 07:25:33.351093: selinux support is enabled. Sep 21 07:25:33.351155: systemd watchdog not enabled - not sending watchdog keepalives Sep 21 07:25:33.351294: | unbound context created - setting debug level to 5 Sep 21 07:25:33.351313: | /etc/hosts lookups activated Sep 21 07:25:33.351323: | /etc/resolv.conf usage activated Sep 21 07:25:33.351355: | outgoing-port-avoid set 0-65535 Sep 21 07:25:33.351371: | outgoing-port-permit set 32768-60999 Sep 21 07:25:33.351372: | Loading dnssec root key from:/var/lib/unbound/root.key Sep 21 07:25:33.351375: | No additional dnssec trust anchors defined via dnssec-trusted= option Sep 21 07:25:33.351376: | Setting up events, loop start Sep 21 07:25:33.351378: | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x55d7e736a290 Sep 21 07:25:33.351380: | libevent_malloc: new ptr-libevent@0x55d7e73863d0 size 128 Sep 21 07:25:33.351382: | libevent_malloc: new ptr-libevent@0x55d7e7386460 size 16 Sep 21 07:25:33.351387: | libevent_realloc: new ptr-libevent@0x55d7e72ea5b0 size 256 Sep 21 07:25:33.351389: | libevent_malloc: new ptr-libevent@0x55d7e7386480 size 8 Sep 21 07:25:33.351391: | libevent_realloc: new ptr-libevent@0x55d7e737b1d0 size 144 Sep 21 07:25:33.351392: | libevent_malloc: new ptr-libevent@0x55d7e73864a0 size 152 Sep 21 07:25:33.351395: | libevent_malloc: new ptr-libevent@0x55d7e7386540 size 16 Sep 21 07:25:33.351397: | signal event handler PLUTO_SIGCHLD installed Sep 21 07:25:33.351399: | libevent_malloc: new ptr-libevent@0x55d7e7386560 size 8 Sep 21 07:25:33.351401: | libevent_malloc: new ptr-libevent@0x55d7e7386580 size 152 Sep 21 07:25:33.351403: | signal event handler PLUTO_SIGTERM installed Sep 21 07:25:33.351404: | libevent_malloc: new ptr-libevent@0x55d7e7386620 size 8 Sep 21 07:25:33.351406: | libevent_malloc: new ptr-libevent@0x55d7e7386640 size 152 Sep 21 07:25:33.351408: | signal event handler PLUTO_SIGHUP installed Sep 21 07:25:33.351409: | libevent_malloc: new ptr-libevent@0x55d7e73866e0 size 8 Sep 21 07:25:33.351411: | libevent_realloc: release ptr-libevent@0x55d7e737b1d0 Sep 21 07:25:33.351413: | libevent_realloc: new ptr-libevent@0x55d7e7386700 size 256 Sep 21 07:25:33.351414: | libevent_malloc: new ptr-libevent@0x55d7e737b1d0 size 152 Sep 21 07:25:33.351416: | signal event handler PLUTO_SIGSYS installed Sep 21 07:25:33.351662: | created addconn helper (pid:11146) using fork+execve Sep 21 07:25:33.351674: | forked child 11146 Sep 21 07:25:33.351703: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.351715: | pluto_sd: executing action action: reloading(4), status 0 Sep 21 07:25:33.351719: listening for IKE messages Sep 21 07:25:33.351753: | Inspecting interface lo Sep 21 07:25:33.351757: | found lo with address 127.0.0.1 Sep 21 07:25:33.351759: | Inspecting interface eth0 Sep 21 07:25:33.351762: | found eth0 with address 192.0.3.254 Sep 21 07:25:33.351764: | Inspecting interface eth1 Sep 21 07:25:33.351766: | found eth1 with address 192.1.3.33 Sep 21 07:25:33.351811: Kernel supports NIC esp-hw-offload Sep 21 07:25:33.351827: adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.3.33:500 Sep 21 07:25:33.351845: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:25:33.351851: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:25:33.351854: adding interface eth1/eth1 192.1.3.33:4500 Sep 21 07:25:33.351874: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.3.254:500 Sep 21 07:25:33.351890: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:25:33.351893: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:25:33.351895: adding interface eth0/eth0 192.0.3.254:4500 Sep 21 07:25:33.351913: adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 Sep 21 07:25:33.351930: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:25:33.351932: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:25:33.351934: adding interface lo/lo 127.0.0.1:4500 Sep 21 07:25:33.352002: | no interfaces to sort Sep 21 07:25:33.352006: | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations Sep 21 07:25:33.352011: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386a70 Sep 21 07:25:33.352013: | libevent_malloc: new ptr-libevent@0x55d7e7386ab0 size 128 Sep 21 07:25:33.352015: | libevent_malloc: new ptr-libevent@0x55d7e7386b40 size 16 Sep 21 07:25:33.352021: | setup callback for interface lo 127.0.0.1:4500 fd 22 Sep 21 07:25:33.352023: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386b60 Sep 21 07:25:33.352025: | libevent_malloc: new ptr-libevent@0x55d7e7386ba0 size 128 Sep 21 07:25:33.352027: | libevent_malloc: new ptr-libevent@0x55d7e7386c30 size 16 Sep 21 07:25:33.352030: | setup callback for interface lo 127.0.0.1:500 fd 21 Sep 21 07:25:33.352031: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386c50 Sep 21 07:25:33.352033: | libevent_malloc: new ptr-libevent@0x55d7e7386c90 size 128 Sep 21 07:25:33.352034: | libevent_malloc: new ptr-libevent@0x55d7e7386d20 size 16 Sep 21 07:25:33.352037: | setup callback for interface eth0 192.0.3.254:4500 fd 20 Sep 21 07:25:33.352039: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386d40 Sep 21 07:25:33.352041: | libevent_malloc: new ptr-libevent@0x55d7e7386d80 size 128 Sep 21 07:25:33.352042: | libevent_malloc: new ptr-libevent@0x55d7e7386e10 size 16 Sep 21 07:25:33.352045: | setup callback for interface eth0 192.0.3.254:500 fd 19 Sep 21 07:25:33.352047: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386e30 Sep 21 07:25:33.352048: | libevent_malloc: new ptr-libevent@0x55d7e7386e70 size 128 Sep 21 07:25:33.352050: | libevent_malloc: new ptr-libevent@0x55d7e7386f00 size 16 Sep 21 07:25:33.352053: | setup callback for interface eth1 192.1.3.33:4500 fd 18 Sep 21 07:25:33.352054: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386f20 Sep 21 07:25:33.352056: | libevent_malloc: new ptr-libevent@0x55d7e7386f60 size 128 Sep 21 07:25:33.352057: | libevent_malloc: new ptr-libevent@0x55d7e7386ff0 size 16 Sep 21 07:25:33.352060: | setup callback for interface eth1 192.1.3.33:500 fd 17 Sep 21 07:25:33.352064: | certs and keys locked by 'free_preshared_secrets' Sep 21 07:25:33.352066: | certs and keys unlocked by 'free_preshared_secrets' Sep 21 07:25:33.352080: loading secrets from "/etc/ipsec.secrets" Sep 21 07:25:33.352095: | saving Modulus Sep 21 07:25:33.352099: | saving PublicExponent Sep 21 07:25:33.352102: | ignoring PrivateExponent Sep 21 07:25:33.352104: | ignoring Prime1 Sep 21 07:25:33.352106: | ignoring Prime2 Sep 21 07:25:33.352108: | ignoring Exponent1 Sep 21 07:25:33.352110: | ignoring Exponent2 Sep 21 07:25:33.352111: | ignoring Coefficient Sep 21 07:25:33.352113: | ignoring CKAIDNSS Sep 21 07:25:33.352146: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:33.352149: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:33.352151: loaded private key for keyid: PKK_RSA:AQPl33O2P Sep 21 07:25:33.352156: | certs and keys locked by 'process_secret' Sep 21 07:25:33.352160: | certs and keys unlocked by 'process_secret' Sep 21 07:25:33.352163: | pluto_sd: executing action action: ready(5), status 0 Sep 21 07:25:33.352169: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.352177: | spent 0.477 milliseconds in whack Sep 21 07:25:33.387057: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.387075: | pluto_sd: executing action action: reloading(4), status 0 Sep 21 07:25:33.387080: listening for IKE messages Sep 21 07:25:33.387366: | Inspecting interface lo Sep 21 07:25:33.387372: | found lo with address 127.0.0.1 Sep 21 07:25:33.387374: | Inspecting interface eth0 Sep 21 07:25:33.387376: | found eth0 with address 192.0.3.254 Sep 21 07:25:33.387378: | Inspecting interface eth1 Sep 21 07:25:33.387380: | found eth1 with address 192.1.3.33 Sep 21 07:25:33.387449: | no interfaces to sort Sep 21 07:25:33.387457: | libevent_free: release ptr-libevent@0x55d7e7386ab0 Sep 21 07:25:33.387459: | free_event_entry: release EVENT_NULL-pe@0x55d7e7386a70 Sep 21 07:25:33.387461: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386a70 Sep 21 07:25:33.387464: | libevent_malloc: new ptr-libevent@0x55d7e7386ab0 size 128 Sep 21 07:25:33.387469: | setup callback for interface lo 127.0.0.1:4500 fd 22 Sep 21 07:25:33.387471: | libevent_free: release ptr-libevent@0x55d7e7386ba0 Sep 21 07:25:33.387473: | free_event_entry: release EVENT_NULL-pe@0x55d7e7386b60 Sep 21 07:25:33.387475: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386b60 Sep 21 07:25:33.387476: | libevent_malloc: new ptr-libevent@0x55d7e7386ba0 size 128 Sep 21 07:25:33.387479: | setup callback for interface lo 127.0.0.1:500 fd 21 Sep 21 07:25:33.387482: | libevent_free: release ptr-libevent@0x55d7e7386c90 Sep 21 07:25:33.387483: | free_event_entry: release EVENT_NULL-pe@0x55d7e7386c50 Sep 21 07:25:33.387485: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386c50 Sep 21 07:25:33.387486: | libevent_malloc: new ptr-libevent@0x55d7e7386c90 size 128 Sep 21 07:25:33.387489: | setup callback for interface eth0 192.0.3.254:4500 fd 20 Sep 21 07:25:33.387492: | libevent_free: release ptr-libevent@0x55d7e7386d80 Sep 21 07:25:33.387493: | free_event_entry: release EVENT_NULL-pe@0x55d7e7386d40 Sep 21 07:25:33.387495: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386d40 Sep 21 07:25:33.387496: | libevent_malloc: new ptr-libevent@0x55d7e7386d80 size 128 Sep 21 07:25:33.387499: | setup callback for interface eth0 192.0.3.254:500 fd 19 Sep 21 07:25:33.387501: | libevent_free: release ptr-libevent@0x55d7e7386e70 Sep 21 07:25:33.387503: | free_event_entry: release EVENT_NULL-pe@0x55d7e7386e30 Sep 21 07:25:33.387504: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386e30 Sep 21 07:25:33.387506: | libevent_malloc: new ptr-libevent@0x55d7e7386e70 size 128 Sep 21 07:25:33.387509: | setup callback for interface eth1 192.1.3.33:4500 fd 18 Sep 21 07:25:33.387511: | libevent_free: release ptr-libevent@0x55d7e7386f60 Sep 21 07:25:33.387513: | free_event_entry: release EVENT_NULL-pe@0x55d7e7386f20 Sep 21 07:25:33.387514: | add_fd_read_event_handler: new ethX-pe@0x55d7e7386f20 Sep 21 07:25:33.387516: | libevent_malloc: new ptr-libevent@0x55d7e7386f60 size 128 Sep 21 07:25:33.387518: | setup callback for interface eth1 192.1.3.33:500 fd 17 Sep 21 07:25:33.387521: | certs and keys locked by 'free_preshared_secrets' Sep 21 07:25:33.387522: forgetting secrets Sep 21 07:25:33.387530: | certs and keys unlocked by 'free_preshared_secrets' Sep 21 07:25:33.387543: loading secrets from "/etc/ipsec.secrets" Sep 21 07:25:33.387555: | saving Modulus Sep 21 07:25:33.387558: | saving PublicExponent Sep 21 07:25:33.387560: | ignoring PrivateExponent Sep 21 07:25:33.387562: | ignoring Prime1 Sep 21 07:25:33.387564: | ignoring Prime2 Sep 21 07:25:33.387566: | ignoring Exponent1 Sep 21 07:25:33.387567: | ignoring Exponent2 Sep 21 07:25:33.387569: | ignoring Coefficient Sep 21 07:25:33.387571: | ignoring CKAIDNSS Sep 21 07:25:33.387591: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:33.387592: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:33.387595: loaded private key for keyid: PKK_RSA:AQPl33O2P Sep 21 07:25:33.387600: | certs and keys locked by 'process_secret' Sep 21 07:25:33.387608: | certs and keys unlocked by 'process_secret' Sep 21 07:25:33.387612: | pluto_sd: executing action action: ready(5), status 0 Sep 21 07:25:33.387618: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.387625: | spent 0.574 milliseconds in whack Sep 21 07:25:33.388055: | processing signal PLUTO_SIGCHLD Sep 21 07:25:33.388066: | waitpid returned pid 11146 (exited with status 0) Sep 21 07:25:33.388068: | reaped addconn helper child (status 0) Sep 21 07:25:33.388072: | waitpid returned ECHILD (no child processes left) Sep 21 07:25:33.388075: | spent 0.0122 milliseconds in signal handler PLUTO_SIGCHLD Sep 21 07:25:33.446514: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.446534: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:33.446539: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:25:33.446543: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:33.446545: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:25:33.446550: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:33.446558: | Added new connection north-eastnets/0x1 with policy ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:25:33.446562: | No AUTH policy was set - defaulting to RSASIG Sep 21 07:25:33.446583: | ike (phase1) algorithm values: AES_CBC_256-HMAC_SHA2_256-MODP2048 Sep 21 07:25:33.446585: | from whack: got --esp=aes128-sha2_512;modp3072 Sep 21 07:25:33.446595: | ESP/AH string values: AES_CBC_128-HMAC_SHA2_512_256-MODP3072 Sep 21 07:25:33.446598: | counting wild cards for @north is 0 Sep 21 07:25:33.446601: | counting wild cards for @east is 0 Sep 21 07:25:33.446608: | connect_to_host_pair: 192.1.3.33:500 192.1.2.23:500 -> hp@(nil): none Sep 21 07:25:33.446610: | new hp@0x55d7e7353670 Sep 21 07:25:33.446614: added connection description "north-eastnets/0x1" Sep 21 07:25:33.446621: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:25:33.446629: | 192.0.3.0/24===192.1.3.33<192.1.3.33>[@north]...192.1.2.23<192.1.2.23>[@east]===192.0.2.0/24 Sep 21 07:25:33.446635: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.446641: | spent 0.135 milliseconds in whack Sep 21 07:25:33.446674: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.446681: add keyid @north Sep 21 07:25:33.446684: | add pubkey 01 03 e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab Sep 21 07:25:33.446686: | add pubkey 7f ec 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 Sep 21 07:25:33.446687: | add pubkey 93 9e 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 Sep 21 07:25:33.446689: | add pubkey 01 03 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 Sep 21 07:25:33.446690: | add pubkey 10 84 b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 Sep 21 07:25:33.446691: | add pubkey f4 6b 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f Sep 21 07:25:33.446693: | add pubkey 25 b4 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e Sep 21 07:25:33.446694: | add pubkey c8 16 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 Sep 21 07:25:33.446696: | add pubkey cc 92 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 Sep 21 07:25:33.446697: | add pubkey 13 0f 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 Sep 21 07:25:33.446699: | add pubkey 39 f9 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d Sep 21 07:25:33.446700: | add pubkey 9e ca 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 Sep 21 07:25:33.446702: | add pubkey ba 64 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 Sep 21 07:25:33.446703: | add pubkey 9c 85 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 Sep 21 07:25:33.446704: | add pubkey 61 eb 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 Sep 21 07:25:33.446706: | add pubkey 83 c2 d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca Sep 21 07:25:33.446707: | add pubkey f5 38 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 Sep 21 07:25:33.446712: | add pubkey c7 5e a5 99 Sep 21 07:25:33.446732: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:33.446733: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:33.446739: | keyid: *AQPl33O2P Sep 21 07:25:33.446740: | n e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab 7f ec Sep 21 07:25:33.446742: | n 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 93 9e Sep 21 07:25:33.446743: | n 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 01 03 Sep 21 07:25:33.446745: | n 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 10 84 Sep 21 07:25:33.446746: | n b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 f4 6b Sep 21 07:25:33.446748: | n 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f 25 b4 Sep 21 07:25:33.446749: | n 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e c8 16 Sep 21 07:25:33.446750: | n 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 cc 92 Sep 21 07:25:33.446752: | n 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 13 0f Sep 21 07:25:33.446753: | n 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 39 f9 Sep 21 07:25:33.446755: | n 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d 9e ca Sep 21 07:25:33.446756: | n 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 ba 64 Sep 21 07:25:33.446757: | n 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 9c 85 Sep 21 07:25:33.446759: | n 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 61 eb Sep 21 07:25:33.446760: | n 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 83 c2 Sep 21 07:25:33.446762: | n d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca f5 38 Sep 21 07:25:33.446763: | n 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 c7 5e Sep 21 07:25:33.446765: | n a5 99 Sep 21 07:25:33.446766: | e 03 Sep 21 07:25:33.446767: | CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:33.446769: | CKAID 88 aa 7c 5d Sep 21 07:25:33.446774: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.446777: | spent 0.106 milliseconds in whack Sep 21 07:25:33.446813: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.446821: add keyid @east Sep 21 07:25:33.446823: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Sep 21 07:25:33.446824: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Sep 21 07:25:33.446826: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Sep 21 07:25:33.446827: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Sep 21 07:25:33.446829: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Sep 21 07:25:33.446830: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Sep 21 07:25:33.446832: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Sep 21 07:25:33.446833: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Sep 21 07:25:33.446835: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Sep 21 07:25:33.446836: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Sep 21 07:25:33.446837: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Sep 21 07:25:33.446839: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Sep 21 07:25:33.446840: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Sep 21 07:25:33.446842: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Sep 21 07:25:33.446843: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Sep 21 07:25:33.446845: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Sep 21 07:25:33.446846: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Sep 21 07:25:33.446847: | add pubkey 51 51 48 ef Sep 21 07:25:33.446854: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:25:33.446856: | computed rsa CKAID 8a 82 25 f1 Sep 21 07:25:33.446858: | keyid: *AQO9bJbr3 Sep 21 07:25:33.446860: | n bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b e5 16 Sep 21 07:25:33.446863: | n c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 85 7a Sep 21 07:25:33.446865: | n e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c 78 ca Sep 21 07:25:33.446866: | n 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 21 c9 Sep 21 07:25:33.446868: | n f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d d2 67 Sep 21 07:25:33.446869: | n 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 62 cd Sep 21 07:25:33.446871: | n 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce 62 b5 Sep 21 07:25:33.446872: | n af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e bb 23 Sep 21 07:25:33.446873: | n 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d ac 47 Sep 21 07:25:33.446875: | n f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce e0 98 Sep 21 07:25:33.446876: | n 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a 92 b8 Sep 21 07:25:33.446878: | n 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 4d 58 Sep 21 07:25:33.446879: | n 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 5f 56 Sep 21 07:25:33.446881: | n 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 d5 f1 Sep 21 07:25:33.446882: | n 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c 47 cc Sep 21 07:25:33.446883: | n 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 07 8f Sep 21 07:25:33.446885: | n 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 51 51 Sep 21 07:25:33.446886: | n 48 ef Sep 21 07:25:33.446888: | e 03 Sep 21 07:25:33.446889: | CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:25:33.446890: | CKAID 8a 82 25 f1 Sep 21 07:25:33.446895: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.446898: | spent 0.0879 milliseconds in whack Sep 21 07:25:33.446924: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.446930: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:33.446931: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:25:33.446933: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:33.446935: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:25:33.446937: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:33.446940: | Added new connection north-eastnets/0x2 with policy ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:25:33.446942: | No AUTH policy was set - defaulting to RSASIG Sep 21 07:25:33.446952: | ike (phase1) algorithm values: AES_CBC_256-HMAC_SHA2_256-MODP2048 Sep 21 07:25:33.446954: | from whack: got --esp=aes128-sha2_512;modp3072 Sep 21 07:25:33.446962: | ESP/AH string values: AES_CBC_128-HMAC_SHA2_512_256-MODP3072 Sep 21 07:25:33.446965: | counting wild cards for @north is 0 Sep 21 07:25:33.446967: | counting wild cards for @east is 0 Sep 21 07:25:33.446971: | find_host_pair: comparing 192.1.3.33:500 to 192.1.2.23:500 but ignoring ports Sep 21 07:25:33.446974: | connect_to_host_pair: 192.1.3.33:500 192.1.2.23:500 -> hp@0x55d7e7353670: north-eastnets/0x1 Sep 21 07:25:33.446975: added connection description "north-eastnets/0x2" Sep 21 07:25:33.446981: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:25:33.446988: | 192.0.3.0/24===192.1.3.33<192.1.3.33>[@north]...192.1.2.23<192.1.2.23>[@east]===192.0.22.0/24 Sep 21 07:25:33.446995: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.446998: | spent 0.0763 milliseconds in whack Sep 21 07:25:33.447026: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.447032: add keyid @north Sep 21 07:25:33.447034: | unreference key: 0x55d7e72e18f0 @north cnt 1-- Sep 21 07:25:33.447037: | add pubkey 01 03 e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab Sep 21 07:25:33.447038: | add pubkey 7f ec 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 Sep 21 07:25:33.447040: | add pubkey 93 9e 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 Sep 21 07:25:33.447041: | add pubkey 01 03 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 Sep 21 07:25:33.447045: | add pubkey 10 84 b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 Sep 21 07:25:33.447046: | add pubkey f4 6b 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f Sep 21 07:25:33.447048: | add pubkey 25 b4 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e Sep 21 07:25:33.447049: | add pubkey c8 16 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 Sep 21 07:25:33.447051: | add pubkey cc 92 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 Sep 21 07:25:33.447052: | add pubkey 13 0f 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 Sep 21 07:25:33.447053: | add pubkey 39 f9 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d Sep 21 07:25:33.447055: | add pubkey 9e ca 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 Sep 21 07:25:33.447056: | add pubkey ba 64 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 Sep 21 07:25:33.447058: | add pubkey 9c 85 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 Sep 21 07:25:33.447059: | add pubkey 61 eb 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 Sep 21 07:25:33.447061: | add pubkey 83 c2 d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca Sep 21 07:25:33.447062: | add pubkey f5 38 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 Sep 21 07:25:33.447063: | add pubkey c7 5e a5 99 Sep 21 07:25:33.447069: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:33.447071: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:33.447073: | keyid: *AQPl33O2P Sep 21 07:25:33.447075: | n e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab 7f ec Sep 21 07:25:33.447076: | n 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 93 9e Sep 21 07:25:33.447077: | n 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 01 03 Sep 21 07:25:33.447079: | n 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 10 84 Sep 21 07:25:33.447080: | n b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 f4 6b Sep 21 07:25:33.447082: | n 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f 25 b4 Sep 21 07:25:33.447083: | n 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e c8 16 Sep 21 07:25:33.447085: | n 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 cc 92 Sep 21 07:25:33.447086: | n 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 13 0f Sep 21 07:25:33.447087: | n 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 39 f9 Sep 21 07:25:33.447089: | n 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d 9e ca Sep 21 07:25:33.447090: | n 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 ba 64 Sep 21 07:25:33.447092: | n 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 9c 85 Sep 21 07:25:33.447093: | n 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 61 eb Sep 21 07:25:33.447095: | n 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 83 c2 Sep 21 07:25:33.447096: | n d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca f5 38 Sep 21 07:25:33.447097: | n 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 c7 5e Sep 21 07:25:33.447099: | n a5 99 Sep 21 07:25:33.447100: | e 03 Sep 21 07:25:33.447102: | CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:33.447103: | CKAID 88 aa 7c 5d Sep 21 07:25:33.447107: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.447110: | spent 0.0867 milliseconds in whack Sep 21 07:25:33.447137: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:33.447142: add keyid @east Sep 21 07:25:33.447144: | unreference key: 0x55d7e72ea6c0 @east cnt 1-- Sep 21 07:25:33.447146: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Sep 21 07:25:33.447148: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Sep 21 07:25:33.447149: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Sep 21 07:25:33.447151: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Sep 21 07:25:33.447152: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Sep 21 07:25:33.447153: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Sep 21 07:25:33.447155: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Sep 21 07:25:33.447156: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Sep 21 07:25:33.447160: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Sep 21 07:25:33.447161: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Sep 21 07:25:33.447163: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Sep 21 07:25:33.447164: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Sep 21 07:25:33.447166: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Sep 21 07:25:33.447167: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Sep 21 07:25:33.447168: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Sep 21 07:25:33.447170: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Sep 21 07:25:33.447171: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Sep 21 07:25:33.447173: | add pubkey 51 51 48 ef Sep 21 07:25:33.447178: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:25:33.447179: | computed rsa CKAID 8a 82 25 f1 Sep 21 07:25:33.447181: | keyid: *AQO9bJbr3 Sep 21 07:25:33.447183: | n bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b e5 16 Sep 21 07:25:33.447184: | n c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 85 7a Sep 21 07:25:33.447186: | n e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c 78 ca Sep 21 07:25:33.447187: | n 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 21 c9 Sep 21 07:25:33.447188: | n f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d d2 67 Sep 21 07:25:33.447190: | n 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 62 cd Sep 21 07:25:33.447191: | n 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce 62 b5 Sep 21 07:25:33.447193: | n af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e bb 23 Sep 21 07:25:33.447194: | n 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d ac 47 Sep 21 07:25:33.447196: | n f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce e0 98 Sep 21 07:25:33.447197: | n 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a 92 b8 Sep 21 07:25:33.447198: | n 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 4d 58 Sep 21 07:25:33.447200: | n 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 5f 56 Sep 21 07:25:33.447201: | n 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 d5 f1 Sep 21 07:25:33.447203: | n 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c 47 cc Sep 21 07:25:33.447204: | n 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 07 8f Sep 21 07:25:33.447206: | n 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 51 51 Sep 21 07:25:33.447207: | n 48 ef Sep 21 07:25:33.447208: | e 03 Sep 21 07:25:33.447210: | CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:25:33.447211: | CKAID 8a 82 25 f1 Sep 21 07:25:33.447216: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:33.447218: | spent 0.0838 milliseconds in whack Sep 21 07:25:53.371809: | processing global timer EVENT_SHUNT_SCAN Sep 21 07:25:53.371823: | expiring aged bare shunts from shunt table Sep 21 07:25:53.371830: | spent 0.00521 milliseconds in global timer EVENT_SHUNT_SCAN