Feb 29 19:52:49 sun charon: 01[DMN] starting charon (strongSwan Version 4.1.11) Feb 29 19:52:49 sun charon: 01[DMN] integrity test of libstrongswan code Feb 29 19:52:49 sun charon: 01[LIB] TEXT: 0x40026a38 + 140256 = 0x40048e18 Feb 29 19:52:49 sun charon: 01[LIB] RODATA: 0x40048e80 + 40692 = 0x40052d74 Feb 29 19:52:49 sun charon: 01[LIB] SHA-1 HMAC key: strongSwan Version 4.1.11 Feb 29 19:52:49 sun charon: 01[LIB] SHA-1 HMAC sig: ae:de:ef:d1:ab:ff:27:bd:b8:05:33:d3:9a:cf:8c:a2:3b:5d:4f:38 Feb 29 19:52:49 sun charon: 01[DMN] integrity test passed Feb 29 19:52:49 sun charon: 01[CFG] loading ca certificates from '/etc/ipsec.d/cacerts' Feb 29 19:52:49 sun charon: 01[LIB] loading ca certificate file '/etc/ipsec.d/cacerts/strongswanCert.pem' (1346 bytes) Feb 29 19:52:49 sun charon: 01[CFG] loading aa certificates from '/etc/ipsec.d/aacerts' Feb 29 19:52:49 sun charon: 01[CFG] loading attribute certificates from '/etc/ipsec.d/acerts' Feb 29 19:52:49 sun charon: 01[CFG] loading ocsp certificates from '/etc/ipsec.d/ocspcerts' Feb 29 19:52:49 sun charon: 01[CFG] loading crls from '/etc/ipsec.d/crls' Feb 29 19:52:49 sun charon: 01[CFG] loading secrets from "/etc/ipsec.secrets" Feb 29 19:52:49 sun charon: 01[LIB] loading private key file '/etc/ipsec.d/private/sunKey.pem' (1675 bytes) Feb 29 19:52:49 sun charon: 01[CFG] loading control interface modules from '/usr/local/libexec/ipsec/plugins/interfaces' Feb 29 19:52:49 sun charon: 01[CFG] loaded control interface module successfully from libcharon-stroke.so Feb 29 19:52:49 sun charon: 01[CFG] loading backend modules from '/usr/local/libexec/ipsec/plugins/backends' Feb 29 19:52:49 sun charon: 01[CFG] loaded backend module successfully from libcharon-local.so Feb 29 19:52:49 sun charon: 01[KNL] listening on interfaces: Feb 29 19:52:49 sun charon: 01[KNL] eth0 Feb 29 19:52:49 sun charon: 01[KNL] 192.168.0.2 Feb 29 19:52:49 sun charon: 01[KNL] fec0::2 Feb 29 19:52:49 sun charon: 01[KNL] fe80::fcfd:c0ff:fea8:2 Feb 29 19:52:49 sun charon: 01[KNL] eth1 Feb 29 19:52:49 sun charon: 01[KNL] 10.2.0.1 Feb 29 19:52:49 sun charon: 01[KNL] fec2::1 Feb 29 19:52:49 sun charon: 01[KNL] fe80::fcfd:aff:fe02:1 Feb 29 19:52:49 sun charon: 01[LIB] initializing libcurl Feb 29 19:52:49 sun charon: 01[CFG] loading EAP modules from '/usr/local/libexec/ipsec/plugins/eap' Feb 29 19:52:49 sun charon: 01[CFG] loaded EAP method EAP_AKA successfully from libcharon-eapaka.so Feb 29 19:52:49 sun charon: 01[CFG] opening triplet file /etc/ipsec.d/triplets.dat failed: No such file or directory Feb 29 19:52:49 sun charon: 01[CFG] loaded EAP method EAP_SIM successfully from libcharon-eapsim.so Feb 29 19:52:49 sun charon: 01[JOB] spawning 16 worker threads Feb 29 19:52:49 sun charon: 06[CFG] received stroke: add connection 'net-net' Feb 29 19:52:49 sun charon: 06[LIB] loading end entity certificate file '/etc/ipsec.d/certs/sunCert.pem' (1464 bytes) Feb 29 19:52:49 sun charon: 06[CFG] added configuration 'net-net': fec0::2[sun.strongswan.org]...fec0::1[moon.strongswan.org] Feb 29 19:52:49 sun charon: 06[CFG] received stroke: add connection 'host-host' Feb 29 19:52:49 sun charon: 06[LIB] loading end entity certificate file '/etc/ipsec.d/certs/sunCert.pem' (1464 bytes) Feb 29 19:52:49 sun charon: 06[CFG] reusing existing configuration 'net-net' Feb 29 19:52:51 sun charon: 09[NET] received packet: from fec0::1[500] to fec0::2[500] Feb 29 19:52:51 sun charon: 09[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_D_IP) N(NATD_S_IP) ] Feb 29 19:52:51 sun charon: 09[AUD] fec0::1 is initiating an IKE_SA Feb 29 19:52:51 sun charon: 09[IKE] IKE_SA '(unnamed)' state change: CREATED => CONNECTING Feb 29 19:52:52 sun charon: 09[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ ] Feb 29 19:52:52 sun charon: 09[NET] sending packet: from fec0::2[500] to fec0::1[500] Feb 29 19:52:52 sun charon: 07[NET] received packet: from fec0::1[4500] to fec0::2[4500] Feb 29 19:52:52 sun charon: 07[ENC] parsed IKE_AUTH request 1 [ IDi CERTREQ CERT IDr AUTH SA TSi TSr N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_6_ADDR) ] Feb 29 19:52:52 sun charon: 07[CFG] verifying end entity certificate up to trust anchor: Feb 29 19:52:52 sun charon: 07[CFG] subject: 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' Feb 29 19:52:52 sun charon: 07[CFG] issuer: 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA' Feb 29 19:52:52 sun charon: 07[CFG] keyid: d7:0d:bd:46:d5:13:35:19:06:4f:12:f1:00:52:5e:ad:08:02:ca:95 Feb 29 19:52:52 sun charon: 07[CFG] issuer does not enforce a strict crl policy Feb 29 19:52:52 sun charon: 07[LIB] no crl is locally available Feb 29 19:52:52 sun charon: 07[LIB] sending curl request to 'http://crl.strongswan.org/strongswan.crl'... Feb 29 19:52:52 sun charon: 07[LIB] received valid curl response Feb 29 19:52:52 sun charon: 07[CFG] certificate is good Feb 29 19:52:52 sun charon: 07[CFG] going up one step in the certificate trust chain (1) Feb 29 19:52:52 sun charon: 07[CFG] subject: 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA' Feb 29 19:52:52 sun charon: 07[CFG] issuer: 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA' Feb 29 19:52:52 sun charon: 07[CFG] keyid: ae:09:6b:87:b4:48:86:d3:b8:20:97:86:23:da:bd:0e:ae:22:eb:bc Feb 29 19:52:52 sun charon: 07[CFG] reached self-signed root ca Feb 29 19:52:52 sun charon: 07[IKE] authentication of 'moon.strongswan.org' with RSA signature successful Feb 29 19:52:52 sun charon: 07[CFG] found matching config "net-net": sun.strongswan.org...moon.strongswan.org, prio 0 Feb 29 19:52:52 sun charon: 07[IKE] peer supports MOBIKE Feb 29 19:52:52 sun charon: 07[IKE] authentication of 'sun.strongswan.org' (myself) with RSA signature Feb 29 19:52:52 sun charon: 07[IKE] IKE_SA 'net-net' state change: CONNECTING => ESTABLISHED Feb 29 19:52:52 sun charon: 07[IKE] scheduling reauthentication in 3326s Feb 29 19:52:52 sun charon: 07[IKE] maximum IKE_SA lifetime 3506s Feb 29 19:52:52 sun charon: 07[AUD] IKE_SA 'net-net' established between sun.strongswan.org[fec0::2]...[fec0::1]moon.strongswan.org Feb 29 19:52:52 sun charon: 07[AUD] CHILD_SA 'host-host' established successfully Feb 29 19:52:52 sun charon: 07[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_6_ADDR) ] Feb 29 19:52:52 sun charon: 07[NET] sending packet: from fec0::2[4500] to fec0::1[4500] Feb 29 19:52:54 sun charon: 15[NET] received packet: from fec0::1[4500] to fec0::2[4500] Feb 29 19:52:54 sun charon: 15[ENC] parsed INFORMATIONAL request 2 [ D ] Feb 29 19:52:54 sun charon: 15[IKE] deleting IKE_SA on request Feb 29 19:52:54 sun charon: 15[IKE] IKE_SA 'net-net' state change: ESTABLISHED => DELETING Feb 29 19:52:54 sun charon: 15[ENC] generating INFORMATIONAL response 2 [ ] Feb 29 19:52:54 sun charon: 15[NET] sending packet: from fec0::2[4500] to fec0::1[4500] Feb 29 19:52:55 sun charon: 01[DMN] signal of type SIGINT received. Shutting down Feb 29 19:52:55 sun charon: 01[LIB] finalizing libcurl