May 1 01:52:27 sun charon: 00[DMN] Starting IKEv2 charon daemon (strongSwan 4.6.3) May 1 01:52:27 sun charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts' May 1 01:52:27 sun charon: 00[CFG] loaded ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" from '/etc/ipsec.d/cacerts/strongswanCert.pem' May 1 01:52:27 sun charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts' May 1 01:52:27 sun charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts' May 1 01:52:27 sun charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts' May 1 01:52:27 sun charon: 00[CFG] loading crls from '/etc/ipsec.d/crls' May 1 01:52:27 sun charon: 00[CFG] loading secrets from '/etc/ipsec.secrets' May 1 01:52:27 sun charon: 00[CFG] loaded RSA private key from '/etc/ipsec.d/private/sunKey.pem' May 1 01:52:27 sun charon: 00[KNL] listening on interfaces: May 1 01:52:27 sun charon: 00[KNL] eth0 May 1 01:52:27 sun charon: 00[KNL] 192.168.0.2 May 1 01:52:27 sun charon: 00[KNL] fec0::2 May 1 01:52:27 sun charon: 00[KNL] fe80::fcfd:c0ff:fea8:2 May 1 01:52:27 sun charon: 00[KNL] eth1 May 1 01:52:27 sun charon: 00[KNL] 10.2.0.1 May 1 01:52:27 sun charon: 00[KNL] fec2::1 May 1 01:52:27 sun charon: 00[KNL] fe80::fcfd:aff:fe02:1 May 1 01:52:27 sun charon: 00[DMN] loaded plugins: curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default updown May 1 01:52:27 sun charon: 00[JOB] spawning 16 worker threads May 1 01:52:28 sun charon: 08[CFG] received stroke: add ca 'strongswan' May 1 01:52:28 sun charon: 08[CFG] added ca 'strongswan' May 1 01:52:28 sun charon: 08[CFG] received stroke: add connection 'net-net' May 1 01:52:28 sun charon: 08[CFG] loaded certificate "C=CH, O=Linux strongSwan, CN=sun.strongswan.org" from 'sunCert.pem' May 1 01:52:28 sun charon: 08[CFG] added configuration 'net-net' May 1 01:52:28 sun charon: 08[CFG] received stroke: add connection 'host-host' May 1 01:52:28 sun charon: 08[CFG] loaded certificate "C=CH, O=Linux strongSwan, CN=sun.strongswan.org" from 'sunCert.pem' May 1 01:52:28 sun charon: 08[CFG] added child to existing configuration 'net-net' May 1 01:52:30 sun charon: 03[NET] received packet: from fec0::1[500] to fec0::2[500] May 1 01:52:30 sun charon: 03[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] May 1 01:52:30 sun charon: 03[IKE] fec0::1 is initiating an IKE_SA May 1 01:52:30 sun charon: 03[IKE] sending cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" May 1 01:52:30 sun charon: 03[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(HTTP_CERT_LOOK) CERTREQ N(MULT_AUTH) ] May 1 01:52:30 sun charon: 03[NET] sending packet: from fec0::2[500] to fec0::1[500] May 1 01:52:30 sun charon: 02[NET] received packet: from fec0::1[500] to fec0::2[500] May 1 01:52:30 sun charon: 02[ENC] parsed IKE_AUTH request 1 [ IDi CERT N(INIT_CONTACT) N(HTTP_CERT_LOOK) CERTREQ IDr AUTH SA TSi TSr N(MULT_AUTH) N(EAP_ONLY) ] May 1 01:52:30 sun charon: 02[IKE] received cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" May 1 01:52:30 sun charon: 02[IKE] received hash-and-url for end entity cert "http://ip6-winnetou.strongswan.org/certs/160769ece9ead9c1c4d89c34aa004c3b66402081" May 1 01:52:30 sun charon: 02[CFG] looking for peer configs matching fec0::2[sun.strongswan.org]...fec0::1[moon.strongswan.org] May 1 01:52:30 sun charon: 02[CFG] selected peer config 'net-net' May 1 01:52:30 sun charon: 02[CFG] fetching certificate from 'http://ip6-winnetou.strongswan.org/certs/160769ece9ead9c1c4d89c34aa004c3b66402081' ... May 1 01:52:30 sun charon: 02[CFG] fetched certificate "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" May 1 01:52:30 sun charon: 02[CFG] using certificate "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" May 1 01:52:30 sun charon: 02[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" May 1 01:52:30 sun charon: 02[CFG] checking certificate status of "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" May 1 01:52:31 sun charon: 02[CFG] fetching crl from 'http://ip6-winnetou.org/strongswan.crl' ... May 1 01:52:31 sun charon: 02[LIB] libcurl http request failed: Couldn't resolve host 'ip6-winnetou.org' May 1 01:52:31 sun charon: 02[CFG] crl fetching failed May 1 01:52:31 sun charon: 02[CFG] fetching crl from 'http://crl.strongswan.org/strongswan.crl' ... May 1 01:52:34 sun charon: 09[MGR] ignoring request with ID 1, already processing May 1 01:52:41 sun charon: 02[LIB] libcurl http request failed: connect() timed out! May 1 01:52:41 sun charon: 02[CFG] crl fetching failed May 1 01:52:41 sun charon: 02[CFG] certificate status is not available May 1 01:52:41 sun charon: 02[CFG] reached self-signed root ca with a path length of 0 May 1 01:52:41 sun charon: 02[IKE] authentication of 'moon.strongswan.org' with RSA signature successful May 1 01:52:41 sun charon: 02[IKE] authentication of 'sun.strongswan.org' (myself) with RSA signature successful May 1 01:52:41 sun charon: 02[IKE] IKE_SA net-net[1] established between fec0::2[sun.strongswan.org]...fec0::1[moon.strongswan.org] May 1 01:52:41 sun charon: 02[IKE] scheduling reauthentication in 3292s May 1 01:52:41 sun charon: 02[IKE] maximum IKE_SA lifetime 3472s May 1 01:52:41 sun charon: 02[IKE] sending hash-and-url "http://ip6-winnetou.strongswan.org/certs/442b7162c7a4c27bd0f1076e345c5664bed53c7c" May 1 01:52:41 sun charon: 02[IKE] sending end entity cert "C=CH, O=Linux strongSwan, CN=sun.strongswan.org" May 1 01:52:41 sun charon: 02[IKE] CHILD_SA net-net{1} established with SPIs cb71b923_i c718b293_o and TS 10.2.0.0/16 === 10.1.0.0/16 May 1 01:52:41 sun charon: 02[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH SA TSi TSr N(AUTH_LFT) ] May 1 01:52:41 sun charon: 02[NET] sending packet: from fec0::2[500] to fec0::1[500] May 1 01:52:52 sun charon: 09[NET] received packet: from fec0::1[500] to fec0::2[500] May 1 01:52:52 sun charon: 09[ENC] parsed INFORMATIONAL request 2 [ D ] May 1 01:52:52 sun charon: 09[IKE] received DELETE for IKE_SA net-net[1] May 1 01:52:52 sun charon: 09[IKE] deleting IKE_SA net-net[1] between fec0::2[sun.strongswan.org]...fec0::1[moon.strongswan.org] May 1 01:52:52 sun charon: 09[IKE] IKE_SA deleted May 1 01:52:52 sun charon: 09[ENC] generating INFORMATIONAL response 2 [ ] May 1 01:52:52 sun charon: 09[NET] sending packet: from fec0::2[500] to fec0::1[500] May 1 01:53:04 sun charon: 00[DMN] signal of type SIGINT received. Shutting down