File: description.txt

package info (click to toggle)
freeswan 2.04-11.3
  • links: PTS
  • area: main
  • in suites: sarge
  • size: 23,340 kB
  • ctags: 12,260
  • sloc: ansic: 72,499; sh: 14,497; asm: 3,312; perl: 3,153; xml: 2,961; makefile: 2,702; tcl: 620; exp: 612; pascal: 228; sed: 206; awk: 124; lisp: 3
file content (25 lines) | stat: -rw-r--r-- 1,126 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
This test will succeed if notify_delete-2.00.diff is applied to pluto. This
patch worked without failed HUNKs as of February 6th.

From the Design list:

Expect the test to fail when formally running it; I haven't figured out how to
suppress the variable elements from the ping test I employ (the summary line,
which will almost always vary).

The test uses whack commands to set up a roadwarrior config on east and a
VPN config with an absurdly low keylife (20 seconds) and no rekeying on west.
Once the IPSec SA expires, west shuts down IPSec.    

Using Mathieu's Notify-Delete SA patch - thanks to Ken for porting it to 2.00
- this prompts a Delete SA request for the ISAKMP SA, killing the conn
instance, unrouting the conn, and allowing a clear traffic ping to succeed.

Without Delete SA code, the ping fails, as the peer still has a %trap eroute
in place.

Why the requirement for the low IPSec SA lifetime? It appears that on "ipsec
auto --delete connname", a Delete SA request for the ISAKMP SA gets issued...
but never for the IPSec SA. As a result, the Delete SA is received, but the  
Roadwarrior conn stays up.