]> git.ipfire.org Git - people/ms/strongswan.git/blob - testing/tests/ikev2-stroke/rw-eap-peap-radius/description.txt
testing: Reorganizing IKEv1 and IKEv2 examples
[people/ms/strongswan.git] / testing / tests / ikev2-stroke / rw-eap-peap-radius / description.txt
1 The roadwarriors <b>carol</b> and <b>dave</b> set up a connection each to gateway <b>moon</b>.
2 At the outset the gateway authenticates itself to the clients by sending an IKEv2
3 <b>RSA signature</b> accompanied by a certificate.
4 <b>carol</b> and <b>dave</b> then set up an <b>EAP-PEAP</b> tunnel each via <b>moon</b> to
5 the FreeRADIUS server <b>alice</b> authenticated by an X.509 AAA certificate.
6 The strong EAP-PEAP tunnel protects the ensuing weak client authentication based on <b>EAP-MD5</b>.
7 <b>carol</b> presents the correct MD5 password and succeeds whereas <b>dave</b> chooses the
8 wrong password and fails.