]> git.ipfire.org Git - thirdparty/strongswan.git/commitdiff
testing: Rename public keys in DNSSEC scenarios
authorTobias Brunner <tobias@strongswan.org>
Mon, 15 Apr 2019 16:20:20 +0000 (18:20 +0200)
committerTobias Brunner <tobias@strongswan.org>
Wed, 8 May 2019 12:56:48 +0000 (14:56 +0200)
We will generate PEM-encoded public keys with the script.

12 files changed:
testing/tests/ikev2/net2net-dnssec/hosts/moon/etc/ipsec.conf
testing/tests/ikev2/net2net-dnssec/hosts/moon/etc/ipsec.d/certs/moonPub.pem [moved from testing/tests/ikev2/net2net-dnssec/hosts/moon/etc/ipsec.d/certs/moonPub.der with 100% similarity]
testing/tests/ikev2/net2net-dnssec/hosts/sun/etc/ipsec.conf
testing/tests/ikev2/net2net-dnssec/hosts/sun/etc/ipsec.d/certs/sunPub.pem [moved from testing/tests/ikev2/net2net-dnssec/hosts/sun/etc/ipsec.d/certs/sunPub.der with 100% similarity]
testing/tests/ikev2/rw-dnssec/hosts/moon/etc/ipsec.conf
testing/tests/ikev2/rw-dnssec/hosts/moon/etc/ipsec.d/certs/moonPub.pem [moved from testing/tests/ikev2/rw-dnssec/hosts/moon/etc/ipsec.d/certs/moonPub.der with 100% similarity]
testing/tests/swanctl/rw-dnssec/hosts/carol/etc/swanctl/pubkey/carolPub.pem [moved from testing/tests/swanctl/rw-dnssec/hosts/carol/etc/swanctl/pubkey/carolPub.der with 100% similarity]
testing/tests/swanctl/rw-dnssec/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-dnssec/hosts/dave/etc/swanctl/pubkey/davePub.pem [moved from testing/tests/swanctl/rw-dnssec/hosts/dave/etc/swanctl/pubkey/davePub.der with 100% similarity]
testing/tests/swanctl/rw-dnssec/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-dnssec/hosts/moon/etc/swanctl/pubkey/moonPub.pem [moved from testing/tests/swanctl/rw-dnssec/hosts/moon/etc/swanctl/pubkey/moonPub.der with 100% similarity]
testing/tests/swanctl/rw-dnssec/hosts/moon/etc/swanctl/swanctl.conf

index ea10eb0a3f4dd47f625ce4360df0700a862e583e..a7799439ede6a93895ba6409962ed77bda505a2b 100644 (file)
@@ -9,12 +9,12 @@ conn %default
        keyingtries=1
        keyexchange=ikev2
        mobike=no
-       
+
 conn net-net
        left=PH_IP_MOON
        leftid=moon.strongswan.org
        leftsubnet=10.1.0.0/16
-       leftsigkey=moonPub.der
+       leftsigkey=moonPub.pem
        leftauth=pubkey
        leftfirewall=yes
        right=sun.strongswan.org
index 9e310050d0472e13a6c41480cbbff9263c0317f8..06704e68ac42e215401a4549f31212f289c3b158 100644 (file)
@@ -9,12 +9,12 @@ conn %default
        keyingtries=1
        keyexchange=ikev2
        mobike=no
-       
+
 conn net-net
        left=PH_IP_SUN
        leftid=sun.strongswan.org
        leftsubnet=10.2.0.0/16
-       leftsigkey=sunPub.der
+       leftsigkey=sunPub.pem
        leftauth=pubkey
        leftfirewall=yes
        right=moon.strongswan.org
index 74ddc6e0161079449a04e3f47a7f418c60632f1c..3c5c64cdeb44ad1754027ae43e097f6fd2a27abe 100644 (file)
@@ -2,19 +2,19 @@
 
 config setup
 
-conn %default 
+conn %default
        ikelifetime=60m
        keylife=20m
        rekeymargin=3m
        keyingtries=1
        keyexchange=ikev2
 
-conn rw 
+conn rw
        left=PH_IP_MOON
        leftsubnet=10.1.0.0/16
        leftid=moon.strongswan.org
        leftauth=pubkey
-       leftsigkey=moonPub.der
+       leftsigkey=moonPub.pem
        leftfirewall=yes
        right=%any
        rightauth=pubkey
index edb9710e2a25f6710240b14fd497b1986fdb2512..abcea5c98de862ad1da9be300ac624fda646c0f2 100755 (executable)
@@ -2,13 +2,13 @@ connections {
 
    home {
       local_addrs  = 192.168.0.100
-      remote_addrs = 192.168.0.1 
+      remote_addrs = 192.168.0.1
       vips = 0.0.0.0
 
       local {
          auth = pubkey
          id = carol.strongswan.org
-         pubkeys = carolPub.der
+         pubkeys = carolPub.pem
       }
       remote {
          auth = pubkey
@@ -16,7 +16,7 @@ connections {
       }
       children {
          home {
-            remote_ts = 10.1.0.0/16 
+            remote_ts = 10.1.0.0/16
 
             updown = /usr/local/libexec/ipsec/_updown iptables
             esp_proposals = aes128gcm128-x25519
index b894dc7fbbdfde9bed4f0a99b3effdb54259443f..fe711c12067f0a3590e2d0a35504038d479f3f45 100755 (executable)
@@ -2,13 +2,13 @@ connections {
 
    home {
       local_addrs  = 192.168.0.200
-      remote_addrs = 192.168.0.1 
+      remote_addrs = 192.168.0.1
       vips = 0.0.0.0
 
       local {
          auth = pubkey
          id = dave.strongswan.org
-         pubkeys = davePub.der
+         pubkeys = davePub.pem
       }
       remote {
          auth = pubkey
@@ -16,7 +16,7 @@ connections {
       }
       children {
          home {
-            remote_ts = 10.1.0.0/16 
+            remote_ts = 10.1.0.0/16
 
             updown = /usr/local/libexec/ipsec/_updown iptables
             esp_proposals = aes128gcm128-x25519
index 6b1a2c281d148b196fb0df21cd071907726db1a6..73aabd83c70a6cc614998c06014504e97a7f045f 100755 (executable)
@@ -7,14 +7,14 @@ connections {
       local {
          auth = pubkey
          id = moon.strongswan.org
-         pubkeys = moonPub.der
+         pubkeys = moonPub.pem
       }
       remote {
          auth = pubkey
       }
       children {
          net {
-            local_ts  = 10.1.0.0/16 
+            local_ts  = 10.1.0.0/16
 
             updown = /usr/local/libexec/ipsec/_updown iptables
             esp_proposals = aes128gcm128-x25519