delete-sa-01 test
Sam Sgro <[email protected]>
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- I've created a UML test which demonstrates Delete SA functionality, delete-sa-01. I know I may not have all the code bits in the right place; the test isn't turned on, and I'm trying to subscribe to the "commit code early" philosophy. Expect the test to fail when formally running it; I haven't figured out how to suppress the variable elements from the ping test I employ (the summary line, which will almost always vary). The test uses whack commands to set up a roadwarrior config on east and a VPN config with an absurdly low keylife (20 seconds) and no rekeying on west. Once the IPSec SA expires, west shuts down IPSec. Using Mathieu's Notify-Delete SA patch - thanks to Ken for porting it to 2.00 - - this prompts a Delete SA request for the ISAKMP SA, killing the conn instance, unrouting the conn, and allowing a clear traffic ping to succeed. Without Delete SA code, the ping fails - the peer never acknowledges the request and still has a %trap eroute in place. Why the requirement for the low IPSec SA lifetime? It appears that on "ipsec auto --delete connname", a Delete SA request for the ISAKMP SA gets issued... but never for the IPSec SA. As a result, the Delete SA is received, but the Roadwarrior conn stays up. Mathieu: given that both SAs are in the process of being deleted, is there a logic to not sending a delete for the IPSec SA as well? - -- Sam Sgro [email protected] -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv Comment: For the matching public key, finger the Reply-To: address. iQCVAwUBPkJM7UOSC4btEQUtAQEohgQAxJcwyoY+q5phc/aQfO7zO8sLsfdH9N7/ QzX5socjvPpvmboz9wsK7lRSVHswIKD/2W0nYthVmdD5UbqUgKxwsQuL0bqrVjXZ oFbbBEuDHlRniqqHzv0vnr7VnGVZ1XXAL+P34/rDODzv7Sv/C318cGN/jvuMw5aG v2mTWFaK7jo= =G3vr -----END PGP SIGNATURE-----