delete-sa-01 test

Sam Sgro <[email protected]>
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----



I've created a UML test which demonstrates Delete SA functionality,
delete-sa-01. I know I may not have all the code bits in the right place; the
test isn't turned on, and I'm trying to subscribe to the "commit code early"  
philosophy. 

Expect the test to fail when formally running it; I haven't figured out how to
suppress the variable elements from the ping test I employ (the summary line,
which will almost always vary).

The test uses whack commands to set up a roadwarrior config on east and a
VPN config with an absurdly low keylife (20 seconds) and no rekeying on west.
Once the IPSec SA expires, west shuts down IPSec.

Using Mathieu's Notify-Delete SA patch - thanks to Ken for porting it to 2.00
- - this prompts a Delete SA request for the ISAKMP SA, killing the conn
instance, unrouting the conn, and allowing a clear traffic ping to succeed. 

Without Delete SA code, the ping fails - the peer never acknowledges the
request and still has a %trap eroute in place. 

Why the requirement for the low IPSec SA lifetime? It appears that on "ipsec
auto --delete connname", a Delete SA request for the ISAKMP SA gets issued...
but never for the IPSec SA. As a result, the Delete SA is received, but the
Roadwarrior conn stays up.

Mathieu: given that both SAs are in the process of being deleted, is there a 
logic to not sending a delete for the IPSec SA as well? 

- -- 
Sam Sgro 
[email protected]


-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: For the matching public key, finger the Reply-To: address.

iQCVAwUBPkJM7UOSC4btEQUtAQEohgQAxJcwyoY+q5phc/aQfO7zO8sLsfdH9N7/
QzX5socjvPpvmboz9wsK7lRSVHswIKD/2W0nYthVmdD5UbqUgKxwsQuL0bqrVjXZ
oFbbBEuDHlRniqqHzv0vnr7VnGVZ1XXAL+P34/rDODzv7Sv/C318cGN/jvuMw5aG
v2mTWFaK7jo=
=G3vr
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.