RE: Re: [sfs-dev] Nortel Contivity Client with XAuth (Key -ID)
"Vohra, Meenakshi" <[email protected]> Fri, 20 Jun 2003 20:06:04 -0700
| Newsgroups | gmane.network.freeswan.user,gmane.network.freeswan.devel |
|---|---|
| Message-ID | <C1352E2D7153D411B83000508BD69247F002C4@CA-Mail01.CA.iPolicyNet.COM> |
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01C337A2.0D2257D0 Content-Type: text/plain; charset="ISO-8859-1" Actually, I am trying to evaluate Nortel Client with our VPN gateway that supports XAuth. Following are the two observations I have seen so far: Firstly, I am seeing that Contivity Client is sending me the authentication method as pre-shared key instead of expected xauth-presharedkey even though I have selected Authentication option as "Username and Password authentication" on Client Secondly, if I accept the preshared key authentication method in the Aggressive mode message sent by the client, the Gateway's response is not being accepted by Nortel Client even though I took care of the pre-shared key as prf(passphrase, username) as mentioned in this mail and the draft <http://www.globecom.net/ietf/draft/draft-mamros-pskeyext-00.html> Some non-standard attributes are also being sent by the Client. Does the client expects them back ? Any help would be appreciated Thanks, - Meenakshi -----Original Message----- From: Ken Bantoft [mailto:[email protected]] Sent: Friday, June 20, 2003 4:45 AM To: Vohra, Meenakshi Cc: [email protected]; [email protected] Subject: [Users] Re: [sfs-dev] Nortel Contivity Client with XAuth (Key-ID) -----BEGIN PGP SIGNED MESSAGE----- On Thu, 19 Jun 2003, Vohra, Meenakshi wrote: > Hello Everyone, > > I am trying to evaluate the Nortel's Contivity Client evaluation copy with > my gateway. After discovering the user name being sent as hash by Nortel > client which I am able to resolve I am also seeing the client sending > authentication method as pre-shared key. I want to test the client with > XAuth so was wondering if someone could suggest me how to configure > xauth-preshared-key as authentication method on the Nortel Client. So far I > am using Authentication option as Username and password Authentication on > Nortel Client. I don't quite understand what you're trying to do here... but FreeS/WAN doesn't support XAUTH, so if you're trying inter-op, it won't work. - -- Ken Bantoft Super FreeS/WAN Maintainer [email protected] http://www.freeswan.ca PGP Key: finger [email protected] "It is dangerous to be right when the government is wrong." -- Voltaire -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBPvLzvFiWUusaxGxpAQGpJAP/dFAWQSKzKj5qgZfQwbwnG7EIQKt9pQkQ 6vnk5lf7uqcVVi0bhuZSS2mAAkHjVMA/6mjrnFZt73Kv8EfhJN3fiXEpoSCmMVNU 9v2/bhqSnHLkz9wqT+Ai0G5LzeRxzveCxKbAB3Jw71gRcbMs62uU0fgKPjqBOogm Ds9fLtY38JE= =vV5e -----END PGP SIGNATURE----- _______________________________________________ Users mailing list [email protected] http://lists.freeswan.org/mailman/listinfo/users ------_=_NextPart_001_01C337A2.0D2257D0 Content-Type: text/html; charset="ISO-8859-1" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3DISO-8859-1"> <META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version = 5.5.2653.12"> <TITLE>RE: [Users] Re: [sfs-dev] Nortel Contivity Client with XAuth = (Key-ID)</TITLE> </HEAD> <BODY> <BR> <P><FONT SIZE=3D2>Actually, I am trying to evaluate Nortel Client with = our VPN gateway that supports XAuth. Following are the two observations = I have seen so far:</FONT></P> <P><FONT SIZE=3D2>Firstly, I am seeing that Contivity Client is sending = me the authentication method as pre-shared key instead of expected = xauth-presharedkey even though I have selected Authentication option as = "Username and Password authentication" on Client</FONT></P> <P><FONT SIZE=3D2>Secondly, if I accept the preshared key = authentication method in the Aggressive mode message sent by the = client, the Gateway's response is not being accepted by Nortel Client = even though I took care of the pre-shared key as prf(passphrase, = username) as mentioned in this mail and the draft <<A = HREF=3D"http://www.globecom.net/ietf/draft/draft-mamros-pskeyext-00.html= " = TARGET=3D"_blank">http://www.globecom.net/ietf/draft/draft-mamros-pskeye= xt-00.html</A>> </FONT></P> <P><FONT SIZE=3D2>Some non-standard attributes are also being sent by = the Client. Does the client expects them back ?</FONT> </P> <P><FONT SIZE=3D2>Any help would be appreciated</FONT> <BR><FONT SIZE=3D2>Thanks,</FONT> <BR><FONT SIZE=3D2>- Meenakshi</FONT> </P> <P><FONT SIZE=3D2>-----Original Message-----</FONT> <BR><FONT SIZE=3D2>From: Ken Bantoft [<A = HREF=3D"mailto:[email protected]">mailto:[email protected]</A>]</FONT> <BR><FONT SIZE=3D2>Sent: Friday, June 20, 2003 4:45 AM</FONT> <BR><FONT SIZE=3D2>To: Vohra, Meenakshi</FONT> <BR><FONT SIZE=3D2>Cc: [email protected]; = [email protected]</FONT> <BR><FONT SIZE=3D2>Subject: [Users] Re: [sfs-dev] Nortel Contivity = Client with XAuth</FONT> <BR><FONT SIZE=3D2>(Key-ID)</FONT> </P> <BR> <P><FONT SIZE=3D2>-----BEGIN PGP SIGNED MESSAGE-----</FONT> </P> <BR> <P><FONT SIZE=3D2>On Thu, 19 Jun 2003, Vohra, Meenakshi wrote:</FONT> </P> <P><FONT SIZE=3D2>> Hello Everyone,</FONT> <BR><FONT SIZE=3D2>> </FONT> <BR><FONT SIZE=3D2>> I am trying to evaluate the Nortel's Contivity = Client evaluation copy with</FONT> <BR><FONT SIZE=3D2>> my gateway. After discovering the user name = being sent as hash by Nortel</FONT> <BR><FONT SIZE=3D2>> client which I am able to resolve I am also = seeing the client sending</FONT> <BR><FONT SIZE=3D2>> authentication method as pre-shared key. I want = to test the client with</FONT> <BR><FONT SIZE=3D2>> XAuth so was wondering if someone could suggest = me how to configure</FONT> <BR><FONT SIZE=3D2>> xauth-preshared-key as authentication method on = the Nortel Client. So far I</FONT> <BR><FONT SIZE=3D2>> am using Authentication option as Username and = password Authentication on</FONT> <BR><FONT SIZE=3D2>> Nortel Client.</FONT> </P> <P><FONT SIZE=3D2>I don't quite understand what you're trying to do = here... but FreeS/WAN </FONT> <BR><FONT SIZE=3D2>doesn't support XAUTH, so if you're trying inter-op, = it won't work.</FONT> </P> <BR> <BR> <P><FONT SIZE=3D2>- -- </FONT> <BR><FONT SIZE=3D2>Ken = Bantoft  = ; Super FreeS/WAN Maintainer</FONT> <BR><FONT = SIZE=3D2>[email protected] = <A HREF=3D"http://www.freeswan.ca" = TARGET=3D"_blank">http://www.freeswan.ca</A></FONT> <BR><FONT = SIZE=3D2> &nb= sp; &nb= sp; PGP Key: finger [email protected]</FONT> <BR><FONT SIZE=3D2>"It is dangerous to be right when the = government is wrong."</FONT> <BR><FONT = SIZE=3D2> &nb= sp; = -- Voltaire</FONT> </P> <P><FONT SIZE=3D2>-----BEGIN PGP SIGNATURE-----</FONT> <BR><FONT SIZE=3D2>Version: 2.6.3ia</FONT> <BR><FONT SIZE=3D2>Charset: noconv</FONT> </P> <P><FONT = SIZE=3D2>iQCVAwUBPvLzvFiWUusaxGxpAQGpJAP/dFAWQSKzKj5qgZfQwbwnG7EIQKt9pQk= Q</FONT> <BR><FONT = SIZE=3D2>6vnk5lf7uqcVVi0bhuZSS2mAAkHjVMA/6mjrnFZt73Kv8EfhJN3fiXEpoSCmMVN= U</FONT> <BR><FONT = SIZE=3D2>9v2/bhqSnHLkz9wqT+Ai0G5LzeRxzveCxKbAB3Jw71gRcbMs62uU0fgKPjqBOog= m</FONT> <BR><FONT SIZE=3D2>Ds9fLtY38JE=3D</FONT> <BR><FONT SIZE=3D2>=3DvV5e</FONT> <BR><FONT SIZE=3D2>-----END PGP SIGNATURE-----</FONT> </P> <P><FONT = SIZE=3D2>_______________________________________________</FONT> <BR><FONT SIZE=3D2>Users mailing list</FONT> <BR><FONT SIZE=3D2>[email protected]</FONT> <BR><FONT SIZE=3D2><A = HREF=3D"http://lists.freeswan.org/mailman/listinfo/users" = TARGET=3D"_blank">http://lists.freeswan.org/mailman/listinfo/users</A></= FONT> </P> </BODY> </HTML> ------_=_NextPart_001_01C337A2.0D2257D0--