diff options
author | Markus Friedl <markus@cvs.openbsd.org> | 2012-09-15 13:18:35 +0000 |
---|---|---|
committer | Markus Friedl <markus@cvs.openbsd.org> | 2012-09-15 13:18:35 +0000 |
commit | e47a66e2bd248d3e09c0500c246ff82235b44ee4 (patch) | |
tree | f180aa98090f027d869a547d60db1324ae135066 /regress/sbin/ipsecctl/ike8.ok | |
parent | 288ff53fc888c3ad61a2f046a3124b06cc61b2ab (diff) |
sync with recent ipsecctl changes/fixes
Diffstat (limited to 'regress/sbin/ipsecctl/ike8.ok')
-rw-r--r-- | regress/sbin/ipsecctl/ike8.ok | 19 |
1 files changed, 17 insertions, 2 deletions
diff --git a/regress/sbin/ipsecctl/ike8.ok b/regress/sbin/ipsecctl/ike8.ok index a79aff6fe83..bd0849627ed 100644 --- a/regress/sbin/ipsecctl/ike8.ok +++ b/regress/sbin/ipsecctl/ike8.ok @@ -3,14 +3,29 @@ C set [peer-192.168.3.1]:Phase=1 force C set [peer-192.168.3.1]:Address=192.168.3.1 force C set [peer-192.168.3.1]:Configuration=phase1-peer-192.168.3.1 force C set [phase1-peer-192.168.3.1]:EXCHANGE_TYPE=ID_PROT force -C add [phase1-peer-192.168.3.1]:Transforms=AES-SHA-RSA_SIG force +C add [phase1-peer-192.168.3.1]:Transforms=phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024 force +C set [phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force +C set [phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force +C set [phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force +C set [phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force +C set [phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase1-transform-peer-192.168.3.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force C set [from-1.1.1.1-to-0.0.0.0/0]:Phase=2 force C set [from-1.1.1.1-to-0.0.0.0/0]:ISAKMP-peer=peer-192.168.3.1 force C set [from-1.1.1.1-to-0.0.0.0/0]:Configuration=phase2-from-1.1.1.1-to-0.0.0.0/0 force C set [from-1.1.1.1-to-0.0.0.0/0]:Local-ID=from-1.1.1.1 force C set [from-1.1.1.1-to-0.0.0.0/0]:Remote-ID=to-0.0.0.0/0 force C set [phase2-from-1.1.1.1-to-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force -C set [phase2-from-1.1.1.1-to-0.0.0.0/0]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [phase2-from-1.1.1.1-to-0.0.0.0/0]:Suites=phase2-suite-from-1.1.1.1-to-0.0.0.0/0 force +C set [phase2-suite-from-1.1.1.1-to-0.0.0.0/0]:Protocols=phase2-protocol-from-1.1.1.1-to-0.0.0.0/0 force +C set [phase2-protocol-from-1.1.1.1-to-0.0.0.0/0]:PROTOCOL_ID=IPSEC_ESP force +C set [phase2-protocol-from-1.1.1.1-to-0.0.0.0/0]:Transforms=phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force +C set [phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force +C set [phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force +C set [phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force +C set [phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force +C set [phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase2-transform-from-1.1.1.1-to-0.0.0.0/0-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force C set [from-1.1.1.1]:ID-type=IPV4_ADDR force C set [from-1.1.1.1]:Address=1.1.1.1 force C set [to-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force |