summaryrefslogtreecommitdiff
path: root/regress
diff options
context:
space:
mode:
authorChristian Weisgerber <naddy@cvs.openbsd.org>2012-07-08 17:54:58 +0000
committerChristian Weisgerber <naddy@cvs.openbsd.org>2012-07-08 17:54:58 +0000
commitcfdab4f6d29b0749325be32609449453ffeeb823 (patch)
tree8936dda4a6d7c36f09fd7fafadc0168b4973e8bc /regress
parent0f08f11d6fb9ebc66ba30a94fe1f6d748f72a208 (diff)
AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAs
Diffstat (limited to 'regress')
-rw-r--r--regress/sbin/ipsecctl/Makefile4
-rw-r--r--regress/sbin/ipsecctl/ek2241
-rw-r--r--regress/sbin/ipsecctl/ek2561
-rw-r--r--regress/sbin/ipsecctl/ek2881
-rw-r--r--regress/sbin/ipsecctl/sa11.in5
-rw-r--r--regress/sbin/ipsecctl/sa11.ok6
-rw-r--r--regress/sbin/ipsecctl/sa18.in4
-rw-r--r--regress/sbin/ipsecctl/sa18.ok6
-rw-r--r--regress/sbin/ipsecctl/sa21.in5
-rw-r--r--regress/sbin/ipsecctl/sa21.ok6
-rw-r--r--regress/sbin/ipsecctl/sa23.in5
-rw-r--r--regress/sbin/ipsecctl/sa23.ok6
-rw-r--r--regress/sbin/ipsecctl/sa6.in4
-rw-r--r--regress/sbin/ipsecctl/sa6.ok6
-rw-r--r--regress/sbin/ipsecctl/sa9.in5
-rw-r--r--regress/sbin/ipsecctl/sa9.ok6
-rw-r--r--regress/sbin/ipsecctl/safail3.in34
-rw-r--r--regress/sbin/ipsecctl/safail3.ok11
18 files changed, 50 insertions, 66 deletions
diff --git a/regress/sbin/ipsecctl/Makefile b/regress/sbin/ipsecctl/Makefile
index 16b298b16be..8f035dcae0a 100644
--- a/regress/sbin/ipsecctl/Makefile
+++ b/regress/sbin/ipsecctl/Makefile
@@ -1,4 +1,4 @@
-# $OpenBSD: Makefile,v 1.58 2010/05/10 02:00:49 krw Exp $
+# $OpenBSD: Makefile,v 1.59 2012/07/08 17:54:57 naddy Exp $
# you can update the *.ok files with: make -i | patch
# TARGETS
@@ -13,7 +13,7 @@ IPSECTESTS+=25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44
IPSECTESTS+=51 52 53 54 55 56 57 58
TCPMD5TESTS=1 2 3
SATESTS=1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
-SAFAIL=1 2
+SAFAIL=1 2 3
IPSECFAIL=1 2 3
IKEFAIL=1 3 4 5 6 8 9 11 12 13 14
IKETESTS=1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
diff --git a/regress/sbin/ipsecctl/ek224 b/regress/sbin/ipsecctl/ek224
new file mode 100644
index 00000000000..1e0a2b8cd78
--- /dev/null
+++ b/regress/sbin/ipsecctl/ek224
@@ -0,0 +1 @@
+eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/ek256 b/regress/sbin/ipsecctl/ek256
new file mode 100644
index 00000000000..aea1d0411b2
--- /dev/null
+++ b/regress/sbin/ipsecctl/ek256
@@ -0,0 +1 @@
+eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/ek288 b/regress/sbin/ipsecctl/ek288
new file mode 100644
index 00000000000..f1c61bbdabb
--- /dev/null
+++ b/regress/sbin/ipsecctl/ek288
@@ -0,0 +1 @@
+eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/sa11.in b/regress/sbin/ipsecctl/sa11.in
index 003f797dc94..26919746485 100644
--- a/regress/sbin/ipsecctl/sa11.in
+++ b/regress/sbin/ipsecctl/sa11.in
@@ -16,11 +16,6 @@ esp transport from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef:0xbeef4ead \
auth hmac-sha1 \
authkey file "DIR/ak160:DIR/ak160" \
enckey file "DIR/ek128:DIR/ek128"
-esp transport from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef:0xbeef5ead \
- enc aesctr \
- auth hmac-sha1 \
- authkey file "DIR/ak160:DIR/ak160" \
- enckey file "DIR/ek160:DIR/ek160"
esp transport from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef:0xbeef6ead \
enc blowfish \
auth hmac-sha1 \
diff --git a/regress/sbin/ipsecctl/sa11.ok b/regress/sbin/ipsecctl/sa11.ok
index e36a9a64276..f42fbc246f3 100644
--- a/regress/sbin/ipsecctl/sa11.ok
+++ b/regress/sbin/ipsecctl/sa11.ok
@@ -22,12 +22,6 @@ esp transport from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef auth hmac-sha1 enc aes \
esp transport from 2.2.2.2 to 1.1.1.4 spi 0xbeef4ead auth hmac-sha1 enc aes \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp transport from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp transport from 2.2.2.2 to 1.1.1.5 spi 0xbeef5ead auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
esp transport from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef auth hmac-sha1 enc blowfish \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/sa18.in b/regress/sbin/ipsecctl/sa18.in
index bb46f29d697..44b82e3c18e 100644
--- a/regress/sbin/ipsecctl/sa18.in
+++ b/regress/sbin/ipsecctl/sa18.in
@@ -13,10 +13,6 @@ esp from 3ffe::4 to 3ffe::10 spi 0x4eadbeef:0xbeef4ead auth hmac-sha1 \
enc aes \
authkey file "DIR/ak160:DIR/ak160" \
enckey file "DIR/ek128:DIR/ek128"
-esp from 3ffe::5 to 3ffe::10 spi 0x5eadbeef:0xbeef5ead auth hmac-sha1 \
- enc aesctr \
- authkey file "DIR/ak160:DIR/ak160" \
- enckey file "DIR/ek160:DIR/ek160"
esp from 3ffe::6 to 3ffe::10 spi 0x6eadbeef:0xbeef6ead auth hmac-sha1 \
enc blowfish \
authkey file "DIR/ak160:DIR/ak160" \
diff --git a/regress/sbin/ipsecctl/sa18.ok b/regress/sbin/ipsecctl/sa18.ok
index fcd33b66376..8c4e7c8ac00 100644
--- a/regress/sbin/ipsecctl/sa18.ok
+++ b/regress/sbin/ipsecctl/sa18.ok
@@ -22,12 +22,6 @@ esp tunnel from 3ffe::4 to 3ffe::10 spi 0x4eadbeef auth hmac-sha1 enc aes \
esp tunnel from 3ffe::10 to 3ffe::4 spi 0xbeef4ead auth hmac-sha1 enc aes \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 3ffe::5 to 3ffe::10 spi 0x5eadbeef auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 3ffe::10 to 3ffe::5 spi 0xbeef5ead auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
esp tunnel from 3ffe::6 to 3ffe::10 spi 0x6eadbeef auth hmac-sha1 enc blowfish \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/sa21.in b/regress/sbin/ipsecctl/sa21.in
index 63c8b64f6ad..4580738beb6 100644
--- a/regress/sbin/ipsecctl/sa21.in
+++ b/regress/sbin/ipsecctl/sa21.in
@@ -16,11 +16,6 @@ esp from 3ffe::4 to 3ffe::10 spi 0x4eadbeef:0xbeef4ead \
auth hmac-sha1 \
authkey file "DIR/ak160:DIR/ak160" \
enckey file "DIR/ek128:DIR/ek128"
-esp from 3ffe::5 to 3ffe::10 spi 0x5eadbeef:0xbeef5ead \
- enc aesctr \
- auth hmac-sha1 \
- authkey file "DIR/ak160:DIR/ak160" \
- enckey file "DIR/ek160:DIR/ek160"
esp from 3ffe::6 to 3ffe::10 spi 0x6eadbeef:0xbeef6ead \
enc blowfish \
auth hmac-sha1 \
diff --git a/regress/sbin/ipsecctl/sa21.ok b/regress/sbin/ipsecctl/sa21.ok
index fcd33b66376..8c4e7c8ac00 100644
--- a/regress/sbin/ipsecctl/sa21.ok
+++ b/regress/sbin/ipsecctl/sa21.ok
@@ -22,12 +22,6 @@ esp tunnel from 3ffe::4 to 3ffe::10 spi 0x4eadbeef auth hmac-sha1 enc aes \
esp tunnel from 3ffe::10 to 3ffe::4 spi 0xbeef4ead auth hmac-sha1 enc aes \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 3ffe::5 to 3ffe::10 spi 0x5eadbeef auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 3ffe::10 to 3ffe::5 spi 0xbeef5ead auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
esp tunnel from 3ffe::6 to 3ffe::10 spi 0x6eadbeef auth hmac-sha1 enc blowfish \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/sa23.in b/regress/sbin/ipsecctl/sa23.in
index 528d88cb488..80655d6f214 100644
--- a/regress/sbin/ipsecctl/sa23.in
+++ b/regress/sbin/ipsecctl/sa23.in
@@ -16,11 +16,6 @@ esp transport from 3ffe::4 to 3ffe::10 spi 0x4eadbeef:0xbeef4ead \
auth hmac-sha1 \
authkey file "DIR/ak160:DIR/ak160" \
enckey file "DIR/ek128:DIR/ek128"
-esp transport from 3ffe::5 to 3ffe::10 spi 0x5eadbeef:0xbeef5ead \
- enc aesctr \
- auth hmac-sha1 \
- authkey file "DIR/ak160:DIR/ak160" \
- enckey file "DIR/ek160:DIR/ek160"
esp transport from 3ffe::6 to 3ffe::10 spi 0x6eadbeef:0xbeef6ead \
enc blowfish \
auth hmac-sha1 \
diff --git a/regress/sbin/ipsecctl/sa23.ok b/regress/sbin/ipsecctl/sa23.ok
index ad2832d7730..7aacf9c7742 100644
--- a/regress/sbin/ipsecctl/sa23.ok
+++ b/regress/sbin/ipsecctl/sa23.ok
@@ -22,12 +22,6 @@ esp transport from 3ffe::4 to 3ffe::10 spi 0x4eadbeef auth hmac-sha1 enc aes \
esp transport from 3ffe::10 to 3ffe::4 spi 0xbeef4ead auth hmac-sha1 enc aes \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp transport from 3ffe::5 to 3ffe::10 spi 0x5eadbeef auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp transport from 3ffe::10 to 3ffe::5 spi 0xbeef5ead auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
esp transport from 3ffe::6 to 3ffe::10 spi 0x6eadbeef auth hmac-sha1 enc blowfish \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/sa6.in b/regress/sbin/ipsecctl/sa6.in
index aa9b4d21b02..919f091063d 100644
--- a/regress/sbin/ipsecctl/sa6.in
+++ b/regress/sbin/ipsecctl/sa6.in
@@ -13,10 +13,6 @@ esp from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef:0xbeef4ead auth hmac-sha1 \
enc aes \
authkey file "DIR/ak160:DIR/ak160" \
enckey file "DIR/ek128:DIR/ek128"
-esp from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef:0xbeef5ead auth hmac-sha1 \
- enc aesctr \
- authkey file "DIR/ak160:DIR/ak160" \
- enckey file "DIR/ek160:DIR/ek160"
esp from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef:0xbeef6ead auth hmac-sha1 \
enc blowfish \
authkey file "DIR/ak160:DIR/ak160" \
diff --git a/regress/sbin/ipsecctl/sa6.ok b/regress/sbin/ipsecctl/sa6.ok
index 51a53803e97..d919433b8f2 100644
--- a/regress/sbin/ipsecctl/sa6.ok
+++ b/regress/sbin/ipsecctl/sa6.ok
@@ -22,12 +22,6 @@ esp tunnel from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef auth hmac-sha1 enc aes \
esp tunnel from 2.2.2.2 to 1.1.1.4 spi 0xbeef4ead auth hmac-sha1 enc aes \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 2.2.2.2 to 1.1.1.5 spi 0xbeef5ead auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
esp tunnel from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef auth hmac-sha1 enc blowfish \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/sa9.in b/regress/sbin/ipsecctl/sa9.in
index cbe9c59eb0d..53ebc2be163 100644
--- a/regress/sbin/ipsecctl/sa9.in
+++ b/regress/sbin/ipsecctl/sa9.in
@@ -16,11 +16,6 @@ esp from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef:0xbeef4ead \
auth hmac-sha1 \
authkey file "DIR/ak160:DIR/ak160" \
enckey file "DIR/ek128:DIR/ek128"
-esp from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef:0xbeef5ead \
- enc aesctr \
- auth hmac-sha1 \
- authkey file "DIR/ak160:DIR/ak160" \
- enckey file "DIR/ek160:DIR/ek160"
esp from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef:0xbeef6ead \
enc blowfish \
auth hmac-sha1 \
diff --git a/regress/sbin/ipsecctl/sa9.ok b/regress/sbin/ipsecctl/sa9.ok
index 99f4ae10c6a..40ca0103a7b 100644
--- a/regress/sbin/ipsecctl/sa9.ok
+++ b/regress/sbin/ipsecctl/sa9.ok
@@ -22,12 +22,6 @@ esp tunnel from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef auth hmac-sha1 enc aes \
esp tunnel from 2.2.2.2 to 1.1.1.4 spi 0xbeef4ead auth hmac-sha1 enc aes \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
-esp tunnel from 2.2.2.2 to 1.1.1.5 spi 0xbeef5ead auth hmac-sha1 enc aesctr \
- authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
- enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
esp tunnel from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef auth hmac-sha1 enc blowfish \
authkey 0xaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
enckey 0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
diff --git a/regress/sbin/ipsecctl/safail3.in b/regress/sbin/ipsecctl/safail3.in
new file mode 100644
index 00000000000..cdb19f2b27f
--- /dev/null
+++ b/regress/sbin/ipsecctl/safail3.in
@@ -0,0 +1,34 @@
+esp from 1.1.1.1 to 2.2.2.2 spi 0x1eadbeef:0xbeef1ead \
+ enc aesctr \
+ authkey file "DIR/ak256:DIR/ak256" \
+ enckey file "DIR/ek160:DIR/ek160"
+esp from 1.1.1.2 to 2.2.2.2 spi 0x2eadbeef:0xbeef2ead \
+ enc aes-128-ctr \
+ authkey file "DIR/ak256:DIR/ak256" \
+ enckey file "DIR/ek160:DIR/ek160"
+esp from 1.1.1.3 to 2.2.2.2 spi 0x3eadbeef:0xbeef3ead \
+ enc aes-192-ctr \
+ authkey file "DIR/ak256:DIR/ak256" \
+ enckey file "DIR/ek224:DIR/ek224"
+esp from 1.1.1.4 to 2.2.2.2 spi 0x4eadbeef:0xbeef4ead \
+ enc aes-256-ctr \
+ authkey file "DIR/ak256:DIR/ak256" \
+ enckey file "DIR/ek288:DIR/ek288"
+esp from 1.1.1.5 to 2.2.2.2 spi 0x5eadbeef:0xbeef5ead \
+ enc aes-128-gcm \
+ enckey file "DIR/ek160:DIR/ek160"
+esp from 1.1.1.6 to 2.2.2.2 spi 0x6eadbeef:0xbeef6ead \
+ enc aes-192-gcm \
+ enckey file "DIR/ek224:DIR/ek224"
+esp from 1.1.1.7 to 2.2.2.2 spi 0x7eadbeef:0xbeef7ead \
+ enc aes-256-gcm \
+ enckey file "DIR/ek288:DIR/ek288"
+esp from 1.1.1.8 to 2.2.2.2 spi 0x8eadbeef:0xbeef8ead \
+ enc aes-128-gmac \
+ enckey file "DIR/ek160:DIR/ek160"
+esp from 1.1.1.9 to 2.2.2.2 spi 0x9eadbeef:0xbeef9ead \
+ enc aes-192-gmac \
+ enckey file "DIR/ek224:DIR/ek224"
+esp from 1.1.1.10 to 2.2.2.2 spi 0xaeadbeef:0xbeefaead \
+ enc aes-256-gmac \
+ enckey file "DIR/ek288:DIR/ek288"
diff --git a/regress/sbin/ipsecctl/safail3.ok b/regress/sbin/ipsecctl/safail3.ok
new file mode 100644
index 00000000000..09aff4e95b5
--- /dev/null
+++ b/regress/sbin/ipsecctl/safail3.ok
@@ -0,0 +1,11 @@
+stdin: 4: aesctr is disallowed with static keys
+stdin: 8: aes-128-ctr is disallowed with static keys
+stdin: 12: aes-192-ctr is disallowed with static keys
+stdin: 16: aes-256-ctr is disallowed with static keys
+stdin: 19: aes-128-gcm is disallowed with static keys
+stdin: 22: aes-192-gcm is disallowed with static keys
+stdin: 25: aes-256-gcm is disallowed with static keys
+stdin: 28: aes-128-gmac is disallowed with static keys
+stdin: 31: aes-192-gmac is disallowed with static keys
+stdin: 34: aes-256-gmac is disallowed with static keys
+ipsecctl: Syntax error in config file: ipsec rules not loaded