summaryrefslogtreecommitdiff
path: root/regress/sbin/ipsecctl/ike56.ok
diff options
context:
space:
mode:
Diffstat (limited to 'regress/sbin/ipsecctl/ike56.ok')
-rw-r--r--regress/sbin/ipsecctl/ike56.ok19
1 files changed, 17 insertions, 2 deletions
diff --git a/regress/sbin/ipsecctl/ike56.ok b/regress/sbin/ipsecctl/ike56.ok
index c41b62ec22b..ae63ab58aa7 100644
--- a/regress/sbin/ipsecctl/ike56.ok
+++ b/regress/sbin/ipsecctl/ike56.ok
@@ -3,14 +3,29 @@ C set [peer-127.0.0.1]:Phase=1 force
C set [peer-127.0.0.1]:Address=127.0.0.1 force
C set [peer-127.0.0.1]:Configuration=phase1-peer-127.0.0.1 force
C set [phase1-peer-127.0.0.1]:EXCHANGE_TYPE=ID_PROT force
-C add [phase1-peer-127.0.0.1]:Transforms=AES-SHA-RSA_SIG force
+C add [phase1-peer-127.0.0.1]:Transforms=phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024 force
+C set [phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force
+C set [phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force
+C set [phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force
+C set [phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force
+C set [phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force
+C set [phase1-transform-peer-127.0.0.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force
C set [from-127.0.0.1-to-127.0.0.1]:Phase=2 force
C set [from-127.0.0.1-to-127.0.0.1]:ISAKMP-peer=peer-127.0.0.1 force
C set [from-127.0.0.1-to-127.0.0.1]:Configuration=phase2-from-127.0.0.1-to-127.0.0.1 force
C set [from-127.0.0.1-to-127.0.0.1]:Local-ID=from-127.0.0.1 force
C set [from-127.0.0.1-to-127.0.0.1]:Remote-ID=to-127.0.0.1 force
C set [phase2-from-127.0.0.1-to-127.0.0.1]:EXCHANGE_TYPE=QUICK_MODE force
-C set [phase2-from-127.0.0.1-to-127.0.0.1]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force
+C set [phase2-from-127.0.0.1-to-127.0.0.1]:Suites=phase2-suite-from-127.0.0.1-to-127.0.0.1 force
+C set [phase2-suite-from-127.0.0.1-to-127.0.0.1]:Protocols=phase2-protocol-from-127.0.0.1-to-127.0.0.1 force
+C set [phase2-protocol-from-127.0.0.1-to-127.0.0.1]:PROTOCOL_ID=IPSEC_ESP force
+C set [phase2-protocol-from-127.0.0.1-to-127.0.0.1]:Transforms=phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force
+C set [phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force
+C set [phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force
+C set [phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
+C set [phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
+C set [phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force
+C set [phase2-transform-from-127.0.0.1-to-127.0.0.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force
C set [from-127.0.0.1]:ID-type=IPV4_ADDR force
C set [from-127.0.0.1]:Address=127.0.0.1 force
C set [to-127.0.0.1]:ID-type=IPV4_ADDR force