[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Andrew Cagney
New commits: commit 7bd98957781808205503c7fa44cc6931ac7245d8 Author: Andrew Cagney Date: Fri Feb 8 11:11:57 2019 -0500 shunks: clarify shunk_strsep() So look-ahead parsing is easier. ___ Swan-commit mailing list

Re: [Swan-dev] ikev2-x509-02-eku

2019-02-08 Thread Andrew Cagney
On Fri, 8 Feb 2019 at 00:53, Paul Wouters wrote: > > I suspect andrew’s kvm magic compile invocations to not yet enable IPsec > profiles for nss Yea, it turned out getting it to auto-detect got messy - plutomain.c likes to print the decision. Just tweaking the KVM make line is likely easiest

Re: [Swan-dev] ikev2-x509-02-eku

2019-02-08 Thread Paul Wouters
Yes Sent from mobile device > On Feb 8, 2019, at 19:08, D. Hugh Redelmeier wrote: > > | From: Paul Wouters > > | echo "NSS_HAS_IPSEC_PROFILE" >> Makefile.inc.local > > I don't know how to parse that. Do you mean this? > > echo "NSS_HAS_IPSEC_PROFILE = true" >> Makefile.inc.local >

Re: [Swan-dev] ikev2-x509-02-eku

2019-02-08 Thread D. Hugh Redelmeier
| From: Paul Wouters | echo "NSS_HAS_IPSEC_PROFILE" >> Makefile.inc.local I don't know how to parse that. Do you mean this? echo "NSS_HAS_IPSEC_PROFILE = true" >> Makefile.inc.local ___ Swan-dev mailing list Swan-dev@lists.libreswan.org

[Swan] subnet-to-subnet config

2019-02-08 Thread Alex
Hi, I'm trying to build a subnet-to-subnet VPN with libreswan-3.27 on fedora28 and having some trouble. Should the subnets already exist on the remote networks, or does libreswan create them? When I use the config below, the networks disappear from the routing table and the servers become

[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Paul Wouters
New commits: commit a2c9aa8aca35d2919e44b9365aa6bbda71c6c6d5 Author: Paul Wouters Date: Fri Feb 8 14:47:40 2019 -0500 testing: a few minor test fixups commit bbf07e61edc3ae8f69c21c5ed8f27bc5e8b7d707 Author: Paul Wouters Date: Fri Feb 8 14:47:13 2019 -0500 testing: dnsoe-05 fixup

[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Paul Wouters
New commits: commit 14743da48e7b9424a6c99e43ea2ddbc01cc49c42 Author: Paul Wouters Date: Fri Feb 8 14:37:17 2019 -0500 testing: various updates, mostly related to putting 192.1.2.254 in the clear policy this way stray DNS packets don't trigger an acquire state with ephemeral

[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Andrew Cagney
New commits: commit 82876565c5bd6e20cc9cd3419d64e52ad00d15f7 Author: Andrew Cagney Date: Fri Feb 8 11:11:00 2019 -0500 algparse: update things for the latest round of FIPS changes ___ Swan-commit mailing list Swan-commit@lists.libreswan.org

[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Andrew Cagney
New commits: commit 8b6ac7888ce17616f0b2b928280418fd13371d3f Author: Andrew Cagney Date: Fri Feb 8 10:38:20 2019 -0500 shunks: rename empty_shunk to null_shunk Like for strings, NULL and "" are different. ___ Swan-commit mailing list

Re: [Swan-dev] ikev2-x509-02-eku

2019-02-08 Thread Paul Wouters
On Fri, 8 Feb 2019, D. Hugh Redelmeier wrote: The test is still failing. The same way. So you can try : echo "NSS_HAS_IPSEC_PROFILE" >> Makefile.inc.local Paul ___ Swan-dev mailing list Swan-dev@lists.libreswan.org

[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Andrew Cagney
New commits: commit 50038aaac739546dae50c140d4662cf4c7feade9 Author: Andrew Cagney Date: Fri Feb 8 09:34:14 2019 -0500 algparse: default to IKEv2 ___ Swan-commit mailing list Swan-commit@lists.libreswan.org

[Swan-commit] Changes to ref refs/heads/master

2019-02-08 Thread Andrew Cagney
New commits: commit 155ad7ff6da8046ae5f5338b8932a23dc975c73e Author: Andrew Cagney Date: Fri Feb 8 09:33:21 2019 -0500 testing: delete algparse IKEv1+IKEv2 tests ___ Swan-commit mailing list Swan-commit@lists.libreswan.org

Re: [Swan-dev] match_certs_id()

2019-02-08 Thread Tuomo Soini
On Thu, 7 Feb 2019 22:43:52 -0500 (EST) "D. Hugh Redelmeier" wrote: > | From: Paul Wouters > > | On Thu, 7 Feb 2019, D. Hugh Redelmeier wrote: > | > | > | > > testing/pluto/nss-cert-chain-01-ikev2/OUTPUT/east.pluto.log:1758:"nss-cert-chain" > | > | > #1: EXPECTATION FAILED: cert->next == NULL