Re: [strongSwan] question about the EAP-SIM authentication

2009-09-16 Thread Martin Willi
Hi, I found RAND was read from triplet.dat rather than received from Server. On the client, RAND is received from the server. But the client uses the RAND value to look up SRES and KC. The triplet.dat file contains RAND/SRES/KC triplets, on the client the RAND value is the key to look up SRES

[strongSwan] Child SAs fail to re-activate in IKE1 mode

2009-09-16 Thread Beko, Stephen (EXT-Other - DE/Dusseldorf)
Hello, Does anyone recognise this as a known issue. If no solution, shall I enter this into the bugtracker? Re-activation of child SA connections fail after physical Disconnect in IKE1 mode. I have one IKE SA and seven child SAs routed towards one remote peer (in responder mode). The local

Re: [strongSwan] Support for AKA-Identity and AKA-Reauthentication in the EAP-AKA plugin

2009-09-16 Thread Graham Hudspith
Martin, Thanks for your swift reply. I've gone away and read the RFC on EAP-AKA and had a think about what you said. The problem with not supporting AKA-Identity is that it stops everything else (in an EAP-AKA environment) from working. Get AKA-Identity implemented and you do