Re: [strongSwan] Strongswan client support for the XAUTH_PASSCODE attribute

2020-04-16 Thread MN Lists
Hi, Just a short update on this issue. Today I managed to setup a SecurID authenticated IKEv2 tunnel from my Strongswan Linux client to our ScreenOS gateway. I've been struggling a lot with this over the last days mostly because I have limited knowledge of RADIUS and EAP. Anyway after testing d

Re: [strongSwan] Strongswan client support for the XAUTH_PASSCODE attribute

2020-04-01 Thread Noel Kuntze
Hi, AFAIR it doesn't/can't. I'm not sure though. You'd have to check. Kind regards Noel Am 01.04.20 um 19:26 schrieb mnli...@frimail.net: > Hi, > > But the NetworkManager plugin could prompt for a passcode couldn't it? > > Best regards, > > /Mikael > > On 2020-04-01 19:19, Noel Kuntze wrote

Re: [strongSwan] Strongswan client support for the XAUTH_PASSCODE attribute

2020-04-01 Thread Noel Kuntze
Hi, Yw. There's also no support for dynamic prompting for EAP credentials. I envisioned to implement that using VICI some time later. It'd be the natural choice. Switching to IKEv2 won't solve the problem for you right now. Kind regards Noel Am 01.04.20 um 19:10 schrieb Mikael Nordstrom: > OK

Re: [strongSwan] Strongswan client support for the XAUTH_PASSCODE attribute

2020-04-01 Thread mnlists
Hi, But the NetworkManager plugin could prompt for a passcode couldn't it? Best regards, /Mikael On 2020-04-01 19:19, Noel Kuntze wrote: > Hi, > > Yw. > > There's also no support for dynamic prompting for EAP credentials. > I envisioned to implement that using VICI some time later. It'd be th

Re: [strongSwan] Strongswan client support for the XAUTH_PASSCODE attribute

2020-04-01 Thread Noel Kuntze
Hi, There's just no frontend to ask dynamically for such credentials yet. You'd need to implement that, then you can dynamically prompt for the passcode (after hooking up X_CODE the same way as X_USER is). Other than that, there are no provisions for X_CODE or anything else. The code base would

[strongSwan] Strongswan client support for the XAUTH_PASSCODE attribute

2020-04-01 Thread MN Lists
Hi, This is my first message to the list so sorry in advance if the answer is obvious or well-known. Also, sorry if my terminology is messed up, hopefully you will understand my issue. I have a Juniper ScreenOS gateway that does IKEv1 VPNs with RSA and then XAuth authentication towards an RSA