Bug 1471553
| Summary: | libreswan postquantum preshared key (PPK) support | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Paul Wouters <pwouters> |
| Component: | libreswan | Assignee: | Paul Wouters <pwouters> |
| Status: | CLOSED ERRATA | QA Contact: | Ondrej Moriš <omoris> |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | 7.5 | CC: | jreznik, omoris, pwouters |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | 3.23-3 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-04-10 17:22:34 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Paul Wouters
2017-07-16 21:47:58 UTC
This currently implements draft-fluhrer-qr-ikev2, not its successor draft-ietf-ipsecme-qr-ikev2-00. It also uses private-use values since no IANA code points are available yet. For beta2 we expect to be updated to ipsecme-qr-ikev2-00 and have Early Code points requested at IANA. For testing, see included testing/pluto/*ppk* test cases Successfully verified on all supported architectures. NEW (libreswan-3.23-3.el7) ========================== [ PASS ] :: RESULT: Setup [ PASS ] :: RESULT: PPK static (rsa), insist & insist with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK dynamic (psk), insist & insist with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), insist & insist with incorrect secret (should fail, ppk no) [ PASS ] :: RESULT: PPK static (psk), insist & insist with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), insist & yes with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), insist & propose with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), insist & no with correct secret (should fail, ppk no) [ PASS ] :: RESULT: PPK static (psk), insist & never with correct secret (should fail, ppk no) [ PASS ] :: RESULT: PPK static (psk), propose & propose with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), propose & yes with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), propose & no with correct secret (should pass, ppk no) [ PASS ] :: RESULT: PPK static (psk), propose & never with correct secret (should pass, ppk no) [ PASS ] :: RESULT: PPK static (psk), yes & yes with correct secret (should pass, ppk yes) [ PASS ] :: RESULT: PPK static (psk), yes & no with correct secret (should pass, ppk no) [ PASS ] :: RESULT: PPK static (psk), yes & never with correct secret (should pass, ppk no) [ PASS ] :: RESULT: PPK static (psk), no & no with correct secret (should pass, ppk no) [ PASS ] :: RESULT: PPK static (psk), no & never with correct secret (should pass, ppk no) [ PASS ] :: RESULT: PPK static (psk), never & never with correct secret (should pass, ppk no) [ PASS ] :: RESULT: Cleanup [ PASS ] :: RESULT: /CoreOS/libreswan/Sanity/Multihost-options-ppk For more details see TJ#2302112 and TJ#2300364. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0932 |