Re: [Swan] Fail to authenticate trough PAM+radius in version 3.15, same conf working on 3.13

2015-11-14 Thread Paul Wouters
There is a bug fix for that in git that will be in 3.16. Please check GitHub for the patch Sent from my iPhone > On Nov 15, 2015, at 06:26, Antonio Silva wrote: > > Hi, > > I just update libreswan to newest 3.15 from 3.13 but now i can't authenticate > the user using XAUTH with pam+radius wi

Re: [Swan] subnet to subnet IPv6 very slow

2015-11-14 Thread James Fromm
Thank you for testing the scenario and confirming our findings. For now, we're going to run ipv6 in ipv6. The only reason I was trying to use ipv4 for the tunnel is because many of the server providers we've contacted, especially in South America and Asian locations, do not provide any SLA on

[Swan] Fail to authenticate trough PAM+radius in version 3.15, same conf working on 3.13

2015-11-14 Thread Antonio Silva
Hi, I just update libreswan to newest 3.15 from 3.13 but now i can't authenticate the user using XAUTH with pam+radius with the came configuration. Not sure if it could be some issue with some external lib... i'm using debian wheezy - i did all the tricks to install with the newest version

Re: [Swan] subnet to subnet IPv6 very slow

2015-11-14 Thread Tuomo Soini
On Sat, 14 Nov 2015 13:03:50 +0900 Paul Wouters wrote: > You can try esp=aes_gcm128-null which is the fastest good crypto algo > to use but I'm not sure if that is your real problem I don't think that's the problem. There is some huge performance bottleneck in kernel when running ipv6 in ipv4 w

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-14 Thread Tom Robinson
On 14/11/15 22:58, Tuomo Soini wrote: > On Sat, 14 Nov 2015 21:56:54 +1100 > Tom Robinson wrote: > > >> My apologies, I should have said earlier. We're running >> libreswan-3.9-1 on CentOS 5. > > That is all too old version. It doesn't have any support for this > config. Upgrade to 3.13 which i

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-14 Thread Tuomo Soini
On Sat, 14 Nov 2015 21:56:54 +1100 Tom Robinson wrote: > My apologies, I should have said earlier. We're running > libreswan-3.9-1 on CentOS 5. That is all too old version. It doesn't have any support for this config. Upgrade to 3.13 which is last version which will work on centos-5. I'd advic

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-14 Thread Tom Robinson
On 14/11/15 01:50, Matt Rogers wrote: > - Original Message - >> From: "Tom Robinson" >> To: swan@lists.libreswan.org >> Sent: Thursday, November 12, 2015 4:24:10 PM >> Subject: Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA >> authentication failed" >> >> On 12/11/15 0