[Bug 1451091] Re: new upstream version 5.2.2

2016-02-18 Thread Launchpad Bug Tracker
*** This bug is a duplicate of bug 1535951 *** https://bugs.launchpad.net/bugs/1535951 This bug was fixed in the package strongswan - 5.3.5-1ubuntu1 --- strongswan (5.3.5-1ubuntu1) xenial; urgency=medium * debian/{rules,control,libstrongswan-extra-plugins.install} Enable

[Bug 1451091] Re: new upstream version 5.2.2

2016-02-18 Thread Launchpad Bug Tracker
*** This bug is a duplicate of bug 1535951 *** https://bugs.launchpad.net/bugs/1535951 This bug was fixed in the package strongswan - 5.3.5-1ubuntu1 --- strongswan (5.3.5-1ubuntu1) xenial; urgency=medium * debian/{rules,control,libstrongswan-extra-plugins.install} Enable

[Bug 1451091] Re: new upstream version 5.2.2

2016-01-20 Thread Simon Déziel
*** This bug is a duplicate of bug 1535951 *** https://bugs.launchpad.net/bugs/1535951 Marking this bug as a duplicate of LP: #1535951 since Strongswan 5.3.5 should land in Xenial thus addressing the issues mentioned here. ** This bug has been marked a duplicate of bug 1535951 Please

[Bug 1451091] Re: new upstream version 5.2.2

2016-01-20 Thread Simon Déziel
*** This bug is a duplicate of bug 1535951 *** https://bugs.launchpad.net/bugs/1535951 Marking this bug as a duplicate of LP: #1535951 since Strongswan 5.3.5 should land in Xenial thus addressing the issues mentioned here. ** This bug has been marked a duplicate of bug 1535951 Please

[Bug 1451091] Re: new upstream version 5.2.2

2015-07-20 Thread Eric Heydrick
Strongswan 5.3.2 is out now. What would it take to pull it in? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu. https://bugs.launchpad.net/bugs/1451091 Title: new upstream version 5.2.2 To manage notifications

[Bug 1451091] Re: new upstream version 5.2.2

2015-07-20 Thread Eric Heydrick
Strongswan 5.3.2 is out now. What would it take to pull it in? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1451091 Title: new upstream version 5.2.2 To manage notifications about this bug go to:

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-29 Thread Tobias Brunner
Thanks for the example config. The client will encode the identity as FQDN and the server is forced to encode it as keyid (the content will be the same but the type is different). So there won't be a match. Looking at the screenshot I'm not sure how to configure a FQDN in the pfSense GUI, perhaps

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-29 Thread Tobias Brunner
Thanks for the example config. The client will encode the identity as FQDN and the server is forced to encode it as keyid (the content will be the same but the type is different). So there won't be a match. Looking at the screenshot I'm not sure how to configure a FQDN in the pfSense GUI, perhaps

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Summary changed: - new upstream version 5.2.1 + new upstream version 5.2.2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1451091 Title: new upstream version 5.2.2 To manage notifications about

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Summary changed: - new upstream version 5.2.1 + new upstream version 5.2.2 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu. https://bugs.launchpad.net/bugs/1451091 Title: new upstream version 5.2.2 To

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
The current version of Strongswan (5.1.2) does not work with newer versions of pfSense (Strongswan 5.3.2 based). When using IPsec IKEv2/PSK the identity type is now prefixed leftid and rightid for better matching. The change requires at least Strongswan 5.2.2 but newest upstream is 5.3.2.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
The current version of Strongswan (5.1.2) does not work with newer versions of pfSense (Strongswan 5.3.2 based). When using IPsec IKEv2/PSK the identity type is now prefixed leftid and rightid for better matching. The change requires at least Strongswan 5.2.2 but newest upstream is 5.3.2.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Tobias Brunner
The current version of Strongswan (5.1.2) does not work with newer versions of pfSense (Strongswan 5.3.2 based). When using IPsec IKEv2/PSK the identity type is now prefixed leftid and rightid for better matching. Hm, could you elaborate on that? For instance, provide example configs? At a

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Tobias Brunner
The current version of Strongswan (5.1.2) does not work with newer versions of pfSense (Strongswan 5.3.2 based). When using IPsec IKEv2/PSK the identity type is now prefixed leftid and rightid for better matching. Hm, could you elaborate on that? For instance, provide example configs? At a

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
When using PSK in pfSense you are required to select identifier type. Looking at it from a security perspective it seems better to explicit define identifier type rather then auto detect type. ** Attachment added: pfsense_ipsec_keyid.png

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_client.conf https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420799/+files/ipsec_client.conf -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_server.conf https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420800/+files/ipsec_server.conf -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_sever.secrets https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420802/+files/ipsec_sever.secrets -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_client.secrets https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420801/+files/ipsec_client.secrets -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
I have attached an example configuration where the pfSense server leftid is configured with keyid:-prefix and therefor in unable to authenticate an IPsec connection from a client where rightid does not contain keyid:-prefix. -- You received this bug notification because you are a member of

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_sever.secrets https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420802/+files/ipsec_sever.secrets -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_client.conf https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420799/+files/ipsec_client.conf -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
I have attached an example configuration where the pfSense server leftid is configured with keyid:-prefix and therefor in unable to authenticate an IPsec connection from a client where rightid does not contain keyid:-prefix. -- You received this bug notification because you are a member of

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_server.conf https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420800/+files/ipsec_server.conf -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
** Attachment added: ipsec_client.secrets https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1451091/+attachment/4420801/+files/ipsec_client.secrets -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1451091] Re: new upstream version 5.2.2

2015-06-26 Thread Bruno Thomsen
When using PSK in pfSense you are required to select identifier type. Looking at it from a security perspective it seems better to explicit define identifier type rather then auto detect type. ** Attachment added: pfsense_ipsec_keyid.png