Re: [strongSwan] StrongSwan Android App

2014-08-11 Thread Tobias Brunner
Hi Noel, > I just noticed, that the strongSwan app still displays the tunnel as > active, although a CHILD rekey event failed, because of a DH > group/algorithm mismatch. As long as the original CHILD_SA is still established the connection is not broken, so displaying the connection as active is

Re: [strongSwan] Startup with strongSwan 5.2.0

2014-08-11 Thread Prashant Upadhyaya
Hi, I could finally get over this issue. The main problem was that the .so's for the plugins were not building. The following configure line helped me generate the .so's [I had to pass the --target and --host properly] ./configure --with-random-device=/dev/urandom --target=mips64-octeon-linux-

Re: [strongSwan] Charon crash

2014-08-11 Thread Noel Kuntze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello Martin, I don't use RADIUS accounting in this setup, but the plugin is loaded. I think charon follows a wrong code path, which causes the error. Regards, Noel Kuntze GPG Key id: 0x63EC6658 Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F

Re: [strongSwan] IPv6 source addresses marked as deprecated (preferred_lft == 0)

2014-08-11 Thread Martin Willi
Hi Andrej, > Surprisingly, getaddrinfo() started to prefer IPv4 all the time, > All IPv6 addresses set by StrongSwan are now marked as expired, i.e., > "deprecated". Looks like a regression that has been introduced with [1]. You may try to revert that patch to restore the pre-5.2.0 behavior. Pr

Re: [strongSwan] Charon crash

2014-08-11 Thread Martin Willi
Hi Noel, > 31[IKE] DH group ECP_521 inacceptable, requesting ECP_512_BP > 31[IKE] IKE_SA strongswan-app[38] state change: CONNECTING => DESTROYING > 31[DMN] thread 31 received 11 > 31[LIB] dumping 11 stack frame addresses: > 31[LIB] /usr/lib/libpthread.so.0 @ 0x7fed6a5a7000 [0x7fed6a5b64b0] > 3