[strongSwan] VICI and multiple threads

2017-09-06 Thread Modster, Anthony
Hello ? is the VICI library considered thread safe Can a host use multiple threads to access the library functions.

[strongSwan] revoke certification with out "ipsec restart"

2017-09-06 Thread Nimo
Hi, I'm trying to revoke Windows machine certificate. But it fails as below. Could please someone help me ? I made two machine certificate for Win-A, Win-B. Windows is windows7 and I setup it based on https://wiki.strongswan.org/projects/strongswan/wiki/Win7Certs. strongSwan is 5.5.3 and ipsec.co

Re: [strongSwan] Cannot ping machines on remote local network

2017-09-06 Thread Ric S
Update, I compiled kernel wih xfrm stats and noticed, the error XfrmInStateProtoError, increases by one for each ping, so the issue must be in this area, what could be the cause for this: cat /proc/net/xfrm_stat XfrmInError 0 XfrmInBufferError 0 XfrmInHdrError

Re: [strongSwan] Strongswan as responder only

2017-09-06 Thread Tobias Brunner
Hi Balaji, > Attached is the wireshark of the message sent to the strongswan. Which shows that the peer sends an invalid IKE_SA_INIT message (not even Wireshark will parse it). The first payload is an SA payload, which has 33 (0x22) as next payload (KE payload), but the next payload has 44 (0x2c