diff options
author | Andreas Steffen <andreas.steffen@strongswan.org> | 2007-03-21 22:19:17 +0000 |
---|---|---|
committer | Andreas Steffen <andreas.steffen@strongswan.org> | 2007-03-21 22:19:17 +0000 |
commit | 1eb6a5f4a2a4f1bd02318a4bd68e845e3f5d3130 (patch) | |
tree | dd9c62bab434414081ea3c83d238ff6ddb00ceee | |
parent | d8d948a7e015d33d7834ba78a914e597b98d44ee (diff) | |
download | strongswan-1eb6a5f4a2a4f1bd02318a4bd68e845e3f5d3130.tar.bz2 strongswan-1eb6a5f4a2a4f1bd02318a4bd68e845e3f5d3130.tar.xz |
deleted
11 files changed, 0 insertions, 173 deletions
diff --git a/testing/tests/ikev2/ocsp-timeouts/description.txt b/testing/tests/ikev2/ocsp-timeouts/description.txt deleted file mode 100644 index 9ee5db95b..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/description.txt +++ /dev/null @@ -1,10 +0,0 @@ -This scenario is based on <a href="../ocsp-signer-cert">ikev2/ocsp-signer-cert</a> -and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fetching -by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by -<b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no -OCSP server is listening. Thanks to timeouts the connection can nevertheless -be established successfully by contacting a valid OCSP URI contained in -<b>carol</b>'s certificate. -<p> -As an additional test the OCSP response is delayed by 5 seconds in order to check -the correct handling of retransmitted IKE_AUTH messages. diff --git a/testing/tests/ikev2/ocsp-timeouts/evaltest.dat b/testing/tests/ikev2/ocsp-timeouts/evaltest.dat deleted file mode 100644 index 420ae56e3..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/evaltest.dat +++ /dev/null @@ -1,9 +0,0 @@ -moon::cat /var/log/daemon.log::http post request to.*using libcurl failed::YES -carol::cat /var/log/daemon.log::http post request to.*using libcurl failed::YES -moon::cat /var/log/daemon.log::received valid http response::YES -carol::cat /var/log/daemon.log::received valid http response::YES -moon::cat /var/log/daemon.log::certificate is good::YES -carol::cat /var/log/daemon.log::certificate is good::YES -moon::ipsec status::rw.*ESTABLISHED::YES -carol::ipsec status::home.*ESTABLISHED::YES - diff --git a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.conf b/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.conf deleted file mode 100755 index b53de16e4..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.conf +++ /dev/null @@ -1,28 +0,0 @@ -# /etc/ipsec.conf - strongSwan IPsec configuration file - -config setup - crlcheckinterval=180 - strictcrlpolicy=yes - plutostart=no - -ca strongswan-ca - cacert=strongswanCert.pem - ocspuri2=http://bob.strongswan.org:8800 - auto=add - -conn %default - keyexchange=ikev2 - ikelifetime=60m - keylife=20m - rekeymargin=3m - keyingtries=1 - left=PH_IP_CAROL - leftnexthop=%direct - leftcert=carolCert-ocsp.pem - leftid=carol@strongswan.org - -conn home - right=PH_IP_MOON - rightsubnet=10.1.0.0/16 - rightid=@moon.strongswan.org - auto=add diff --git a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.d/certs/carolCert-ocsp.pem b/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.d/certs/carolCert-ocsp.pem deleted file mode 100644 index aeca7e1db..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.d/certs/carolCert-ocsp.pem +++ /dev/null @@ -1,26 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIEWzCCA0OgAwIBAgIBEzANBgkqhkiG9w0BAQUFADBFMQswCQYDVQQGEwJDSDEZ -MBcGA1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ryb25nU3dhbiBS -b290IENBMB4XDTA3MDIyNTA3NTg1N1oXDTEyMDIyNDA3NTg1N1owVjELMAkGA1UE -BhMCQ0gxGTAXBgNVBAoTEExpbnV4IHN0cm9uZ1N3YW4xDTALBgNVBAsTBE9DU1Ax -HTAbBgNVBAMUFGNhcm9sQHN0cm9uZ3N3YW4ub3JnMIIBIjANBgkqhkiG9w0BAQEF -AAOCAQ8AMIIBCgKCAQEAyO4WxrPomcQSspX+ZnPit3t+tzYE/wi1E8rH3h5aO3e5 -vVZX3YxNvBqge2RPB3oQHrWwWT8vKmqzZNjJUx4bRIqd1JdTRI7L0f6XJHjnrRv8 -G7M2uHe+JbHQKPRT7IefJ4PZ1FEA8SCwKfWs5vk1/w/cabM6DVzzjtWTV9DXKD6J -5rRlvXtJDbhAvI2w8pCC1Gt6H8qjVSb7ItJ+SD3BlW3tq3nBsYFJRL24TyQg+Kdt -kkCRQYirog29q+J59SErjolse59dte+MhNTv+SnVFgpQE9IGEo6yaKMAWLSTv0If -pPr/QaEV9rcsYFmR3RtHc+QaaP0hvDAPMaKdhQMIUwIDAQABo4IBQzCCAT8wCQYD -VR0TBAIwADALBgNVHQ8EBAMCA6gwHQYDVR0OBBYEFDRTWKccFIi95BslK3U92mIQ -2rWGMG0GA1UdIwRmMGSAFF2n3XAGUTJ+57Zts7Xl4GDqLk3voUmkRzBFMQswCQYD -VQQGEwJDSDEZMBcGA1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ry -b25nU3dhbiBSb290IENBggEAMB8GA1UdEQQYMBaBFGNhcm9sQHN0cm9uZ3N3YW4u -b3JnMDsGCCsGAQUFBwEBBC8wLTArBggrBgEFBQcwAYYfaHR0cDovL29jc3Auc3Ry -b25nc3dhbi5vcmc6ODg4MDA5BgNVHR8EMjAwMC6gLKAqhihodHRwOi8vY3JsLnN0 -cm9uZ3N3YW4ub3JnL3N0cm9uZ3N3YW4uY3JsMA0GCSqGSIb3DQEBBQUAA4IBAQAc -1bBYLYcc+js3UsHVk7W17Nr/qoNFzQZJ5Er3RjhNAgzAX1wOTrNgKXztwZde1Alj -o05ZLXUFkB4coQwl7xo7I3EMJPUmSdHoyYyG7c7AgfcL/wwnzz4rWQl74WIZjySc -ON0Ny9vrzbVboktYof/9Yp/+HgeKopfsaIiuNCAwmAWxiYqvDmlxxn16oOXeJFV8 -pFzZMirQ5l7QRD9iuabOdcnBp8ASH+5AbD4KjFQjo5RBVg92LwOkJo3Pf1twI57s -pObrcM4JbHVohDornYQYfr9ymkMxJbqqkEgD8oIip0NFSbziam4ZkwgUlRIMUMU1 -/xsH+BXYZtKJbYjlnyc8 ------END CERTIFICATE----- diff --git a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.d/private/carolKey-ocsp.pem b/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.d/private/carolKey-ocsp.pem deleted file mode 100644 index 603f071d0..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.d/private/carolKey-ocsp.pem +++ /dev/null @@ -1,27 +0,0 @@ ------BEGIN RSA PRIVATE KEY----- -MIIEogIBAAKCAQEAyO4WxrPomcQSspX+ZnPit3t+tzYE/wi1E8rH3h5aO3e5vVZX -3YxNvBqge2RPB3oQHrWwWT8vKmqzZNjJUx4bRIqd1JdTRI7L0f6XJHjnrRv8G7M2 -uHe+JbHQKPRT7IefJ4PZ1FEA8SCwKfWs5vk1/w/cabM6DVzzjtWTV9DXKD6J5rRl -vXtJDbhAvI2w8pCC1Gt6H8qjVSb7ItJ+SD3BlW3tq3nBsYFJRL24TyQg+KdtkkCR -QYirog29q+J59SErjolse59dte+MhNTv+SnVFgpQE9IGEo6yaKMAWLSTv0IfpPr/ -QaEV9rcsYFmR3RtHc+QaaP0hvDAPMaKdhQMIUwIDAQABAoIBAFTGd5+gmpv96TGm -LW8Gp/poRX+BcDw2bUgLf6aMwd9jVV+4RVw5bTbXOSy2ls19x71dRSlyijDoUgZT -nSXPhwu1PIBM1JoRcZeJRjXiOUWFkCoTxBuykeyPiFcvNxWN5y2h6M822iHie9FI -UYomTYzvIT0LnIu00yJJpGAhwhW9BcL+Mo9lfWmhv4I1hXC9RTqZZ4rjPojDeFvL -maZNCk3kX2pxIJ1kG41/PJjg3JD2uEVrvV7SRuOknM+7f3SDtY60/Wnqx8dfBtjJ -hEdIxG+XXEOafdqwEPmmM++6V76uD8Rs1eFrrI4rfK6/H2PjppJCYtQeryug0q+0 -UN2u00kCgYEA5qJOcDSzb7CQAi58yYicYc3ShEbaL75V7G5rlnFg4/G1axU19hXQ -wEPDf87So9hnVroCMewjyDiNgI/OyYK2cv1TABUGAEFAHPzj99jtBT0/R0kX+Jd2 -kPwCU4/T2cHrezwNobrJf010JAvwc52b+U3lWtHxBWeq5KALUVT+BhcCgYEA3wdx -OwVxTf+OBOBcxPPGUcfsKbf9uVTcXFLNRSBbjzRIOR/bIVgUQaBXem2fJJTm1mWN -Yl/U14G5orv9693GKgE5IDAMMrDF7mOsX808o3pcXM04MTAyGmQEDDEO8tgmWzWo -nrYzxe9uBR1tej9IsiEPlD9ZLtWix9C2uV7EcSUCgYBKOrDuMjgSWYxv91BYeOyE -Gf+IbVlqBmOXPg7Ik+MwWioetevxMSJHz0eLyiBHda4E3sc4FB2MIo+AckiG2Ngp -+FiPbTTKPjYJXmds7NeUWRsVsXPSocUactG43VC9BEnrFu/4Pqr9mwsnUuRoAbEi -syx/Z5SgPbZl8RDTc3xyrwKBgBFpB1HQLvQjyvZefV9ymDyyGqF3F3tsQHeEjzmi -OQOI1UqATh7gPVSSK8IG5LF6XjrGWq8fRAI+wjsN6diLy3hj+A2nMoySeCEP7tjb -sKwiVSt5abWNSZv9ysMY4U3bycK9AZjCKHB/LFuB3JX6crZVFl5AQ7oAO2DVzi3S -VAtxAoGALzFZH7o1ZvVJGa23dW7p96G5vgop6Ulp2DLz4Qg6NYIeatZhwX3lls2J -P7ZxmHiECC7zR67xwv5QKjKfg6t/sOKU/bsyp6c3hOWQjcFbWU3AwlO1TeVX9TMG -SmPYcKM+KQ969qKD3aP9MQ+t4FERvlQcBAr0Qun3quN2i3eDkDo= ------END RSA PRIVATE KEY----- diff --git a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.secrets b/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.secrets deleted file mode 100644 index a89065443..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/hosts/carol/etc/ipsec.secrets +++ /dev/null @@ -1,3 +0,0 @@ -# /etc/ipsec.secrets - strongSwan IPsec secrets file - -: RSA carolKey-ocsp.pem diff --git a/testing/tests/ikev2/ocsp-timeouts/hosts/moon/etc/ipsec.conf b/testing/tests/ikev2/ocsp-timeouts/hosts/moon/etc/ipsec.conf deleted file mode 100755 index f3b19d292..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/hosts/moon/etc/ipsec.conf +++ /dev/null @@ -1,27 +0,0 @@ -# /etc/ipsec.conf - strongSwan IPsec configuration file - -config setup - crlcheckinterval=180 - strictcrlpolicy=yes - plutostart=no - -ca strongswan-ca - cacert=strongswanCert.pem - ocspuri2=http://ocsp2.strongswan.org:8880 - auto=add - -conn %default - keyexchange=ikev2 - ikelifetime=60m - keylife=20m - rekeymargin=3m - keyingtries=1 - -conn rw - left=PH_IP_MOON - leftnexthop=%direct - leftcert=moonCert.pem - leftid=@moon.strongswan.org - leftsubnet=10.1.0.0/16 - right=%any - auto=add diff --git a/testing/tests/ikev2/ocsp-timeouts/hosts/winnetou/etc/openssl/ocsp/ocsp.cgi b/testing/tests/ikev2/ocsp-timeouts/hosts/winnetou/etc/openssl/ocsp/ocsp.cgi deleted file mode 100755 index 92aa920aa..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/hosts/winnetou/etc/openssl/ocsp/ocsp.cgi +++ /dev/null @@ -1,14 +0,0 @@ -#!/bin/bash - -cd /etc/openssl - -echo "Content-type: application/ocsp-response" -echo "" - -# simulate a delayed response -sleep 5 - -/usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \ - -rkey ocspKey.pem -rsigner ocspCert.pem \ - -nmin 5 \ - -reqin /dev/stdin -respout /dev/stdout diff --git a/testing/tests/ikev2/ocsp-timeouts/posttest.dat b/testing/tests/ikev2/ocsp-timeouts/posttest.dat deleted file mode 100644 index 220bc2c1d..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/posttest.dat +++ /dev/null @@ -1,4 +0,0 @@ -moon::ipsec stop -carol::ipsec stop -carol::rm /etc/ipsec.d/certs/* -carol::rm /etc/ipsec.d/private/* diff --git a/testing/tests/ikev2/ocsp-timeouts/pretest.dat b/testing/tests/ikev2/ocsp-timeouts/pretest.dat deleted file mode 100644 index d92333d86..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/pretest.dat +++ /dev/null @@ -1,4 +0,0 @@ -moon::ipsec start -carol::ipsec start -carol::sleep 2 -carol::ipsec up home diff --git a/testing/tests/ikev2/ocsp-timeouts/test.conf b/testing/tests/ikev2/ocsp-timeouts/test.conf deleted file mode 100644 index 2b240d895..000000000 --- a/testing/tests/ikev2/ocsp-timeouts/test.conf +++ /dev/null @@ -1,21 +0,0 @@ -#!/bin/bash -# -# This configuration file provides information on the -# UML instances used for this test - -# All UML instances that are required for this test -# -UMLHOSTS="moon carol winnetou" - -# Corresponding block diagram -# -DIAGRAM="m-c-w.png" - -# UML instances on which tcpdump is to be started -# -TCPDUMPHOSTS="" - -# UML instances on which IPsec is started -# Used for IPsec logging purposes -# -IPSECHOSTS="moon carol" |