diff options
author | Andreas Steffen <andreas.steffen@strongswan.org> | 2010-01-11 11:20:45 +0100 |
---|---|---|
committer | Andreas Steffen <andreas.steffen@strongswan.org> | 2010-01-11 11:20:45 +0100 |
commit | 8fb389b299af8ef6cf9b4138f641dbd69f985bfc (patch) | |
tree | e9cdd9183c4596e3639a56a186060a0aa386f471 /testing/tests/ikev2/rw-eap-sim-only-radius/description.txt | |
parent | b9790320885b7f48e20cdf2384cf7e989a78ca70 (diff) | |
download | strongswan-8fb389b299af8ef6cf9b4138f641dbd69f985bfc.tar.bz2 strongswan-8fb389b299af8ef6cf9b4138f641dbd69f985bfc.tar.xz |
added ikev2/rw-eap-sim-only-radius scenario
Diffstat (limited to 'testing/tests/ikev2/rw-eap-sim-only-radius/description.txt')
-rw-r--r-- | testing/tests/ikev2/rw-eap-sim-only-radius/description.txt | 14 |
1 files changed, 14 insertions, 0 deletions
diff --git a/testing/tests/ikev2/rw-eap-sim-only-radius/description.txt b/testing/tests/ikev2/rw-eap-sim-only-radius/description.txt new file mode 100644 index 000000000..d50175664 --- /dev/null +++ b/testing/tests/ikev2/rw-eap-sim-only-radius/description.txt @@ -0,0 +1,14 @@ +The roadwarrior <b>carol</b> sets up a connection to gateway <b>moon</b>. +The gateway <b>moon</b> does not send an AUTH payload thus signalling +a mutual <b>EAP-only</b> authentication. +<b>carol</b> then uses the <i>Extensible Authentication Protocol</i> +in association with a <i>GSM Subscriber Identity Module</i> +(<b>EAP-SIM</b>) to authenticate against the gateway <b>moon</b>. +In this scenario, triplets from the file <b>/etc/ipsec.d/triplets.dat</b> +are used instead of a physical SIM card on the client <b>carol</b>. +The gateway forwards all EAP messages to the RADIUS server <b>alice</b> +which also uses a static triplets file. +<p> +The roadwarrior <b>dave</b> sends wrong EAP-SIM triplets. As a consequence +the radius server <b>alice</b> returns an <b>Access-Reject</b> message +and the gateway <b>moon</b> sends back an <b>EAP_FAILURE</b>. |