Raise ALERT_PROPOSAL_MISMATCH_IKE in IKE V1
In IKE V2 StrongSwan raise ALERT_PROPOSAL_MISMATCH_IKE
We currently don't raise such an alert for IKEv1 , and it would make sense to do so.
#1 Updated by Martin Willi over 5 years ago
- Status changed from New to Feedback
- Assignee set to Martin Willi
- Target version set to 5.3.2
Thanks for your patch. I've split it up to individual commits, cleaned it up and made some changes:
While strongSwan sends NO_PROPOSAL_CHOSEN in different situations, only some are actually due to a real proposal mismatch. I'd prefer to raise the alert only if it is actually results from a real proposal mismatch (not for protocol errors or the like).
Further, we should really catch proposal mismatches reported through INFORMATIONAL messages; this is the way most clients will report such errors.
The individual commits are available in the proposal-alerts branch.