Project

General

Profile

Raspi 3 - Initiating IoT Device » History » Version 34

Andreas Steffen, 15.08.2015 22:12

1 14 Andreas Steffen
{{>toc}}
2 14 Andreas Steffen
3 21 Andreas Steffen
h1. Raspi 3 - Initiating IoT Device
4 1 Andreas Steffen
5 14 Andreas Steffen
h2. Configuration Files
6 14 Andreas Steffen
7 1 Andreas Steffen
strongSwan IPsec configuration file */etc/ipsec.conf*
8 1 Andreas Steffen
<pre>
9 1 Andreas Steffen
config setup
10 1 Andreas Steffen
     charondebug="tnc 2, imc 2, imv 2, pts 3"
11 1 Andreas Steffen
12 1 Andreas Steffen
conn %default
13 1 Andreas Steffen
     ike=aes128-sha256-ecp256!
14 1 Andreas Steffen
     esp=aes128-sha256-ecp256!
15 1 Andreas Steffen
     keyexchange=ikev2
16 1 Andreas Steffen
17 1 Andreas Steffen
conn peer
18 1 Andreas Steffen
     left=10.10.1.39
19 1 Andreas Steffen
     leftauth=eap-ttls
20 1 Andreas Steffen
     leftcert=raspi3Cert.pem
21 1 Andreas Steffen
     leftid=raspi3.example.com
22 1 Andreas Steffen
     leftfirewall=yes
23 1 Andreas Steffen
     right=10.10.1.40
24 1 Andreas Steffen
     rightauth=any
25 1 Andreas Steffen
     rightid=raspi4.example.com
26 1 Andreas Steffen
     type=transport
27 1 Andreas Steffen
     auto=add
28 1 Andreas Steffen
</pre>
29 1 Andreas Steffen
30 1 Andreas Steffen
strongSwan IPsec secrets file */etc/ipsec.secrets*
31 1 Andreas Steffen
<pre>
32 1 Andreas Steffen
: RSA raspi3Key.pem
33 1 Andreas Steffen
</pre>
34 1 Andreas Steffen
35 1 Andreas Steffen
strongSwan configuration file */etc/strongswan.conf*
36 1 Andreas Steffen
<pre>
37 1 Andreas Steffen
# strongswan.conf - strongSwan configuration file
38 1 Andreas Steffen
39 1 Andreas Steffen
charon {
40 1 Andreas Steffen
  load = random nonce x509 revocation constraints pkcs1 pkcs8 pem openssl pubkey tnc-imc tnc-imv tnc-tnccs tnccs-20 eap-identity eap-ttls eap-tnc sqlite curl kernel-netlink socket-default updown stroke
41 1 Andreas Steffen
42 1 Andreas Steffen
  half_open_timeout = 90
43 1 Andreas Steffen
44 1 Andreas Steffen
  plugins {
45 1 Andreas Steffen
    eap-ttls
46 1 Andreas Steffen
    {
47 1 Andreas Steffen
      max_message_count = 0
48 1 Andreas Steffen
      request_peer_auth = yes
49 1 Andreas Steffen
      phase2_piggyback = yes
50 1 Andreas Steffen
      phase2_tnc = yes
51 1 Andreas Steffen
    }
52 1 Andreas Steffen
    eap-tnc {
53 1 Andreas Steffen
      max_message_count = 0
54 1 Andreas Steffen
    }
55 1 Andreas Steffen
    tnccs-20 {
56 1 Andreas Steffen
      mutual = yes
57 1 Andreas Steffen
    }
58 1 Andreas Steffen
  }
59 1 Andreas Steffen
}
60 1 Andreas Steffen
61 1 Andreas Steffen
libimcv {
62 1 Andreas Steffen
  database = sqlite:///etc/pts/config.db
63 1 Andreas Steffen
  policy_script = ipsec imv_policy_manager
64 1 Andreas Steffen
65 1 Andreas Steffen
  plugins {
66 1 Andreas Steffen
    imc-os {
67 1 Andreas Steffen
      device_pubkey = /etc/pts/aik3Pub.der
68 1 Andreas Steffen
    }
69 1 Andreas Steffen
    imc-attestation {
70 1 Andreas Steffen
      aik_blob = /etc/pts/aik3Blob.bin
71 1 Andreas Steffen
      aik_cert = /etc/pts/aik3Cert.der
72 1 Andreas Steffen
    }
73 1 Andreas Steffen
    imv-attestation {
74 1 Andreas Steffen
      cadir = /etc/pts/cacerts
75 1 Andreas Steffen
      hash_algorithm = sha1
76 1 Andreas Steffen
    }
77 1 Andreas Steffen
  }
78 1 Andreas Steffen
}
79 1 Andreas Steffen
80 1 Andreas Steffen
libtls {
81 1 Andreas Steffen
  suites = TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
82 1 Andreas Steffen
}
83 1 Andreas Steffen
84 1 Andreas Steffen
pt-tls-client {
85 1 Andreas Steffen
  load = random nonce x509 revocation constraints pkcs1 pkcs8 pem openssl pubkey tnc-imc tnc-imv tnc-tnccs tnccs-20 curl 
86 1 Andreas Steffen
}
87 1 Andreas Steffen
88 1 Andreas Steffen
attest {
89 1 Andreas Steffen
  database=sqlite:///etc/pts/config.db
90 1 Andreas Steffen
}
91 1 Andreas Steffen
</pre>
92 1 Andreas Steffen
93 16 Andreas Steffen
h2. Starting the IKEv2 Daemon
94 14 Andreas Steffen
95 14 Andreas Steffen
First the IKEv2 charon daemon is started in the background
96 1 Andreas Steffen
<pre>
97 17 Andreas Steffen
raspi3# ipsec start
98 14 Andreas Steffen
</pre>
99 14 Andreas Steffen
100 14 Andreas Steffen
<pre>
101 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[DMN] Starting IKE charon daemon (strongSwan 5.3.1, Linux 3.18.13-v7+, armv7l)
102 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] TNC recommendation policy is 'default'
103 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] loading IMVs from '/etc/tnc_config'
104 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] added IETF attributes
105 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] added ITA-HSR attributes
106 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] added TCG attributes
107 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS] added TCG functional component namespace
108 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS] added ITA-HSR functional component namespace
109 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS] added ITA-HSR functional component 'Trusted GRUB Boot Loader'
110 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS] added ITA-HSR functional component 'Trusted Boot'
111 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS] added ITA-HSR functional component 'Linux IMA'
112 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[LIB] libimcv initialized
113 3 Andreas Steffen
</pre>
114 3 Andreas Steffen
115 3 Andreas Steffen
Loading Attestation IMV
116 3 Andreas Steffen
<pre>
117 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[IMV] IMV 1 "Attestation" initialized
118 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS] loading PTS ca certificates from '/etc/pts/cacerts'
119 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   loaded ca certificate "C=US, O=TNC Demo, CN=AIK CA" from '/etc/pts/cacerts/aikCaCert.pem'
120 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   mandatory PTS measurement algorithm HASH_SHA1[openssl] available
121 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   mandatory PTS measurement algorithm HASH_SHA256[openssl] available
122 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS measurement algorithm HASH_SHA384[openssl] available
123 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group MODP_2048[openssl] available
124 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group MODP_1536[openssl] available
125 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group MODP_1024[openssl] available
126 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   mandatory PTS DH group ECP_256[openssl] available
127 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group ECP_384[openssl] available
128 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] IMV 1 supports 2 message types: 'TCG/PTS' 0x005597/0x00000001 'IETF/Operating System' 0x000000/0x00000001
129 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] IMV 1 "Attestation" loaded from '/usr/lib/ipsec/imcvs/imv-attestation.so'
130 3 Andreas Steffen
</pre>
131 3 Andreas Steffen
132 3 Andreas Steffen
Loading OS IMC
133 3 Andreas Steffen
<pre>
134 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] loading IMCs from '/etc/tnc_config'
135 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[IMC] IMC 1 "OS" initialized
136 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[IMC] processing "/etc/debian_version" file
137 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[IMC] operating system name is 'Debian'
138 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[IMC] operating system version is '7.8 armv7l'
139 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] IMC 1 supports 1 message type: 'IETF/Operating System' 0x000000/0x00000001
140 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] IMC 1 "OS" loaded from '/usr/lib/ipsec/imcvs/imc-os.so'
141 3 Andreas Steffen
</pre>
142 3 Andreas Steffen
143 3 Andreas Steffen
Loading Attestation IMC
144 3 Andreas Steffen
<pre>
145 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[IMC] IMC 2 "Attestation" initialized
146 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   mandatory PTS measurement algorithm HASH_SHA1[openssl] available
147 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   mandatory PTS measurement algorithm HASH_SHA256[openssl] available
148 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS measurement algorithm HASH_SHA384[openssl] available
149 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group MODP_2048[openssl] available
150 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group MODP_1536[openssl] available
151 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group MODP_1024[openssl] available
152 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   mandatory PTS DH group ECP_256[openssl] available
153 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[PTS]   optional  PTS DH group ECP_384[openssl] available
154 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] IMC 2 supports 1 message type: 'TCG/PTS' 0x005597/0x00000001
155 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[TNC] IMC 2 "Attestation" loaded from '/usr/lib/ipsec/imcvs/imc-attestation.so'
156 3 Andreas Steffen
</pre>
157 3 Andreas Steffen
158 19 Andreas Steffen
Initializing IKE daemon
159 3 Andreas Steffen
<pre>
160 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
161 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG]   loaded ca certificate "C=US, O=TNC Demo, CN=TNC Demo CA" from '/etc/ipsec.d/cacerts/demoCaCert.pem'
162 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
163 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
164 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
165 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG] loading crls from '/etc/ipsec.d/crls'
166 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG] loading secrets from '/etc/ipsec.secrets'
167 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[CFG]   loaded RSA private key from '/etc/ipsec.d/private/raspi3Key.pem'
168 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[LIB] loaded plugins: charon random nonce x509 revocation constraints pkcs1 pkcs8 pem openssl pubkey tnc-imc tnc-imv tnc-tnccs tnccs-20 eap-identity eap-ttls eap-tnc sqlite curl kernel-netlink socket-default updown stroke
169 1 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 00[JOB] spawning 16 worker threads
170 19 Andreas Steffen
</pre>
171 19 Andreas Steffen
172 19 Andreas Steffen
Loading *peer* IPsec connection
173 19 Andreas Steffen
<pre>
174 2 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 06[CFG] received stroke: add connection 'peer'
175 3 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 06[CFG]   loaded certificate "C=US, O=TNC Demo, CN=raspi3.example.com" from 'raspi3Cert.pem'
176 3 Andreas Steffen
Aug 15 14:45:55 raspi3 charon: 06[CFG] added configuration 'peer'
177 1 Andreas Steffen
</pre>
178 1 Andreas Steffen
179 19 Andreas Steffen
h2. Initiating IPsec Connection Setup
180 1 Andreas Steffen
181 20 Andreas Steffen
The *peer* IPsec connection to the IoT device *raspi4* is initiated using the IKEv2 key exchange protocol
182 18 Andreas Steffen
<pre>
183 17 Andreas Steffen
raspi3# ipsec up peer
184 15 Andreas Steffen
</pre>
185 15 Andreas Steffen
186 3 Andreas Steffen
<pre>
187 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 10[CFG] received stroke: initiate 'peer'
188 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 11[IKE] initiating IKE_SA peer[1] to 10.10.1.40
189 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 11[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(HASH_ALG) ]
190 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 11[NET] sending packet: from 10.10.1.39[500] to 10.10.1.40[500] (256 bytes)
191 6 Andreas Steffen
</pre>
192 6 Andreas Steffen
193 6 Andreas Steffen
<pre>
194 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[NET] received packet: from 10.10.1.40[500] to 10.10.1.39[500] (309 bytes)
195 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[ENC] parsed IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(HASH_ALG) N(MULT_AUTH) ]
196 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[IKE] received cert request for "C=US, O=TNC Demo, CN=TNC Demo CA"
197 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[IKE] sending cert request for "C=US, O=TNC Demo, CN=TNC Demo CA"
198 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[IKE] establishing CHILD_SA peer
199 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[ENC] generating IKE_AUTH request 1 [ IDi N(INIT_CONTACT) CERTREQ IDr N(USE_TRANSP) SA TSi TSr N(MOBIKE_SUP) N(NO_ADD_ADDR) N(MULT_AUTH) N(EAP_ONLY) ]
200 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 12[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (304 bytes)
201 6 Andreas Steffen
</pre>
202 6 Andreas Steffen
203 6 Andreas Steffen
<pre>
204 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (112 bytes)
205 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[ENC] parsed IKE_AUTH response 1 [ IDr EAP/REQ/TTLS ]
206 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[IKE] server requested EAP_TTLS authentication (id 0xDB)
207 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[TLS] EAP_TTLS version is v0
208 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[IKE] allow mutual EAP-only authentication
209 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[ENC] generating IKE_AUTH request 2 [ EAP/RES/TTLS ]
210 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 13[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (208 bytes)
211 6 Andreas Steffen
</pre>
212 6 Andreas Steffen
213 6 Andreas Steffen
<pre>
214 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 14[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes)
215 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 14[ENC] parsed IKE_AUTH response 2 [ EAP/REQ/TTLS ]
216 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 14[ENC] generating IKE_AUTH request 3 [ EAP/RES/TTLS ]
217 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 14[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes)
218 6 Andreas Steffen
</pre>
219 6 Andreas Steffen
220 6 Andreas Steffen
<pre>
221 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (480 bytes)
222 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[ENC] parsed IKE_AUTH response 3 [ EAP/REQ/TTLS ]
223 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[TLS] negotiated TLS 1.2 using suite TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
224 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[TLS] received TLS server certificate 'C=US, O=TNC Demo, CN=raspi4.example.com'
225 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[CFG]   using certificate "C=US, O=TNC Demo, CN=raspi4.example.com"
226 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[CFG]   using trusted ca certificate "C=US, O=TNC Demo, CN=TNC Demo CA"
227 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[CFG] checking certificate status of "C=US, O=TNC Demo, CN=raspi4.example.com"
228 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[CFG] certificate status is not available
229 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[CFG]   reached self-signed root ca with a path length of 0
230 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[TLS] received TLS cert request for 'C=US, O=TNC Demo, CN=TNC Demo CA
231 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[TLS] sending TLS peer certificate 'C=US, O=TNC Demo, CN=raspi3.example.com'
232 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[ENC] generating IKE_AUTH request 4 [ EAP/RES/TTLS ]
233 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 15[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
234 6 Andreas Steffen
</pre>
235 6 Andreas Steffen
236 6 Andreas Steffen
<pre>
237 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 16[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
238 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 16[ENC] parsed IKE_AUTH response 4 [ EAP/REQ/TTLS ]
239 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 16[ENC] generating IKE_AUTH request 5 [ EAP/RES/TTLS ]
240 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 16[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (352 bytes)
241 6 Andreas Steffen
</pre>
242 6 Andreas Steffen
243 6 Andreas Steffen
<pre>
244 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes)
245 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[ENC] parsed IKE_AUTH response 5 [ EAP/REQ/TTLS ]
246 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/ID]
247 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[IKE] server requested EAP_IDENTITY authentication (id 0x00)
248 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/ID]
249 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[ENC] generating IKE_AUTH request 6 [ EAP/RES/TTLS ]
250 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 09[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (192 bytes)
251 6 Andreas Steffen
</pre>
252 6 Andreas Steffen
253 6 Andreas Steffen
<pre>
254 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (176 bytes)
255 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[ENC] parsed IKE_AUTH response 6 [ EAP/REQ/TTLS ]
256 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
257 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IKE] server requested EAP_PT_EAP authentication (id 0xB8)
258 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TLS] EAP_PT_EAP version is v1
259 7 Andreas Steffen
</pre>
260 1 Andreas Steffen
261 21 Andreas Steffen
h2. Start of Mutual Attestation
262 14 Andreas Steffen
263 7 Andreas Steffen
<pre>
264 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] TNC client is handling outbound connection
265 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] assigned TNCCS Connection ID 1
266 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] IMC 1 "OS" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh
267 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
268 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[PTS] loaded AIK certificate from '/etc/pts/aik3Cert.der'
269 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[PTS] loaded AIK Blob from '/etc/pts/aik3Blob.bin'
270 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] IMC 2 "Attestation" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh
271 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
272 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] IMC 1 "OS" changed state of Connection ID 1 to 'Handshake'
273 1 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] IMC 2 "Attestation" changed state of Connection ID 1 to 'Handshake'
274 7 Andreas Steffen
</pre>
275 7 Andreas Steffen
276 7 Andreas Steffen
<pre>
277 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] proposing PB-TNC mutual half duplex protocol
278 6 Andreas Steffen
</pre>
279 6 Andreas Steffen
280 32 Andreas Steffen
h3. Sending OS Information
281 32 Andreas Steffen
282 6 Andreas Steffen
<pre>
283 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] operating system numeric version is 7.8
284 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] last boot: Aug 15 07:56:52 UTC 2015, 17353 s ago
285 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] IPv4 forwarding is disabled
286 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] factory default password is disabled
287 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] loaded device public key from '/etc/pts/aik3Pub.der'
288 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IMC] device ID is 565feb9e8462870dba884ce540a0768d68829873
289 6 Andreas Steffen
</pre>
290 6 Andreas Steffen
291 6 Andreas Steffen
<pre>
292 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC message with ID 0x83cf019d
293 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002
294 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004
295 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003
296 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005
297 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b
298 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c
299 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008
300 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
301 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] PB-TNC state transition from 'Init' to 'Server Working'
302 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] creating PB-TNC CDATA batch
303 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] adding ITA-HSR/PB-Mutual-Capability message
304 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] adding IETF/PB-Language-Preference message
305 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] adding IETF/PB-PA message
306 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[TNC] sending PB-TNC CDATA batch (283 bytes) for Connection ID 1
307 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
308 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[ENC] generating IKE_AUTH request 7 [ EAP/RES/TTLS ]
309 2 Andreas Steffen
Aug 15 14:46:05 raspi3 charon: 08[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (448 bytes)
310 6 Andreas Steffen
</pre>
311 6 Andreas Steffen
312 6 Andreas Steffen
<pre>
313 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (272 bytes)
314 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[ENC] parsed IKE_AUTH response 7 [ EAP/REQ/TTLS ]
315 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
316 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] received TNCCS batch (108 bytes)
317 7 Andreas Steffen
</pre>
318 7 Andreas Steffen
319 7 Andreas Steffen
<pre>
320 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] TNC client is handling inbound connection
321 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing PB-TNC SDATA batch for Connection ID 1
322 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
323 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing ITA-HSR/PB-Mutual-Capability message (16 bytes)
324 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing IETF/PB-PA message (84 bytes)
325 7 Andreas Steffen
</pre>
326 7 Andreas Steffen
327 7 Andreas Steffen
<pre>
328 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] activating mutual PB-TNC half duplex protocol
329 7 Andreas Steffen
</pre>
330 7 Andreas Steffen
331 8 Andreas Steffen
<pre>
332 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
333 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMC] IMC 2 "Attestation" received message for Connection ID 1 from IMV 1
334 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing PA-TNC message with ID 0x42501f74
335 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
336 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Request PTS Protocol Capabilities' 0x005597/0x01000000
337 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/PTS Measurement Algorithm Request' 0x005597/0x06000000
338 7 Andreas Steffen
</pre>
339 7 Andreas Steffen
340 7 Andreas Steffen
<pre>
341 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMC] IMC 2 received a segmentation contract request from IMV 1 for PA message type 'TCG/PTS' 0x005597/0x00000001
342 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMC]   maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes
343 7 Andreas Steffen
</pre>
344 7 Andreas Steffen
345 7 Andreas Steffen
<pre>
346 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[PTS] supported PTS protocol capabilities: .VDT.
347 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[PTS] selected PTS measurement algorithm is HASH_SHA1
348 8 Andreas Steffen
</pre>
349 8 Andreas Steffen
350 8 Andreas Steffen
<pre>
351 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] creating PA-TNC message with ID 0x1d5fa63a
352 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
353 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] creating PA-TNC attribute type 'TCG/PTS Protocol Capabilities' 0x005597/0x02000000
354 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] creating PA-TNC attribute type 'TCG/PTS Measurement Algorithm' 0x005597/0x07000000
355 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
356 7 Andreas Steffen
</pre>
357 7 Andreas Steffen
358 7 Andreas Steffen
<pre>
359 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] TNC server is handling outbound connection
360 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] assigned TNCCS Connection ID 2
361 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMV] IMV 1 "Attestation" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh
362 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
363 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMV]   user AR identity 'raspi4.example.com' of type username authenticated by certificate
364 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMV]   machine AR identity '10.10.1.40' of type IPv4 address authenticated by unknown method
365 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IMV] IMV 1 "Attestation" changed state of Connection ID 2 to 'Handshake'
366 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] PB-TNC state transition from 'Init' to 'Client Working'
367 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] creating PB-TNC SDATA batch
368 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[TNC] sending PB-TNC SDATA batch (8 bytes) for Connection ID 2
369 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
370 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[ENC] generating IKE_AUTH request 8 [ EAP/RES/TTLS ]
371 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 07[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (176 bytes)
372 7 Andreas Steffen
</pre>
373 7 Andreas Steffen
374 7 Andreas Steffen
<pre>
375 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (432 bytes)
376 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[ENC] parsed IKE_AUTH response 8 [ EAP/REQ/TTLS ]
377 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
378 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] received TNCCS batch (267 bytes)
379 7 Andreas Steffen
</pre>
380 7 Andreas Steffen
381 7 Andreas Steffen
<pre>
382 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] TNC server is handling inbound connection
383 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PB-TNC CDATA batch for Connection ID 2
384 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
385 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing IETF/PB-Language-Preference message (31 bytes)
386 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing IETF/PB-PA message (228 bytes)
387 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] setting language preference to 'en'
388 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] handling PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
389 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] IMV 1 "Attestation" received message for Connection ID 2 from IMC 1
390 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC message with ID 0x366c28ea
391 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002
392 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004
393 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003
394 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005
395 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b
396 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c
397 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] processing PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008
398 7 Andreas Steffen
</pre>
399 32 Andreas Steffen
400 32 Andreas Steffen
h3. Receiving OS Information
401 7 Andreas Steffen
402 7 Andreas Steffen
<pre>
403 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] operating system name is 'Debian' from vendor Debian Project
404 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] operating system version is '7.8 armv7l'
405 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] device ID is 762872c90011671ef219b6a2a0c3c7dda875b43c
406 7 Andreas Steffen
</pre>
407 7 Andreas Steffen
408 33 Andreas Steffen
h3. Starting Session with Policy Manager
409 33 Andreas Steffen
410 9 Andreas Steffen
<pre>
411 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] assigned session ID 3 to Connection ID 2
412 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] policy: imv_policy_manager start successful
413 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] policy: skipping enforcment 6
414 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] FWDEN workitem 13
415 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] FMETA workitem 14
416 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] PCKGS workitem 15
417 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] TCPOP workitem 16
418 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] UDPOP workitem 17
419 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] TPMRA workitem 18
420 7 Andreas Steffen
</pre>
421 7 Andreas Steffen
422 7 Andreas Steffen
<pre>
423 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV] IMV 1 requests a segmentation contract for PA message type 'TCG/PTS' 0x005597/0x00000001
424 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes
425 7 Andreas Steffen
</pre>
426 7 Andreas Steffen
427 7 Andreas Steffen
<pre>
428 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] creating PA-TNC message with ID 0x918da8fe
429 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
430 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] creating PA-TNC attribute type 'TCG/Request PTS Protocol Capabilities' 0x005597/0x01000000
431 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] creating PA-TNC attribute type 'TCG/PTS Measurement Algorithm Request' 0x005597/0x06000000
432 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
433 7 Andreas Steffen
</pre>
434 7 Andreas Steffen
435 7 Andreas Steffen
<pre>
436 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] TNC client is handling outbound connection
437 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
438 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] creating PB-TNC CDATA batch
439 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] adding IETF/PB-PA message
440 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[TNC] sending PB-TNC CDATA batch (92 bytes) for Connection ID 1
441 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
442 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[ENC] generating IKE_AUTH request 9 [ EAP/RES/TTLS ]
443 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 06[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes)
444 7 Andreas Steffen
</pre>
445 7 Andreas Steffen
446 7 Andreas Steffen
<pre>
447 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes)
448 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[ENC] parsed IKE_AUTH response 9 [ EAP/REQ/TTLS ]
449 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
450 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] received TNCCS batch (87 bytes)
451 10 Andreas Steffen
</pre>
452 10 Andreas Steffen
453 10 Andreas Steffen
<pre>
454 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] TNC client is handling inbound connection
455 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] processing PB-TNC SDATA batch for Connection ID 1
456 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
457 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] processing IETF/PB-PA message (79 bytes)
458 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
459 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[IMC] IMC 2 "Attestation" received message for Connection ID 1 from IMV 1
460 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] processing PA-TNC message with ID 0xaff3c130
461 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] processing PA-TNC attribute type 'TCG/Request File Metadata' 0x005597/0x00700000
462 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] processing PA-TNC attribute type 'TCG/DH Nonce Parameters Request' 0x005597/0x03000000
463 7 Andreas Steffen
</pre>
464 7 Andreas Steffen
465 7 Andreas Steffen
<pre>
466 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[IMC] metadata request for file '/etc/tnc_config'
467 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[PTS] selected PTS DH group is ECP_256
468 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[PTS] nonce length is 20
469 7 Andreas Steffen
</pre>
470 7 Andreas Steffen
471 7 Andreas Steffen
<pre>
472 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] creating PA-TNC message with ID 0x5e3ee705
473 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] creating PA-TNC attribute type 'TCG/Unix-Style File Metadata' 0x005597/0x00900000
474 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] creating PA-TNC attribute type 'TCG/DH Nonce Parameters Response' 0x005597/0x04000000
475 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
476 11 Andreas Steffen
</pre>
477 11 Andreas Steffen
478 11 Andreas Steffen
<pre>
479 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] TNC server is handling outbound connection
480 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
481 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] creating PB-TNC SDATA batch
482 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] adding IETF/PB-PA message
483 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[TNC] sending PB-TNC SDATA batch (92 bytes) for Connection ID 2
484 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
485 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[ENC] generating IKE_AUTH request 10 [ EAP/RES/TTLS ]
486 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 05[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes)
487 7 Andreas Steffen
</pre>
488 7 Andreas Steffen
489 7 Andreas Steffen
<pre>
490 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes)
491 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[ENC] parsed IKE_AUTH response 10 [ EAP/REQ/TTLS ]
492 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
493 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] received TNCCS batch (92 bytes)
494 7 Andreas Steffen
</pre>
495 7 Andreas Steffen
496 7 Andreas Steffen
<pre>
497 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] TNC server is handling inbound connection
498 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] processing PB-TNC CDATA batch for Connection ID 2
499 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
500 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] processing IETF/PB-PA message (84 bytes)
501 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
502 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV] IMV 1 "Attestation" received message for Connection ID 2 from IMC 2 to IMV 1
503 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] processing PA-TNC message with ID 0xf94741eb
504 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
505 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] processing PA-TNC attribute type 'TCG/PTS Protocol Capabilities' 0x005597/0x02000000
506 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] processing PA-TNC attribute type 'TCG/PTS Measurement Algorithm' 0x005597/0x07000000
507 7 Andreas Steffen
</pre>
508 7 Andreas Steffen
509 7 Andreas Steffen
<pre>
510 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV] IMV 1 received a segmentation contract response from IMC 2 for PA message type 'TCG/PTS' 0x005597/0x00000001
511 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes
512 7 Andreas Steffen
</pre>
513 7 Andreas Steffen
514 7 Andreas Steffen
<pre>
515 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[PTS] supported PTS protocol capabilities: .VDT.
516 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[PTS] selected PTS measurement algorithm is HASH_SHA1
517 7 Andreas Steffen
</pre>
518 7 Andreas Steffen
519 7 Andreas Steffen
<pre>
520 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV] IMV 1 handles FMETA workitem 14
521 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV] IMV 1 requests metadata for file '/etc/tnc_config'
522 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV] IMV 1 handled FMETA workitem 14: allow - file metadata requested
523 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IMV] IMV 1 handles TPMRA workitem 18
524 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] creating PA-TNC message with ID 0xda2a70e9
525 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] creating PA-TNC attribute type 'TCG/Request File Metadata' 0x005597/0x00700000
526 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] creating PA-TNC attribute type 'TCG/DH Nonce Parameters Request' 0x005597/0x03000000
527 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
528 7 Andreas Steffen
</pre>
529 7 Andreas Steffen
530 7 Andreas Steffen
<pre>
531 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] TNC client is handling outbound connection
532 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
533 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] creating PB-TNC CDATA batch
534 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] adding IETF/PB-PA message
535 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[TNC] sending PB-TNC CDATA batch (226 bytes) for Connection ID 1
536 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
537 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[ENC] generating IKE_AUTH request 11 [ EAP/RES/TTLS ]
538 1 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 11[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (400 bytes)
539 7 Andreas Steffen
</pre>
540 7 Andreas Steffen
541 7 Andreas Steffen
<pre>
542 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (336 bytes)
543 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[ENC] parsed IKE_AUTH response 11 [ EAP/REQ/TTLS ]
544 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
545 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] received TNCCS batch (172 bytes)
546 8 Andreas Steffen
</pre>
547 8 Andreas Steffen
548 8 Andreas Steffen
<pre>
549 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] TNC client is handling inbound connection
550 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] processing PB-TNC SDATA batch for Connection ID 1
551 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
552 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] processing IETF/PB-PA message (164 bytes)
553 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
554 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[IMC] IMC 2 "Attestation" received message for Connection ID 1 from IMV 1
555 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] processing PA-TNC message with ID 0xd27d5b33
556 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] processing PA-TNC attribute type 'TCG/DH Nonce Finish' 0x005597/0x05000000
557 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] processing PA-TNC attribute type 'TCG/Get TPM Version Information' 0x005597/0x08000000
558 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] processing PA-TNC attribute type 'TCG/Get Attestation Identity Key' 0x005597/0x0d000000
559 22 Andreas Steffen
</pre>
560 22 Andreas Steffen
561 22 Andreas Steffen
<pre>
562 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS] selected DH hash algorithm is HASH_SHA1
563 22 Andreas Steffen
</pre>
564 22 Andreas Steffen
565 22 Andreas Steffen
<pre>
566 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS] initiator nonce: => 20 bytes @ 0x11d940
567 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]    0: 01 97 8C C2 90 09 6D 02 F0 0A 40 E1 8C 90 5F 15  ......m...@..._.
568 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]   16: FB 4E 28 AD                                      .N(.
569 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS] responder nonce: => 20 bytes @ 0x11d410
570 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]    0: 3D D0 72 39 3A E1 A0 E2 0B 30 B4 D4 D9 22 9F E0  =.r9:....0..."..
571 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]   16: B6 D1 2A 01                                      ..*.
572 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS] shared DH secret: => 32 bytes @ 0x11e038
573 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]    0: 5F 0F D8 1E B5 39 B4 E2 86 BF 0C 92 9E E3 3A EA  _....9........:.
574 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]   16: D7 23 93 EB C2 85 F5 09 EC DB C0 B1 E5 51 50 DE  .#...........QP.
575 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS] secret assessment value: => 20 bytes @ 0x11c5e0
576 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]    0: D8 9D 1E 70 CE 78 C3 13 F2 79 BA 5D 7C E5 05 7C  ...p.x...y.]|..|
577 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS]   16: E0 E0 83 77                                      ...w
578 8 Andreas Steffen
</pre>
579 8 Andreas Steffen
580 34 Andreas Steffen
h3. Sending TPM Version Information
581 34 Andreas Steffen
582 8 Andreas Steffen
<pre>
583 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[PTS] TPM Version Info: Chip Version: 1.2.133.32, Spec Level: 2, Errata Rev: 3, Vendor ID: IFX
584 8 Andreas Steffen
</pre>
585 8 Andreas Steffen
586 8 Andreas Steffen
<pre>
587 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] creating PA-TNC message with ID 0x641bcea1
588 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] creating PA-TNC attribute type 'TCG/TPM Version Information' 0x005597/0x09000000
589 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] creating PA-TNC attribute type 'TCG/Attestation Identity Key' 0x005597/0x0e000000
590 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
591 8 Andreas Steffen
</pre>
592 8 Andreas Steffen
593 8 Andreas Steffen
<pre>
594 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] TNC server is handling outbound connection
595 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
596 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] creating PB-TNC SDATA batch
597 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] adding IETF/PB-PA message
598 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[TNC] sending PB-TNC SDATA batch (87 bytes) for Connection ID 2
599 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
600 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[ENC] generating IKE_AUTH request 12 [ EAP/RES/TTLS ]
601 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 12[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes)
602 8 Andreas Steffen
</pre>
603 8 Andreas Steffen
604 8 Andreas Steffen
<pre>
605 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (400 bytes)
606 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[ENC] parsed IKE_AUTH response 12 [ EAP/REQ/TTLS ]
607 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
608 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] received TNCCS batch (226 bytes)
609 8 Andreas Steffen
</pre>
610 8 Andreas Steffen
611 8 Andreas Steffen
<pre>
612 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] TNC server is handling inbound connection
613 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] processing PB-TNC CDATA batch for Connection ID 2
614 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
615 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] processing IETF/PB-PA message (218 bytes)
616 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
617 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[IMV] IMV 1 "Attestation" received message for Connection ID 2 from IMC 2 to IMV 1
618 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] processing PA-TNC message with ID 0x676268aa
619 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] processing PA-TNC attribute type 'TCG/Unix-Style File Metadata' 0x005597/0x00900000
620 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] processing PA-TNC attribute type 'TCG/DH Nonce Parameters Response' 0x005597/0x04000000
621 22 Andreas Steffen
</pre>
622 22 Andreas Steffen
623 22 Andreas Steffen
<pre>
624 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[IMV] metadata request returned 1 file:
625 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[IMV]  'tnc_config' (177 bytes) owner 0, group 0, type Regular
626 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[IMV]     created Jun 16 20:09:17 2015, modified Jun 16 20:09:17 2015, accessed Jun 16 20:09:17 2015
627 22 Andreas Steffen
</pre>
628 22 Andreas Steffen
629 22 Andreas Steffen
<pre>
630 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] selected DH hash algorithm is HASH_SHA1
631 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] selected PTS DH group is ECP_256
632 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] nonce length is 20
633 22 Andreas Steffen
</pre>
634 22 Andreas Steffen
635 23 Andreas Steffen
<pre>
636 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] initiator nonce: => 20 bytes @ 0x11d890
637 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]    0: 27 B7 51 A0 C8 66 92 54 F0 57 C1 49 9D 2A 7D 3A  '.Q..f.T.W.I.*}:
638 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]   16: F1 38 81 26                                      .8.&
639 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] responder nonce: => 20 bytes @ 0x11e418
640 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]    0: 96 48 1F 52 8C A6 D5 6E 5F A4 17 2B AF BE 26 71  .H.R...n_..+..&q
641 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]   16: 49 73 01 42                                      Is.B
642 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] shared DH secret: => 32 bytes @ 0x127170
643 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]    0: AA FE 9F 01 D7 CC 22 17 FF 35 CF 9C 70 41 7B 11  ......"..5..pA{.
644 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]   16: D0 3C B6 32 BF 3D 80 BF 73 32 1E 95 F3 20 9E D1  .<.2.=..s2... ..
645 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS] secret assessment value: => 20 bytes @ 0x11e9f0
646 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]    0: B2 E0 AB DF 89 C5 1D B2 A3 51 FD A9 C8 3B F8 7F  .........Q...;..
647 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[PTS]   16: 68 50 6C DE                                      hPl.
648 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] creating PA-TNC message with ID 0xe1b84e91
649 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] creating PA-TNC attribute type 'TCG/DH Nonce Finish' 0x005597/0x05000000
650 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] creating PA-TNC attribute type 'TCG/Get TPM Version Information' 0x005597/0x08000000
651 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] creating PA-TNC attribute type 'TCG/Get Attestation Identity Key' 0x005597/0x0d000000
652 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
653 8 Andreas Steffen
</pre>
654 8 Andreas Steffen
655 8 Andreas Steffen
<pre>
656 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] TNC client is handling outbound connection
657 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
658 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] creating PB-TNC CDATA batch
659 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] adding IETF/PB-PA message
660 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[TNC] sending PB-TNC CDATA batch (902 bytes) for Connection ID 1
661 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
662 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[ENC] generating IKE_AUTH request 13 [ EAP/RES/TTLS ]
663 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 13[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1072 bytes)
664 8 Andreas Steffen
</pre>
665 8 Andreas Steffen
666 8 Andreas Steffen
<pre>
667 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes)
668 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[ENC] parsed IKE_AUTH response 13 [ EAP/REQ/TTLS ]
669 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
670 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] received TNCCS batch (80 bytes)
671 8 Andreas Steffen
</pre>
672 8 Andreas Steffen
673 8 Andreas Steffen
<pre>
674 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] TNC client is handling inbound connection
675 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] processing PB-TNC SDATA batch for Connection ID 1
676 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
677 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] processing IETF/PB-PA message (72 bytes)
678 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
679 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[IMC] IMC 2 "Attestation" received message for Connection ID 1 from IMV 1
680 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] processing PA-TNC message with ID 0xed256fac
681 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] processing PA-TNC attribute type 'TCG/Request Functional Component Evidence' 0x005597/0x00100000
682 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[TNC] processing PA-TNC attribute type 'TCG/Generate Attestation Evidence' 0x005597/0x00200000
683 25 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[IMC] evidence requested for 1 functional components
684 25 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] * ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
685 8 Andreas Steffen
</pre>
686 8 Andreas Steffen
687 28 Andreas Steffen
h3. Initiator Attestation Measurements
688 2 Andreas Steffen
689 2 Andreas Steffen
<pre>
690 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] loaded ima measurements '/sys/kernel/security/ima/binary_runtime_measurements' (434 entries)
691 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
692 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
693 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: dd:ee:60:04:dc:3b:d4:ee:30:04:06:cd:93:18:1c:5a:21:87:b5:9b
694 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:boot_aggregate'
695 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
696 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
697 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: 65:ee:0c:a2:cd:ac:0d:67:f8:1a:fd:53:7b:96:75:6f:3b:b8:0f:82
698 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:/init'
699 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
700 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
701 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: 6b:a1:a0:58:89:a8:f2:57:53:42:b5:dc:5f:3e:de:54:89:8a:ee:29
702 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:/bin/sh'
703 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
704 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
705 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: 85:e6:6e:7a:96:98:8b:0a:af:c8:88:46:5d:7a:fe:b5:e9:d3:c2:3e
706 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:/lib/klibc-sO6SifHCdmbehHGtm0y1yHu6vb0.so'
707 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
708 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
709 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: 68:4a:c3:8d:48:55:be:e0:21:93:4f:52:a0:d2:3d:66:86:0c:b2:82
710 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:/bin/mkdir'
711 5 Andreas Steffen
...
712 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
713 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
714 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: 1a:71:6c:9c:9f:6d:4f:2e:4a:88:42:49:b0:00:8d:5e:ec:05:7e:eb
715 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:/usr/sbin/service'
716 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
717 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] measurement time: Jan 01 01:00:04 1970
718 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] PCR 10 extended with: e8:f5:f2:02:d4:c1:18:d5:f7:55:5c:2d:4a:a0:d3:12:d4:13:06:ce
719 2 Andreas Steffen
Aug 15 14:46:08 raspi3 charon: 14[PTS] 'sha1:/bin/cp'
720 8 Andreas Steffen
</pre>
721 8 Andreas Steffen
722 29 Andreas Steffen
h3. Generating Initiator TPM Quote Signature
723 26 Andreas Steffen
724 8 Andreas Steffen
<pre>
725 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS] Hash of PCR Composite: 58:f2:83:91:d6:a8:df:3d:3e:c6:33:c7:24:93:9f:9c:22:a2:01:20
726 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS] TPM Quote Info: => 52 bytes @ 0x135360
727 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]    0: 00 36 51 55 54 32 D8 9D 1E 70 CE 78 C3 13 F2 79  .6QUT2...p.x...y
728 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   16: BA 5D 7C E5 05 7C E0 E0 83 77 00 03 00 04 00 01  .]|..|...w......
729 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   32: 58 F2 83 91 D6 A8 DF 3D 3E C6 33 C7 24 93 9F 9C  X......=>.3.$...
730 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   48: 22 A2 01 20                                      ".. 
731 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS] TPM Quote Signature: => 256 bytes @ 0x14b5d0
732 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]    0: 88 6E 6B 2E 33 AC AD 94 E6 A1 38 3E CD EC 9F E9  .nk.3.....8>....
733 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   16: F0 92 E9 E4 4A 66 05 50 0B 30 F2 DF 50 DC 80 4E  ....Jf.P.0..P..N
734 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   32: F1 AC BE 93 99 06 DF 41 AD 49 F9 DE 09 F1 18 15  .......A.I......
735 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   48: 2B B9 97 D9 DD A9 E9 7F 3D ED B8 BF EB FF 7E C6  +.......=.....~.
736 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   64: A1 1A 77 87 67 9B 24 78 46 AC C0 AA 25 FA 87 5F  ..w.g.$xF...%.._
737 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   80: E3 F4 F8 33 35 30 C3 31 BE DE 77 A5 2E 4F 8D 3B  ...350.1..w..O.;
738 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]   96: F5 52 36 F4 8E C4 FA D4 A1 61 1C 4B 71 A2 52 8B  .R6......a.Kq.R.
739 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  112: 80 AD A6 DD 8D E5 D8 47 4F 2B 9C 17 CF BF AC 10  .......GO+......
740 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  128: C6 31 4B 01 C3 59 C3 FD F7 D2 65 C1 F0 32 12 8B  .1K..Y....e..2..
741 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  144: 8F 54 49 A7 40 F9 BD 43 86 79 A1 FD 51 05 DB 65  .TI.@..C.y..Q..e
742 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  160: C8 A4 C1 67 44 96 89 4D F4 E7 DB D5 AE 67 35 17  ...gD..M.....g5.
743 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  176: D7 D3 68 23 E9 1F 98 9E E6 7C 86 89 EE A4 31 68  ..h#.....|....1h
744 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  192: 15 B6 F6 E3 10 86 F0 FE C3 9B C2 7D 5B FB 33 BA  ...........}[.3.
745 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  208: 88 BE 5C D9 71 54 7F BF 72 31 5F 8E 58 4A E9 A4  ..\.qT..r1_.XJ..
746 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  224: B0 8E 3B 55 03 90 AD E1 C8 A0 C7 9C 83 13 DE 0F  ..;U............
747 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[PTS]  240: 60 D8 A4 E2 4C CD E4 E2 A4 BA 11 BE 3D D4 A5 A7  `...L.......=...
748 26 Andreas Steffen
</pre>
749 26 Andreas Steffen
750 26 Andreas Steffen
<pre>
751 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC message with ID 0x2d059578
752 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
753 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
754 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
755 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
756 8 Andreas Steffen
...
757 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
758 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
759 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Simple Evidence Final' 0x005597/0x00400000
760 1 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
761 11 Andreas Steffen
</pre>
762 11 Andreas Steffen
763 11 Andreas Steffen
<pre>
764 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] TNC server is handling outbound connection
765 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
766 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] creating PB-TNC SDATA batch
767 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] adding IETF/PB-PA message
768 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[TNC] sending PB-TNC SDATA batch (172 bytes) for Connection ID 2
769 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
770 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[ENC] generating IKE_AUTH request 14 [ EAP/RES/TTLS ]
771 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (336 bytes)
772 8 Andreas Steffen
</pre>
773 8 Andreas Steffen
774 8 Andreas Steffen
<pre>
775 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1072 bytes)
776 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[ENC] parsed IKE_AUTH response 14 [ EAP/REQ/TTLS ]
777 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
778 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] received TNCCS batch (902 bytes)
779 8 Andreas Steffen
</pre>
780 8 Andreas Steffen
781 8 Andreas Steffen
<pre>
782 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] TNC server is handling inbound connection
783 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] processing PB-TNC CDATA batch for Connection ID 2
784 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
785 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] processing IETF/PB-PA message (894 bytes)
786 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
787 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IMV] IMV 1 "Attestation" received message for Connection ID 2 from IMC 2 to IMV 1
788 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] processing PA-TNC message with ID 0x951e0284
789 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] processing PA-TNC attribute type 'TCG/TPM Version Information' 0x005597/0x09000000
790 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] processing PA-TNC attribute type 'TCG/Attestation Identity Key' 0x005597/0x0e000000
791 13 Andreas Steffen
</pre>
792 34 Andreas Steffen
793 34 Andreas Steffen
h3. Sending TPM Version Information
794 13 Andreas Steffen
795 13 Andreas Steffen
<pre>
796 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[PTS] TPM Version Info: Chip Version: 1.2.133.32, Spec Level: 2, Errata Rev: 3, Vendor ID: IFX
797 13 Andreas Steffen
</pre>
798 13 Andreas Steffen
799 13 Andreas Steffen
<pre>
800 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IMV] verifying AIK with keyid 76:28:72:c9:00:11:67:1e:f2:19:b6:a2:a0:c3:c7:dd:a8:75:b4:3c
801 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IMV] AIK public key is trusted
802 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[CFG]   using trusted certificate "C=US, O=TNC Demo, CN=AIK CA"
803 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IMV] AIK certificate is trusted
804 13 Andreas Steffen
</pre>
805 13 Andreas Steffen
806 13 Andreas Steffen
<pre>
807 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IMV] evidence request by
808 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[PTS]   ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
809 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] creating PA-TNC message with ID 0xc8f4500b
810 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] creating PA-TNC attribute type 'TCG/Request Functional Component Evidence' 0x005597/0x00100000
811 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] creating PA-TNC attribute type 'TCG/Generate Attestation Evidence' 0x005597/0x00200000
812 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
813 8 Andreas Steffen
</pre>
814 8 Andreas Steffen
815 8 Andreas Steffen
<pre>
816 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] TNC client is handling outbound connection
817 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
818 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] creating PB-TNC CDATA batch
819 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] adding IETF/PB-PA message
820 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[TNC] sending PB-TNC CDATA batch (47615 bytes) for Connection ID 1
821 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
822 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[ENC] generating IKE_AUTH request 15 [ EAP/RES/TTLS ]
823 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 12[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
824 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 13[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
825 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 13[ENC] parsed IKE_AUTH response 15 [ EAP/REQ/TTLS ]
826 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 13[ENC] generating IKE_AUTH request 16 [ EAP/RES/TTLS ]
827 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 13[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
828 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 15[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
829 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 15[ENC] parsed IKE_AUTH response 16 [ EAP/REQ/TTLS ]
830 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 15[ENC] generating IKE_AUTH request 17 [ EAP/RES/TTLS ]
831 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 15[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
832 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 16[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
833 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 16[ENC] parsed IKE_AUTH response 17 [ EAP/REQ/TTLS ]
834 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 16[ENC] generating IKE_AUTH request 18 [ EAP/RES/TTLS ]
835 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 16[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
836 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
837 2 Andreas Steffen
Aug 15 14:46:09 raspi3 charon: 14[ENC] parsed IKE_AUTH response 18 [ EAP/REQ/TTLS ]
838 13 Andreas Steffen
...
839 2 Andreas Steffen
Aug 15 14:46:10 raspi3 charon: 13[ENC] generating IKE_AUTH request 60 [ EAP/RES/TTLS ]
840 2 Andreas Steffen
Aug 15 14:46:10 raspi3 charon: 13[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
841 2 Andreas Steffen
Aug 15 14:46:10 raspi3 charon: 15[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
842 2 Andreas Steffen
Aug 15 14:46:10 raspi3 charon: 15[ENC] parsed IKE_AUTH response 60 [ EAP/REQ/TTLS ]
843 2 Andreas Steffen
Aug 15 14:46:10 raspi3 charon: 15[ENC] generating IKE_AUTH request 61 [ EAP/RES/TTLS ]
844 2 Andreas Steffen
Aug 15 14:46:10 raspi3 charon: 15[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
845 2 Andreas Steffen
Aug 15 14:46:14 raspi3 charon: 13[IKE] retransmit 1 of request with message ID 61
846 2 Andreas Steffen
Aug 15 14:46:14 raspi3 charon: 13[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes)
847 13 Andreas Steffen
</pre>
848 13 Andreas Steffen
849 13 Andreas Steffen
<pre>
850 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes)
851 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[ENC] parsed IKE_AUTH response 61 [ EAP/REQ/TTLS ]
852 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
853 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] received TNCCS batch (88 bytes)
854 2 Andreas Steffen
</pre>
855 2 Andreas Steffen
856 2 Andreas Steffen
<pre>
857 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] TNC client is handling inbound connection
858 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] processing PB-TNC RESULT batch for Connection ID 1
859 1 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] PB-TNC state transition from 'Server Working' to 'Decided'
860 11 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] processing IETF/PB-PA message (48 bytes)
861 11 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] processing IETF/PB-Assessment-Result message (16 bytes)
862 11 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] processing IETF/PB-Access-Recommendation message (16 bytes)
863 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
864 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IMC] IMC 2 "Attestation" received message for Connection ID 1 from IMV 1
865 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] processing PA-TNC message with ID 0x57254d62
866 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] processing PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
867 13 Andreas Steffen
</pre>
868 13 Andreas Steffen
869 30 Andreas Steffen
h3. Receiving Assessment Result
870 30 Andreas Steffen
871 13 Andreas Steffen
<pre>
872 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IMC] ***** assessment of IMC 2 "Attestation" from IMV 1 *****
873 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IMC] assessment result is 'compliant'
874 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IMC] ***** end of assessment *****
875 13 Andreas Steffen
</pre>
876 13 Andreas Steffen
877 13 Andreas Steffen
<pre>
878 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] PB-TNC assessment result is 'compliant'
879 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] PB-TNC access recommendation is 'Access Allowed'
880 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IMC] IMC 1 "OS" changed state of Connection ID 1 to 'Allowed'
881 1 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IMC] IMC 2 "Attestation" changed state of Connection ID 1 to 'Allowed'
882 11 Andreas Steffen
</pre>
883 11 Andreas Steffen
884 11 Andreas Steffen
<pre>
885 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] TNC server is handling outbound connection
886 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
887 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] creating PB-TNC SDATA batch
888 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] adding IETF/PB-PA message
889 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[TNC] sending PB-TNC SDATA batch (80 bytes) for Connection ID 2
890 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
891 2 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[ENC] generating IKE_AUTH request 62 [ EAP/RES/TTLS ]
892 1 Andreas Steffen
Aug 15 14:46:16 raspi3 charon: 15[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes)
893 11 Andreas Steffen
</pre>
894 11 Andreas Steffen
895 11 Andreas Steffen
<pre>
896 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 16[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes)
897 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 16[ENC] parsed IKE_AUTH response 62 [ EAP/REQ/TTLS ]
898 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 16[ENC] generating IKE_AUTH request 63 [ EAP/RES/TTLS ]
899 1 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 16[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes)
900 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 14[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes)
901 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 14[ENC] parsed IKE_AUTH response 63 [ EAP/REQ/TTLS ]
902 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 14[ENC] generating IKE_AUTH request 64 [ EAP/RES/TTLS ]
903 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 14[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes)
904 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 09[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes)
905 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 09[ENC] parsed IKE_AUTH response 64 [ EAP/REQ/TTLS ]
906 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 09[ENC] generating IKE_AUTH request 65 [ EAP/RES/TTLS ]
907 2 Andreas Steffen
Aug 15 14:46:17 raspi3 charon: 09[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes)
908 11 Andreas Steffen
...
909 1 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 08[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes)
910 1 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 08[ENC] parsed IKE_AUTH response 109 [ EAP/REQ/TTLS ]
911 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 08[ENC] generating IKE_AUTH request 110 [ EAP/RES/TTLS ]
912 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 08[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes)
913 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1040 bytes)
914 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[ENC] parsed IKE_AUTH response 110 [ EAP/REQ/TTLS ]
915 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[IKE] need more AVP data
916 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
917 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] received TNCCS batch (49524 bytes)
918 11 Andreas Steffen
</pre>
919 11 Andreas Steffen
920 11 Andreas Steffen
<pre>
921 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] TNC server is handling inbound connection
922 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PB-TNC CDATA batch for Connection ID 2
923 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
924 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing IETF/PB-PA message (49516 bytes)
925 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001
926 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[IMV] IMV 1 "Attestation" received message for Connection ID 2 from IMC 2 to IMV 1
927 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC message with ID 0xed64f7ab
928 11 Andreas Steffen
</pre>
929 24 Andreas Steffen
930 28 Andreas Steffen
h3. Responder Attestation Measurements
931 11 Andreas Steffen
932 11 Andreas Steffen
<pre>
933 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
934 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
935 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
936 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: dd:ee:60:04:dc:3b:d4:ee:30:04:06:cd:93:18:1c:5a:21:87:b5:9b
937 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:boot_aggregate'
938 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
939 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
940 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
941 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: 65:ee:0c:a2:cd:ac:0d:67:f8:1a:fd:53:7b:96:75:6f:3b:b8:0f:82
942 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:/init'
943 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
944 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
945 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
946 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: 6b:a1:a0:58:89:a8:f2:57:53:42:b5:dc:5f:3e:de:54:89:8a:ee:29
947 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:/bin/sh'
948 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
949 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
950 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
951 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: 85:e6:6e:7a:96:98:8b:0a:af:c8:88:46:5d:7a:fe:b5:e9:d3:c2:3e
952 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:/lib/klibc-sO6SifHCdmbehHGtm0y1yHu6vb0.so'
953 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
954 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
955 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
956 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: 68:4a:c3:8d:48:55:be:e0:21:93:4f:52:a0:d2:3d:66:86:0c:b2:82
957 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:/bin/mkdir'
958 2 Andreas Steffen
...
959 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
960 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
961 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
962 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: 55:f4:cd:fd:82:d2:99:e1:33:b6:82:67:95:e6:5d:03:5c:bb:d2:c2
963 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:/usr/bin/clear_console'
964 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000
965 5 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System'
966 1 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] measurement time: Jan 01 01:00:04 1970
967 1 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] PCR 10 extended with: 7a:fc:49:eb:8f:e6:74:3f:ac:91:41:a2:c0:ac:92:28:33:fd:7b:33
968 5 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 'sha1:/usr/libexec/ipsec/stroke'
969 28 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Simple Evidence Final' 0x005597/0x00400000
970 28 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] checking boot aggregate evidence measurement
971 1 Andreas Steffen
</pre>
972 11 Andreas Steffen
973 28 Andreas Steffen
h3. Verifying Responder Attestation Measurements
974 28 Andreas Steffen
975 2 Andreas Steffen
<pre>
976 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 65:ee:0c:a2:cd:ac:0d:67:f8:1a:fd:53:7b:96:75:6f:3b:b8:0f:82 for '/init' not found
977 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 6b:a1:a0:58:89:a8:f2:57:53:42:b5:dc:5f:3e:de:54:89:8a:ee:29 for '/bin/sh' is ok
978 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 85:e6:6e:7a:96:98:8b:0a:af:c8:88:46:5d:7a:fe:b5:e9:d3:c2:3e for '/lib/klibc-sO6SifHCdmbehHGtm0y1yHu6vb0.so' is ok
979 2 Andreas Steffen
Aug 15 14:46:18 raspi3 charon: 07[PTS] 68:4a:c3:8d:48:55:be:e0:21:93:4f:52:a0:d2:3d:66:86:0c:b2:82 for '/bin/mkdir' is ok
980 2 Andreas Steffen
...
981 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS] 55:f4:cd:fd:82:d2:99:e1:33:b6:82:67:95:e6:5d:03:5c:bb:d2:c2 for '/usr/bin/clear_console' is ok
982 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS] 7a:fc:49:eb:8f:e6:74:3f:ac:91:41:a2:c0:ac:92:28:33:fd:7b:33 for '/usr/libexec/ipsec/stroke' is ok
983 11 Andreas Steffen
</pre>
984 26 Andreas Steffen
985 29 Andreas Steffen
h3. Verfiying Responder TPM Quote Signature
986 11 Andreas Steffen
987 11 Andreas Steffen
<pre>
988 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS] constructed PCR Composite: => 29 bytes @ 0x125488
989 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS]    0: 00 03 00 04 00 00 00 00 14 7D C1 1B 87 CF 2E B8  .........}......
990 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS]   16: 5C 1B 52 99 B8 BD 11 D9 B9 8A 31 8E 61           \.R.......1.a
991 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS] constructed PCR Composite hash: c4:6a:f4:fa:82:39:a6:7a:80:fe:4e:d2:7e:a5:05:b3:1e:60:4f:ff
992 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS] constructed TPM Quote Info: => 52 bytes @ 0x1954c8
993 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS]    0: 00 36 51 55 54 32 B2 E0 AB DF 89 C5 1D B2 A3 51  .6QUT2.........Q
994 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS]   16: FD A9 C8 3B F8 7F 68 50 6C DE 00 03 00 04 00 01  ...;..hPl.......
995 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS]   32: C4 6A F4 FA 82 39 A6 7A 80 FE 4E D2 7E A5 05 B3  .j...9.z..N.~...
996 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS]   48: 1E 60 4F FF                                      .`O.
997 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IMV] received PCR Composite matches constructed one
998 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IMV] TPM Quote Info signature verification successful
999 11 Andreas Steffen
</pre>
1000 11 Andreas Steffen
1001 11 Andreas Steffen
<pre>
1002 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[PTS] processed 450 IMA file evidence measurements: 385 ok, 65 unknown, 0 differ, 0 failed
1003 11 Andreas Steffen
</pre>
1004 11 Andreas Steffen
1005 11 Andreas Steffen
<pre>
1006 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IMV] IMV 1 handled TPMRA workitem 18: allow - processed 450 IMA file evidence measurements: 385 ok, 65 unknown, 0 differ, 0 failed
1007 4 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] creating PA-TNC message with ID 0x4077e3ed
1008 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
1009 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001
1010 30 Andreas Steffen
</pre>
1011 30 Andreas Steffen
1012 30 Andreas Steffen
h3. Sending Assessment Result
1013 30 Andreas Steffen
1014 31 Andreas Steffen
<pre>
1015 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] IMV 1 provides recommendation 'allow' and evaluation 'compliant'
1016 11 Andreas Steffen
</pre>
1017 11 Andreas Steffen
1018 11 Andreas Steffen
<pre>
1019 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] TNC server is handling outbound connection
1020 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IMV] policy: recommendation for access requestor 10.10.1.40 is allow
1021 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IMV] policy: imv_policy_manager stop successful
1022 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IMV] IMV 1 "Attestation" changed state of Connection ID 2 to 'Allowed'
1023 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] PB-TNC state transition from 'Server Working' to 'Decided'
1024 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] creating PB-TNC RESULT batch
1025 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] adding IETF/PB-PA message
1026 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] adding IETF/PB-Assessment-Result message
1027 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] adding IETF/PB-Access-Recommendation message
1028 5 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[TNC] sending PB-TNC RESULT batch (88 bytes) for Connection ID 2
1029 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
1030 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[ENC] generating IKE_AUTH request 111 [ EAP/RES/TTLS ]
1031 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 07[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes)
1032 11 Andreas Steffen
</pre>
1033 11 Andreas Steffen
1034 12 Andreas Steffen
<pre>
1035 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (176 bytes)
1036 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[ENC] parsed IKE_AUTH response 111 [ EAP/REQ/TTLS ]
1037 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[IKE] received tunneled EAP-TTLS AVP [EAP/REQ/PT]
1038 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] received TNCCS batch (8 bytes)
1039 11 Andreas Steffen
</pre>
1040 11 Andreas Steffen
1041 11 Andreas Steffen
<pre>
1042 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] TNC server is handling inbound connection
1043 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] processing PB-TNC CLOSE batch for Connection ID 2
1044 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] PB-TNC state transition from 'Decided' to 'End'
1045 11 Andreas Steffen
</pre>
1046 11 Andreas Steffen
1047 11 Andreas Steffen
<pre>
1048 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] TNC client is handling outbound connection
1049 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] PB-TNC state transition from 'Decided' to 'End'
1050 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] creating PB-TNC CLOSE batch
1051 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[TNC] sending PB-TNC CLOSE batch (8 bytes) for Connection ID 1
1052 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[IKE] sending tunneled EAP-TTLS AVP [EAP/RES/PT]
1053 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[ENC] generating IKE_AUTH request 112 [ EAP/RES/TTLS ]
1054 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 11[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (176 bytes)
1055 11 Andreas Steffen
</pre>
1056 11 Andreas Steffen
1057 11 Andreas Steffen
<pre>
1058 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 05[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
1059 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 05[ENC] parsed IKE_AUTH response 112 [ EAP/SUCC ]
1060 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 05[IKE] EAP method EAP_TTLS succeeded, MSK established
1061 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 05[IKE] authentication of 'raspi3.example.com' (myself) with EAP
1062 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 05[ENC] generating IKE_AUTH request 113 [ AUTH ]
1063 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 05[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (112 bytes)
1064 11 Andreas Steffen
</pre>
1065 11 Andreas Steffen
1066 11 Andreas Steffen
<pre>
1067 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (240 bytes)
1068 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[ENC] parsed IKE_AUTH response 113 [ AUTH N(USE_TRANSP) SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(NO_ADD_ADDR) ]
1069 11 Andreas Steffen
</pre>
1070 11 Andreas Steffen
1071 11 Andreas Steffen
<pre>
1072 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] authentication of 'raspi4.example.com' with EAP successful
1073 11 Andreas Steffen
</pre>
1074 11 Andreas Steffen
1075 11 Andreas Steffen
<pre>
1076 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IMV] IMV 1 "Attestation" deleted the state of Connection ID 2
1077 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[TNC] removed TNCCS Connection ID 2
1078 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IMC] IMC 1 "OS" deleted the state of Connection ID 1
1079 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IMC] IMC 2 "Attestation" deleted the state of Connection ID 1
1080 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[TNC] removed TNCCS Connection ID 1
1081 11 Andreas Steffen
</pre>
1082 11 Andreas Steffen
1083 11 Andreas Steffen
<pre>
1084 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] IKE_SA peer[1] established between 10.10.1.39[raspi3.example.com]...10.10.1.40[raspi4.example.com]
1085 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] scheduling reauthentication in 10132s
1086 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] maximum IKE_SA lifetime 10672s
1087 2 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] CHILD_SA peer{1} established with SPIs c12c1aae_i ce21eedf_o and TS 10.10.1.39/32 === 10.10.1.40/32 
1088 1 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] received AUTH_LIFETIME of 10143s, scheduling reauthentication in 9603s
1089 1 Andreas Steffen
Aug 15 14:46:25 raspi3 charon: 12[IKE] peer supports MOBIKE
1090 2 Andreas Steffen
</pre>
1091 11 Andreas Steffen
1092 15 Andreas Steffen
h2. Terminating the IPsec Connection
1093 15 Andreas Steffen
1094 11 Andreas Steffen
<pre>
1095 2 Andreas Steffen
Aug 15 14:49:04 raspi3 charon: 13[CFG] received stroke: terminate 'peer'
1096 2 Andreas Steffen
Aug 15 14:49:04 raspi3 charon: 15[IKE] deleting IKE_SA peer[1] between 10.10.1.39[raspi3.example.com]...10.10.1.40[raspi4.example.com]
1097 2 Andreas Steffen
Aug 15 14:49:04 raspi3 charon: 15[IKE] sending DELETE for IKE_SA peer[1]
1098 2 Andreas Steffen
Aug 15 14:49:04 raspi3 charon: 15[ENC] generating INFORMATIONAL request 114 [ D ]
1099 2 Andreas Steffen
Aug 15 14:49:04 raspi3 charon: 15[NET] sending packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes)
1100 1 Andreas Steffen
Aug 15 14:49:05 raspi3 charon: 09[NET] received packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes)
1101 1 Andreas Steffen
Aug 15 14:49:05 raspi3 charon: 09[ENC] parsed INFORMATIONAL response 114 [ ]
1102 2 Andreas Steffen
Aug 15 14:49:05 raspi3 charon: 09[IKE] IKE_SA deleted
1103 2 Andreas Steffen
</pre>
1104 11 Andreas Steffen
1105 16 Andreas Steffen
h2. Stopping the IKEv2 Daemon
1106 15 Andreas Steffen
1107 11 Andreas Steffen
<pre>
1108 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[DMN] signal of type SIGINT received. Shutting down
1109 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[IMC] IMC 2 "Attestation" terminated
1110 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[IMC] IMC 1 "OS" terminated
1111 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[IMV] IMV 1 "Attestation" terminated
1112 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[PTS] removed TCG functional component namespace
1113 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[PTS] removed ITA-HSR functional component namespace
1114 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[TNC] removed IETF attributes
1115 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[TNC] removed ITA-HSR attributes
1116 2 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[TNC] removed TCG attributes
1117 1 Andreas Steffen
Aug 15 14:49:08 raspi3 charon: 00[LIB] libimcv terminated
1118 1 Andreas Steffen
</pre>