Raspi 4 - Responding IoT Device » History » Version 19
Andreas Steffen, 15.08.2015 21:51
1 | 4 | Andreas Steffen | {{>toc}} |
---|---|---|---|
2 | 4 | Andreas Steffen | |
3 | 1 | Andreas Steffen | h1. Raspi 4 - Responding IoT Device |
4 | 1 | Andreas Steffen | |
5 | 6 | Andreas Steffen | h2. Configuration Files |
6 | 6 | Andreas Steffen | |
7 | 1 | Andreas Steffen | strongSwan IPsec configuration file */etc/ipsec.conf* |
8 | 1 | Andreas Steffen | <pre> |
9 | 1 | Andreas Steffen | config setup |
10 | 1 | Andreas Steffen | charondebug="tnc 2, imc 2, imv 2, pts 3" |
11 | 1 | Andreas Steffen | |
12 | 1 | Andreas Steffen | conn %default |
13 | 1 | Andreas Steffen | ike=aes128-sha256-ecp256! |
14 | 1 | Andreas Steffen | esp=aes128-sha256-ecp256! |
15 | 1 | Andreas Steffen | keyexchange=ikev2 |
16 | 1 | Andreas Steffen | |
17 | 1 | Andreas Steffen | conn peer |
18 | 1 | Andreas Steffen | left=10.10.1.40 |
19 | 1 | Andreas Steffen | leftauth=eap-ttls |
20 | 1 | Andreas Steffen | leftcert=raspi4Cert.pem |
21 | 1 | Andreas Steffen | leftid=raspi4.example.com |
22 | 1 | Andreas Steffen | leftfirewall=yes |
23 | 1 | Andreas Steffen | right=10.10.1.39 |
24 | 1 | Andreas Steffen | rightauth=eap-ttls |
25 | 1 | Andreas Steffen | rightid=raspi3.example.com |
26 | 1 | Andreas Steffen | type=transport |
27 | 1 | Andreas Steffen | auto=add |
28 | 1 | Andreas Steffen | </pre> |
29 | 1 | Andreas Steffen | |
30 | 1 | Andreas Steffen | strongSwan IPsec secrets file */etc/ipsec.secrets* |
31 | 1 | Andreas Steffen | <pre> |
32 | 1 | Andreas Steffen | : RSA raspi4Key.pem |
33 | 1 | Andreas Steffen | </pre> |
34 | 1 | Andreas Steffen | |
35 | 1 | Andreas Steffen | strongSwan configuration file */etc/strongswan.conf* |
36 | 1 | Andreas Steffen | <pre> |
37 | 1 | Andreas Steffen | charon { |
38 | 1 | Andreas Steffen | load = random nonce x509 revocation constraints pkcs1 pkcs8 pem openssl pubkey tnc-imc tnc-imv tnc-tnccs tnccs-20 eap-identity eap-ttls eap-tnc sqlite curl kernel-netlink socket-default updown stroke |
39 | 1 | Andreas Steffen | |
40 | 1 | Andreas Steffen | half_open_timeout = 90 |
41 | 1 | Andreas Steffen | |
42 | 1 | Andreas Steffen | plugins { |
43 | 1 | Andreas Steffen | eap-ttls |
44 | 1 | Andreas Steffen | { |
45 | 1 | Andreas Steffen | max_message_count = 0 |
46 | 1 | Andreas Steffen | request_peer_auth = yes |
47 | 1 | Andreas Steffen | phase2_piggyback = yes |
48 | 1 | Andreas Steffen | phase2_tnc = yes |
49 | 1 | Andreas Steffen | } |
50 | 1 | Andreas Steffen | eap-tnc { |
51 | 1 | Andreas Steffen | max_message_count = 0 |
52 | 1 | Andreas Steffen | } |
53 | 1 | Andreas Steffen | tnccs-20 { |
54 | 1 | Andreas Steffen | mutual = yes |
55 | 1 | Andreas Steffen | } |
56 | 1 | Andreas Steffen | } |
57 | 1 | Andreas Steffen | } |
58 | 1 | Andreas Steffen | |
59 | 1 | Andreas Steffen | libimcv { |
60 | 1 | Andreas Steffen | database = sqlite:///etc/pts/config.db |
61 | 1 | Andreas Steffen | policy_script = ipsec imv_policy_manager |
62 | 1 | Andreas Steffen | |
63 | 1 | Andreas Steffen | plugins { |
64 | 1 | Andreas Steffen | imc-os { |
65 | 1 | Andreas Steffen | device_pubkey = /etc/pts/aik4Pub.der |
66 | 1 | Andreas Steffen | } |
67 | 1 | Andreas Steffen | imc-attestation { |
68 | 1 | Andreas Steffen | aik_blob = /etc/pts/aik4Blob.bin |
69 | 1 | Andreas Steffen | aik_cert = /etc/pts/aik4Cert.der |
70 | 1 | Andreas Steffen | } |
71 | 1 | Andreas Steffen | imv-attestation { |
72 | 1 | Andreas Steffen | cadir = /etc/pts/cacerts |
73 | 1 | Andreas Steffen | hash_algorithm = sha1 |
74 | 1 | Andreas Steffen | } |
75 | 1 | Andreas Steffen | } |
76 | 1 | Andreas Steffen | } |
77 | 1 | Andreas Steffen | |
78 | 1 | Andreas Steffen | libtls { |
79 | 1 | Andreas Steffen | suites = TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 |
80 | 1 | Andreas Steffen | } |
81 | 1 | Andreas Steffen | |
82 | 1 | Andreas Steffen | pt-tls-client { |
83 | 1 | Andreas Steffen | load = random nonce x509 revocation constraints pkcs1 pkcs8 pem openssl pubkey tnc-imc tnc-imv tnc-tnccs tnccs-20 curl |
84 | 1 | Andreas Steffen | } |
85 | 1 | Andreas Steffen | |
86 | 1 | Andreas Steffen | attest { |
87 | 1 | Andreas Steffen | database=sqlite:///etc/pts/config.db |
88 | 1 | Andreas Steffen | } |
89 | 1 | Andreas Steffen | </pre> |
90 | 1 | Andreas Steffen | |
91 | 6 | Andreas Steffen | h2. Starting the IKEv2 Daemon |
92 | 6 | Andreas Steffen | |
93 | 6 | Andreas Steffen | First the IKEv2 charon daemon is started in the background |
94 | 1 | Andreas Steffen | <pre> |
95 | 6 | Andreas Steffen | raspi4# ipsec start |
96 | 6 | Andreas Steffen | </pre> |
97 | 6 | Andreas Steffen | |
98 | 6 | Andreas Steffen | <pre> |
99 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[DMN] Starting IKE charon daemon (strongSwan 5.3.1, Linux 3.18.13-v7+, armv7l) |
100 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] TNC recommendation policy is 'default' |
101 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] loading IMVs from '/etc/tnc_config' |
102 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] added IETF attributes |
103 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] added ITA-HSR attributes |
104 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] added TCG attributes |
105 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] added TCG functional component namespace |
106 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] added ITA-HSR functional component namespace |
107 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] added ITA-HSR functional component 'Trusted GRUB Boot Loader' |
108 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] added ITA-HSR functional component 'Trusted Boot' |
109 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] added ITA-HSR functional component 'Linux IMA' |
110 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[LIB] libimcv initialized |
111 | 6 | Andreas Steffen | </pre> |
112 | 6 | Andreas Steffen | |
113 | 6 | Andreas Steffen | Loading Attestation IMV |
114 | 6 | Andreas Steffen | <pre> |
115 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[IMV] IMV 1 "Attestation" initialized |
116 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] loading PTS ca certificates from '/etc/pts/cacerts' |
117 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] loaded ca certificate "C=US, O=TNC Demo, CN=AIK CA" from '/etc/pts/cacerts/aikCaCert.pem' |
118 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] mandatory PTS measurement algorithm HASH_SHA1[openssl] available |
119 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] mandatory PTS measurement algorithm HASH_SHA256[openssl] available |
120 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS measurement algorithm HASH_SHA384[openssl] available |
121 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group MODP_2048[openssl] available |
122 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group MODP_1536[openssl] available |
123 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group MODP_1024[openssl] available |
124 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] mandatory PTS DH group ECP_256[openssl] available |
125 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group ECP_384[openssl] available |
126 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] IMV 1 supports 2 message types: 'TCG/PTS' 0x005597/0x00000001 'IETF/Operating System' 0x000000/0x00000001 |
127 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] IMV 1 "Attestation" loaded from '/usr/lib/ipsec/imcvs/imv-attestation.so' |
128 | 6 | Andreas Steffen | </pre> |
129 | 6 | Andreas Steffen | |
130 | 6 | Andreas Steffen | Loading OS IMC |
131 | 6 | Andreas Steffen | <pre> |
132 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] loading IMCs from '/etc/tnc_config' |
133 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[IMC] IMC 1 "OS" initialized |
134 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[IMC] processing "/etc/debian_version" file |
135 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[IMC] operating system name is 'Debian' |
136 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[IMC] operating system version is '7.8 armv7l' |
137 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] IMC 1 supports 1 message type: 'IETF/Operating System' 0x000000/0x00000001 |
138 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] IMC 1 "OS" loaded from '/usr/lib/ipsec/imcvs/imc-os.so' |
139 | 6 | Andreas Steffen | </pre> |
140 | 6 | Andreas Steffen | |
141 | 6 | Andreas Steffen | Loading Attestation IMC |
142 | 6 | Andreas Steffen | <pre> |
143 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[IMC] IMC 2 "Attestation" initialized |
144 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] mandatory PTS measurement algorithm HASH_SHA1[openssl] available |
145 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] mandatory PTS measurement algorithm HASH_SHA256[openssl] available |
146 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS measurement algorithm HASH_SHA384[openssl] available |
147 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group MODP_2048[openssl] available |
148 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group MODP_1536[openssl] available |
149 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group MODP_1024[openssl] available |
150 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] mandatory PTS DH group ECP_256[openssl] available |
151 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[PTS] optional PTS DH group ECP_384[openssl] available |
152 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] IMC 2 supports 1 message type: 'TCG/PTS' 0x005597/0x00000001 |
153 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[TNC] IMC 2 "Attestation" loaded from '/usr/lib/ipsec/imcvs/imc-attestation.so' |
154 | 6 | Andreas Steffen | </pre> |
155 | 6 | Andreas Steffen | |
156 | 6 | Andreas Steffen | Initializing IKE daemon |
157 | 6 | Andreas Steffen | <pre> |
158 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts' |
159 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loaded ca certificate "C=US, O=TNC Demo, CN=TNC Demo CA" from '/etc/ipsec.d/cacerts/demoCaCert.pem' |
160 | 6 | Andreas Steffen | '/etc/ipsec.d/cacerts/MSE_CA_Cert.pem' |
161 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts' |
162 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts' |
163 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts' |
164 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loading crls from '/etc/ipsec.d/crls' |
165 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loading secrets from '/etc/ipsec.secrets' |
166 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[CFG] loaded RSA private key from '/etc/ipsec.d/private/raspi4Key.pem' |
167 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[LIB] loaded plugins: charon random nonce x509 revocation constraints pkcs1 pkcs8 pem openssl pubkey tnc-imc tnc-imv tnc-tnccs tnccs-20 eap-identity eap-ttls eap-tnc sqlite curl kernel-netlink socket-default updown stroke |
168 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 00[JOB] spawning 16 worker threads |
169 | 6 | Andreas Steffen | </pre> |
170 | 6 | Andreas Steffen | |
171 | 6 | Andreas Steffen | Loading *peer* IPsec connection |
172 | 6 | Andreas Steffen | <pre> |
173 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 06[CFG] received stroke: add connection 'peer' |
174 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 06[CFG] loaded certificate "C=US, O=TNC Demo, CN=raspi4.example.com" from 'raspi4Cert.pem' |
175 | 1 | Andreas Steffen | Aug 15 14:45:49 raspi4 charon: 06[CFG] added configuration 'peer' |
176 | 6 | Andreas Steffen | </pre> |
177 | 6 | Andreas Steffen | |
178 | 6 | Andreas Steffen | h2. Responding to IPsec Connection Setup |
179 | 6 | Andreas Steffen | |
180 | 6 | Andreas Steffen | <pre> |
181 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 07[NET] received packet: from 10.10.1.39[500] to 10.10.1.40[500] (256 bytes) |
182 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 07[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(HASH_ALG) ] |
183 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 07[IKE] 10.10.1.39 is initiating an IKE_SA |
184 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 07[IKE] sending cert request for "C=US, O=TNC Demo, CN=TNC Demo CA" |
185 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 07[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(HASH_ALG) N(MULT_AUTH) ] |
186 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 07[NET] sending packet: from 10.10.1.40[500] to 10.10.1.39[500] (309 bytes) |
187 | 6 | Andreas Steffen | </pre> |
188 | 6 | Andreas Steffen | |
189 | 6 | Andreas Steffen | <pre> |
190 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (304 bytes) |
191 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[ENC] parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) CERTREQ IDr N(USE_TRANSP) SA TSi TSr N(MOBIKE_SUP) N(NO_ADD_ADDR) N(MULT_AUTH) N(EAP_ONLY) ] |
192 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[IKE] received cert request for "C=US, O=TNC Demo, CN=TNC Demo CA" |
193 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[CFG] looking for peer configs matching 10.10.1.40[raspi4.example.com]...10.10.1.39[raspi3.example.com] |
194 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[CFG] selected peer config 'peer' |
195 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[IKE] initiating EAP_TTLS method (id 0xDB) |
196 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[IKE] peer supports MOBIKE |
197 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[ENC] generating IKE_AUTH response 1 [ IDr EAP/REQ/TTLS ] |
198 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 08[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (112 bytes) |
199 | 6 | Andreas Steffen | </pre> |
200 | 6 | Andreas Steffen | |
201 | 6 | Andreas Steffen | <pre> |
202 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (208 bytes) |
203 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[ENC] parsed IKE_AUTH request 2 [ EAP/RES/TTLS ] |
204 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[TLS] negotiated TLS 1.2 using suite TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 |
205 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[TLS] sending TLS server certificate 'C=US, O=TNC Demo, CN=raspi4.example.com' |
206 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[TLS] sending TLS cert request for 'C=CH, O=MSE, OU=TSM_ITSec, CN=MSE CA' |
207 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[TLS] sending TLS cert request for 'C=US, O=TNC Demo, CN=TNC Demo CA' |
208 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[ENC] generating IKE_AUTH response 2 [ EAP/REQ/TTLS ] |
209 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 09[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes) |
210 | 6 | Andreas Steffen | </pre> |
211 | 6 | Andreas Steffen | |
212 | 6 | Andreas Steffen | <pre> |
213 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 10[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
214 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 10[ENC] parsed IKE_AUTH request 3 [ EAP/RES/TTLS ] |
215 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 10[ENC] generating IKE_AUTH response 3 [ EAP/REQ/TTLS ] |
216 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 10[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (480 bytes) |
217 | 6 | Andreas Steffen | </pre> |
218 | 6 | Andreas Steffen | |
219 | 6 | Andreas Steffen | <pre> |
220 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 11[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
221 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 11[ENC] parsed IKE_AUTH request 4 [ EAP/RES/TTLS ] |
222 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 11[ENC] generating IKE_AUTH response 4 [ EAP/REQ/TTLS ] |
223 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 11[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
224 | 6 | Andreas Steffen | </pre> |
225 | 6 | Andreas Steffen | |
226 | 6 | Andreas Steffen | <pre> |
227 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (352 bytes) |
228 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[ENC] parsed IKE_AUTH request 5 [ EAP/RES/TTLS ] |
229 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[TLS] received TLS peer certificate 'C=US, O=TNC Demo, CN=raspi3.example.com' |
230 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[CFG] using certificate "C=US, O=TNC Demo, CN=raspi3.example.com" |
231 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[CFG] using trusted ca certificate "C=US, O=TNC Demo, CN=TNC Demo CA" |
232 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[CFG] checking certificate status of "C=US, O=TNC Demo, CN=raspi3.example.com" |
233 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[CFG] certificate status is not available |
234 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[CFG] reached self-signed root ca with a path length of 0 |
235 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/ID] |
236 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[ENC] generating IKE_AUTH response 5 [ EAP/REQ/TTLS ] |
237 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 12[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes) |
238 | 6 | Andreas Steffen | </pre> |
239 | 6 | Andreas Steffen | |
240 | 6 | Andreas Steffen | <pre> |
241 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (192 bytes) |
242 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[ENC] parsed IKE_AUTH request 6 [ EAP/RES/TTLS ] |
243 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[IKE] received tunneled EAP-TTLS AVP [EAP/RES/ID] |
244 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[IKE] received EAP identity 'raspi3.example.com' |
245 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[IKE] phase2 method EAP_PT_EAP selected |
246 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
247 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[ENC] generating IKE_AUTH response 6 [ EAP/REQ/TTLS ] |
248 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 13[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (176 bytes) |
249 | 6 | Andreas Steffen | </pre> |
250 | 6 | Andreas Steffen | |
251 | 6 | Andreas Steffen | <pre> |
252 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (448 bytes) |
253 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[ENC] parsed IKE_AUTH request 7 [ EAP/RES/TTLS ] |
254 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
255 | 6 | Andreas Steffen | </pre> |
256 | 6 | Andreas Steffen | |
257 | 10 | Andreas Steffen | h2. Start of Mutual Attestation |
258 | 10 | Andreas Steffen | |
259 | 6 | Andreas Steffen | <pre> |
260 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] assigned TNCCS Connection ID 1 |
261 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] IMV 1 "Attestation" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh |
262 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes |
263 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] user AR identity 'raspi3.example.com' of type username authenticated by certificate |
264 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] machine AR identity '10.10.1.39' of type IPv4 address authenticated by unknown method |
265 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] IMV 1 "Attestation" changed state of Connection ID 1 to 'Handshake' |
266 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] received TNCCS batch (283 bytes) |
267 | 6 | Andreas Steffen | </pre> |
268 | 6 | Andreas Steffen | |
269 | 6 | Andreas Steffen | <pre> |
270 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] TNC server is handling inbound connection |
271 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PB-TNC CDATA batch for Connection ID 1 |
272 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] PB-TNC state transition from 'Init' to 'Server Working' |
273 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing ITA-HSR/PB-Mutual-Capability message (16 bytes) |
274 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing IETF/PB-Language-Preference message (31 bytes) |
275 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing IETF/PB-PA message (228 bytes) |
276 | 6 | Andreas Steffen | </pre> |
277 | 6 | Andreas Steffen | |
278 | 6 | Andreas Steffen | <pre> |
279 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] activating mutual PB-TNC half duplex protocol |
280 | 6 | Andreas Steffen | </pre> |
281 | 6 | Andreas Steffen | |
282 | 7 | Andreas Steffen | <pre> |
283 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] setting language preference to 'en' |
284 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] handling PB-PA message type 'IETF/Operating System' 0x000000/0x00000001 |
285 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] IMV 1 "Attestation" received message for Connection ID 1 from IMC 1 |
286 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC message with ID 0x83cf019d |
287 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002 |
288 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004 |
289 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003 |
290 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005 |
291 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b |
292 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c |
293 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[TNC] processing PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008 |
294 | 6 | Andreas Steffen | </pre> |
295 | 6 | Andreas Steffen | |
296 | 6 | Andreas Steffen | <pre> |
297 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] operating system name is 'Debian' from vendor Debian Project |
298 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] operating system version is '7.8 armv7l' |
299 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] device ID is 565feb9e8462870dba884ce540a0768d68829873 |
300 | 6 | Andreas Steffen | </pre> |
301 | 6 | Andreas Steffen | |
302 | 6 | Andreas Steffen | <pre> |
303 | 1 | Andreas Steffen | Aug 15 14:46:05 raspi4 charon: 14[IMV] assigned session ID 3 to Connection ID 1 |
304 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] policy: imv_policy_manager start successful |
305 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] policy: skipping enforcment 6 |
306 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] FWDEN workitem 13 |
307 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] FMETA workitem 14 |
308 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] PCKGS workitem 15 |
309 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] TCPOP workitem 16 |
310 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] UDPOP workitem 17 |
311 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] TPMRA workitem 18 |
312 | 6 | Andreas Steffen | </pre> |
313 | 6 | Andreas Steffen | |
314 | 6 | Andreas Steffen | <pre> |
315 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] IMV 1 requests a segmentation contract for PA message type 'TCG/PTS' 0x005597/0x00000001 |
316 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IMV] maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes |
317 | 6 | Andreas Steffen | </pre> |
318 | 6 | Andreas Steffen | |
319 | 6 | Andreas Steffen | <pre> |
320 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] creating PA-TNC message with ID 0x42501f74 |
321 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021 |
322 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] creating PA-TNC attribute type 'TCG/Request PTS Protocol Capabilities' 0x005597/0x01000000 |
323 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] creating PA-TNC attribute type 'TCG/PTS Measurement Algorithm Request' 0x005597/0x06000000 |
324 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
325 | 6 | Andreas Steffen | </pre> |
326 | 6 | Andreas Steffen | |
327 | 6 | Andreas Steffen | <pre> |
328 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] TNC server is handling outbound connection |
329 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
330 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] creating PB-TNC SDATA batch |
331 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] adding ITA-HSR/PB-Mutual-Capability message |
332 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] adding IETF/PB-PA message |
333 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[TNC] sending PB-TNC SDATA batch (108 bytes) for Connection ID 1 |
334 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
335 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[ENC] generating IKE_AUTH response 7 [ EAP/REQ/TTLS ] |
336 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 14[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (272 bytes) |
337 | 6 | Andreas Steffen | </pre> |
338 | 6 | Andreas Steffen | |
339 | 6 | Andreas Steffen | <pre> |
340 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (176 bytes) |
341 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[ENC] parsed IKE_AUTH request 8 [ EAP/RES/TTLS ] |
342 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
343 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] received TNCCS batch (8 bytes) |
344 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] assigned TNCCS Connection ID 2 |
345 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] IMC 1 "OS" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh |
346 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes |
347 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[PTS] loaded AIK certificate from '/etc/pts/aik4Cert.der' |
348 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[PTS] loaded AIK Blob from '/etc/pts/aik4Blob.bin' |
349 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] IMC 2 "Attestation" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh |
350 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes |
351 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] IMC 1 "OS" changed state of Connection ID 2 to 'Handshake' |
352 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] IMC 2 "Attestation" changed state of Connection ID 2 to 'Handshake' |
353 | 6 | Andreas Steffen | </pre> |
354 | 6 | Andreas Steffen | |
355 | 6 | Andreas Steffen | <pre> |
356 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] operating system numeric version is 7.8 |
357 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] last boot: Aug 15 07:56:45 UTC 2015, 17363 s ago |
358 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] IPv4 forwarding is disabled |
359 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] factory default password is disabled |
360 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] loaded device public key from '/etc/pts/aik4Pub.der' |
361 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IMC] device ID is 762872c90011671ef219b6a2a0c3c7dda875b43c |
362 | 6 | Andreas Steffen | </pre> |
363 | 6 | Andreas Steffen | |
364 | 6 | Andreas Steffen | <pre> |
365 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC message with ID 0x366c28ea |
366 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002 |
367 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004 |
368 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003 |
369 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005 |
370 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b |
371 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c |
372 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008 |
373 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001 |
374 | 6 | Andreas Steffen | </pre> |
375 | 6 | Andreas Steffen | |
376 | 6 | Andreas Steffen | <pre> |
377 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] TNC client is handling inbound connection |
378 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] processing PB-TNC SDATA batch for Connection ID 2 |
379 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] PB-TNC state transition from 'Init' to 'Client Working' |
380 | 9 | Andreas Steffen | </pre> |
381 | 9 | Andreas Steffen | |
382 | 9 | Andreas Steffen | <pre> |
383 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] TNC client is handling outbound connection |
384 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
385 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] creating PB-TNC CDATA batch |
386 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] adding IETF/PB-Language-Preference message |
387 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] adding IETF/PB-PA message |
388 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[TNC] sending PB-TNC CDATA batch (267 bytes) for Connection ID 2 |
389 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
390 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[ENC] generating IKE_AUTH response 8 [ EAP/REQ/TTLS ] |
391 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 15[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (432 bytes) |
392 | 6 | Andreas Steffen | </pre> |
393 | 6 | Andreas Steffen | |
394 | 6 | Andreas Steffen | <pre> |
395 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes) |
396 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[ENC] parsed IKE_AUTH request 9 [ EAP/RES/TTLS ] |
397 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
398 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] received TNCCS batch (92 bytes) |
399 | 6 | Andreas Steffen | </pre> |
400 | 6 | Andreas Steffen | |
401 | 6 | Andreas Steffen | <pre> |
402 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] TNC server is handling inbound connection |
403 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] processing PB-TNC CDATA batch for Connection ID 1 |
404 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
405 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] processing IETF/PB-PA message (84 bytes) |
406 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
407 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] IMV 1 "Attestation" received message for Connection ID 1 from IMC 2 to IMV 1 |
408 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] processing PA-TNC message with ID 0x1d5fa63a |
409 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022 |
410 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] processing PA-TNC attribute type 'TCG/PTS Protocol Capabilities' 0x005597/0x02000000 |
411 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] processing PA-TNC attribute type 'TCG/PTS Measurement Algorithm' 0x005597/0x07000000 |
412 | 6 | Andreas Steffen | </pre> |
413 | 6 | Andreas Steffen | |
414 | 6 | Andreas Steffen | <pre> |
415 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] IMV 1 received a segmentation contract response from IMC 2 for PA message type 'TCG/PTS' 0x005597/0x00000001 |
416 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes |
417 | 6 | Andreas Steffen | </pre> |
418 | 6 | Andreas Steffen | |
419 | 6 | Andreas Steffen | <pre> |
420 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[PTS] supported PTS protocol capabilities: .VDT. |
421 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[PTS] selected PTS measurement algorithm is HASH_SHA1 |
422 | 6 | Andreas Steffen | </pre> |
423 | 6 | Andreas Steffen | |
424 | 6 | Andreas Steffen | <pre> |
425 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] IMV 1 handles FMETA workitem 14 |
426 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] IMV 1 requests metadata for file '/etc/tnc_config' |
427 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] IMV 1 handled FMETA workitem 14: allow - file metadata requested |
428 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IMV] IMV 1 handles TPMRA workitem 18 |
429 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] creating PA-TNC message with ID 0xaff3c130 |
430 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] creating PA-TNC attribute type 'TCG/Request File Metadata' 0x005597/0x00700000 |
431 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] creating PA-TNC attribute type 'TCG/DH Nonce Parameters Request' 0x005597/0x03000000 |
432 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
433 | 6 | Andreas Steffen | </pre> |
434 | 6 | Andreas Steffen | |
435 | 6 | Andreas Steffen | <pre> |
436 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] TNC server is handling outbound connection |
437 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
438 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] creating PB-TNC SDATA batch |
439 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] adding IETF/PB-PA message |
440 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[TNC] sending PB-TNC SDATA batch (87 bytes) for Connection ID 1 |
441 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
442 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[ENC] generating IKE_AUTH response 9 [ EAP/REQ/TTLS ] |
443 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 16[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes) |
444 | 11 | Andreas Steffen | </pre> |
445 | 11 | Andreas Steffen | |
446 | 11 | Andreas Steffen | <pre> |
447 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes) |
448 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[ENC] parsed IKE_AUTH request 10 [ EAP/RES/TTLS ] |
449 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
450 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] received TNCCS batch (92 bytes) |
451 | 9 | Andreas Steffen | </pre> |
452 | 9 | Andreas Steffen | |
453 | 9 | Andreas Steffen | <pre> |
454 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] TNC client is handling inbound connection |
455 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] processing PB-TNC SDATA batch for Connection ID 2 |
456 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
457 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] processing IETF/PB-PA message (84 bytes) |
458 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
459 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[IMC] IMC 2 "Attestation" received message for Connection ID 2 from IMV 1 |
460 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] processing PA-TNC message with ID 0x918da8fe |
461 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021 |
462 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] processing PA-TNC attribute type 'TCG/Request PTS Protocol Capabilities' 0x005597/0x01000000 |
463 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] processing PA-TNC attribute type 'TCG/PTS Measurement Algorithm Request' 0x005597/0x06000000 |
464 | 11 | Andreas Steffen | </pre> |
465 | 11 | Andreas Steffen | |
466 | 11 | Andreas Steffen | <pre> |
467 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[IMC] IMC 2 received a segmentation contract request from IMV 1 for PA message type 'TCG/PTS' 0x005597/0x00000001 |
468 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[IMC] maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes |
469 | 11 | Andreas Steffen | </pre> |
470 | 11 | Andreas Steffen | |
471 | 11 | Andreas Steffen | <pre> |
472 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[PTS] supported PTS protocol capabilities: .VDT. |
473 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[PTS] selected PTS measurement algorithm is HASH_SHA1 |
474 | 11 | Andreas Steffen | </pre> |
475 | 11 | Andreas Steffen | |
476 | 11 | Andreas Steffen | <pre> |
477 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] creating PA-TNC message with ID 0xf94741eb |
478 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022 |
479 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] creating PA-TNC attribute type 'TCG/PTS Protocol Capabilities' 0x005597/0x02000000 |
480 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] creating PA-TNC attribute type 'TCG/PTS Measurement Algorithm' 0x005597/0x07000000 |
481 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
482 | 9 | Andreas Steffen | </pre> |
483 | 9 | Andreas Steffen | |
484 | 9 | Andreas Steffen | <pre> |
485 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] TNC client is handling outbound connection |
486 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
487 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] creating PB-TNC CDATA batch |
488 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] adding IETF/PB-PA message |
489 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[TNC] sending PB-TNC CDATA batch (92 bytes) for Connection ID 2 |
490 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
491 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[ENC] generating IKE_AUTH response 10 [ EAP/REQ/TTLS ] |
492 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 05[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes) |
493 | 11 | Andreas Steffen | </pre> |
494 | 11 | Andreas Steffen | |
495 | 11 | Andreas Steffen | <pre> |
496 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (400 bytes) |
497 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[ENC] parsed IKE_AUTH request 11 [ EAP/RES/TTLS ] |
498 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
499 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] received TNCCS batch (226 bytes) |
500 | 9 | Andreas Steffen | </pre> |
501 | 9 | Andreas Steffen | |
502 | 9 | Andreas Steffen | <pre> |
503 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] TNC server is handling inbound connection |
504 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] processing PB-TNC CDATA batch for Connection ID 1 |
505 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
506 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] processing IETF/PB-PA message (218 bytes) |
507 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
508 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[IMV] IMV 1 "Attestation" received message for Connection ID 1 from IMC 2 to IMV 1 |
509 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] processing PA-TNC message with ID 0x5e3ee705 |
510 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] processing PA-TNC attribute type 'TCG/Unix-Style File Metadata' 0x005597/0x00900000 |
511 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] processing PA-TNC attribute type 'TCG/DH Nonce Parameters Response' 0x005597/0x04000000 |
512 | 11 | Andreas Steffen | </pre> |
513 | 11 | Andreas Steffen | |
514 | 11 | Andreas Steffen | <pre> |
515 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[IMV] metadata request returned 1 file: |
516 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[IMV] 'tnc_config' (177 bytes) owner 0, group 0, type Regular |
517 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[IMV] created Jun 05 20:02:25 2015, modified Jun 05 20:02:25 2015, accessed Jun 05 20:02:25 2015 |
518 | 11 | Andreas Steffen | </pre> |
519 | 11 | Andreas Steffen | |
520 | 11 | Andreas Steffen | <pre> |
521 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] selected DH hash algorithm is HASH_SHA1 |
522 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] selected PTS DH group is ECP_256 |
523 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] nonce length is 20 |
524 | 11 | Andreas Steffen | </pre> |
525 | 11 | Andreas Steffen | |
526 | 11 | Andreas Steffen | <pre> |
527 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] initiator nonce: => 20 bytes @ 0x1ab4f40 |
528 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 0: 01 97 8C C2 90 09 6D 02 F0 0A 40 E1 8C 90 5F 15 ......m...@..._. |
529 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 16: FB 4E 28 AD .N(. |
530 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] responder nonce: => 20 bytes @ 0x1aafba0 |
531 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 0: 3D D0 72 39 3A E1 A0 E2 0B 30 B4 D4 D9 22 9F E0 =.r9:....0...".. |
532 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 16: B6 D1 2A 01 ..*. |
533 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] shared DH secret: => 32 bytes @ 0x1ab3078 |
534 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 0: 5F 0F D8 1E B5 39 B4 E2 86 BF 0C 92 9E E3 3A EA _....9........:. |
535 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 16: D7 23 93 EB C2 85 F5 09 EC DB C0 B1 E5 51 50 DE .#...........QP. |
536 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] secret assessment value: => 20 bytes @ 0x1ab4f28 |
537 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 0: D8 9D 1E 70 CE 78 C3 13 F2 79 BA 5D 7C E5 05 7C ...p.x...y.]|..| |
538 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[PTS] 16: E0 E0 83 77 ...w |
539 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] creating PA-TNC message with ID 0xd27d5b33 |
540 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] creating PA-TNC attribute type 'TCG/DH Nonce Finish' 0x005597/0x05000000 |
541 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] creating PA-TNC attribute type 'TCG/Get TPM Version Information' 0x005597/0x08000000 |
542 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] creating PA-TNC attribute type 'TCG/Get Attestation Identity Key' 0x005597/0x0d000000 |
543 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
544 | 9 | Andreas Steffen | </pre> |
545 | 9 | Andreas Steffen | |
546 | 9 | Andreas Steffen | <pre> |
547 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] TNC server is handling outbound connection |
548 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
549 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] creating PB-TNC SDATA batch |
550 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] adding IETF/PB-PA message |
551 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[TNC] sending PB-TNC SDATA batch (172 bytes) for Connection ID 1 |
552 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
553 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[ENC] generating IKE_AUTH response 11 [ EAP/REQ/TTLS ] |
554 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 06[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (336 bytes) |
555 | 11 | Andreas Steffen | </pre> |
556 | 11 | Andreas Steffen | |
557 | 11 | Andreas Steffen | <pre> |
558 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes) |
559 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[ENC] parsed IKE_AUTH request 12 [ EAP/RES/TTLS ] |
560 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
561 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] received TNCCS batch (87 bytes) |
562 | 9 | Andreas Steffen | </pre> |
563 | 9 | Andreas Steffen | |
564 | 9 | Andreas Steffen | <pre> |
565 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] TNC client is handling inbound connection |
566 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] processing PB-TNC SDATA batch for Connection ID 2 |
567 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
568 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] processing IETF/PB-PA message (79 bytes) |
569 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
570 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[IMC] IMC 2 "Attestation" received message for Connection ID 2 from IMV 1 |
571 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] processing PA-TNC message with ID 0xda2a70e9 |
572 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] processing PA-TNC attribute type 'TCG/Request File Metadata' 0x005597/0x00700000 |
573 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] processing PA-TNC attribute type 'TCG/DH Nonce Parameters Request' 0x005597/0x03000000 |
574 | 11 | Andreas Steffen | </pre> |
575 | 11 | Andreas Steffen | |
576 | 11 | Andreas Steffen | <pre> |
577 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[IMC] metadata request for file '/etc/tnc_config' |
578 | 11 | Andreas Steffen | </pre> |
579 | 11 | Andreas Steffen | |
580 | 11 | Andreas Steffen | <pre> |
581 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[PTS] selected PTS DH group is ECP_256 |
582 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[PTS] nonce length is 20 |
583 | 11 | Andreas Steffen | </pre> |
584 | 12 | Andreas Steffen | |
585 | 12 | Andreas Steffen | <pre> |
586 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] creating PA-TNC message with ID 0x676268aa |
587 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] creating PA-TNC attribute type 'TCG/Unix-Style File Metadata' 0x005597/0x00900000 |
588 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] creating PA-TNC attribute type 'TCG/DH Nonce Parameters Response' 0x005597/0x04000000 |
589 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
590 | 9 | Andreas Steffen | </pre> |
591 | 9 | Andreas Steffen | |
592 | 9 | Andreas Steffen | <pre> |
593 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] TNC client is handling outbound connection |
594 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
595 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] creating PB-TNC CDATA batch |
596 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] adding IETF/PB-PA message |
597 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[TNC] sending PB-TNC CDATA batch (226 bytes) for Connection ID 2 |
598 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
599 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[ENC] generating IKE_AUTH response 12 [ EAP/REQ/TTLS ] |
600 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 07[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (400 bytes) |
601 | 11 | Andreas Steffen | </pre> |
602 | 11 | Andreas Steffen | |
603 | 11 | Andreas Steffen | <pre> |
604 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1072 bytes) |
605 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[ENC] parsed IKE_AUTH request 13 [ EAP/RES/TTLS ] |
606 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
607 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] received TNCCS batch (902 bytes) |
608 | 9 | Andreas Steffen | </pre> |
609 | 9 | Andreas Steffen | |
610 | 9 | Andreas Steffen | <pre> |
611 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] TNC server is handling inbound connection |
612 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] processing PB-TNC CDATA batch for Connection ID 1 |
613 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
614 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] processing IETF/PB-PA message (894 bytes) |
615 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
616 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IMV] IMV 1 "Attestation" received message for Connection ID 1 from IMC 2 to IMV 1 |
617 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] processing PA-TNC message with ID 0x641bcea1 |
618 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/TPM Version Information' 0x005597/0x09000000 |
619 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Attestation Identity Key' 0x005597/0x0e000000 |
620 | 11 | Andreas Steffen | </pre> |
621 | 11 | Andreas Steffen | |
622 | 11 | Andreas Steffen | <pre> |
623 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[PTS] TPM Version Info: Chip Version: 1.2.133.32, Spec Level: 2, Errata Rev: 3, Vendor ID: IFX |
624 | 11 | Andreas Steffen | </pre> |
625 | 11 | Andreas Steffen | |
626 | 11 | Andreas Steffen | <pre> |
627 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IMV] verifying AIK with keyid 56:5f:eb:9e:84:62:87:0d:ba:88:4c:e5:40:a0:76:8d:68:82:98:73 |
628 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IMV] AIK public key is trusted |
629 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[CFG] using trusted certificate "C=US, O=TNC Demo, CN=AIK CA" |
630 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IMV] AIK certificate is trusted |
631 | 11 | Andreas Steffen | </pre> |
632 | 11 | Andreas Steffen | |
633 | 11 | Andreas Steffen | <pre> |
634 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IMV] evidence request by |
635 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
636 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] creating PA-TNC message with ID 0xed256fac |
637 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] creating PA-TNC attribute type 'TCG/Request Functional Component Evidence' 0x005597/0x00100000 |
638 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] creating PA-TNC attribute type 'TCG/Generate Attestation Evidence' 0x005597/0x00200000 |
639 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
640 | 9 | Andreas Steffen | </pre> |
641 | 9 | Andreas Steffen | |
642 | 9 | Andreas Steffen | <pre> |
643 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] TNC server is handling outbound connection |
644 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
645 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] creating PB-TNC SDATA batch |
646 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] adding IETF/PB-PA message |
647 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[TNC] sending PB-TNC SDATA batch (80 bytes) for Connection ID 1 |
648 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
649 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[ENC] generating IKE_AUTH response 13 [ EAP/REQ/TTLS ] |
650 | 1 | Andreas Steffen | Aug 15 14:46:08 raspi4 charon: 08[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes) |
651 | 11 | Andreas Steffen | </pre> |
652 | 11 | Andreas Steffen | |
653 | 11 | Andreas Steffen | <pre> |
654 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (336 bytes) |
655 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[ENC] parsed IKE_AUTH request 14 [ EAP/RES/TTLS ] |
656 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
657 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] received TNCCS batch (172 bytes) |
658 | 9 | Andreas Steffen | </pre> |
659 | 9 | Andreas Steffen | |
660 | 9 | Andreas Steffen | <pre> |
661 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] TNC client is handling inbound connection |
662 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] processing PB-TNC SDATA batch for Connection ID 2 |
663 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
664 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] processing IETF/PB-PA message (164 bytes) |
665 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
666 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[IMC] IMC 2 "Attestation" received message for Connection ID 2 from IMV 1 |
667 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] processing PA-TNC message with ID 0xe1b84e91 |
668 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] processing PA-TNC attribute type 'TCG/DH Nonce Finish' 0x005597/0x05000000 |
669 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] processing PA-TNC attribute type 'TCG/Get TPM Version Information' 0x005597/0x08000000 |
670 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] processing PA-TNC attribute type 'TCG/Get Attestation Identity Key' 0x005597/0x0d000000 |
671 | 11 | Andreas Steffen | </pre> |
672 | 11 | Andreas Steffen | |
673 | 11 | Andreas Steffen | <pre> |
674 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] selected DH hash algorithm is HASH_SHA1 |
675 | 11 | Andreas Steffen | </pre> |
676 | 11 | Andreas Steffen | |
677 | 13 | Andreas Steffen | <pre> |
678 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] initiator nonce: => 20 bytes @ 0x1ab0dc0 |
679 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 0: 27 B7 51 A0 C8 66 92 54 F0 57 C1 49 9D 2A 7D 3A '.Q..f.T.W.I.*}: |
680 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 16: F1 38 81 26 .8.& |
681 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] responder nonce: => 20 bytes @ 0x1ab2e48 |
682 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 0: 96 48 1F 52 8C A6 D5 6E 5F A4 17 2B AF BE 26 71 .H.R...n_..+..&q |
683 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 16: 49 73 01 42 Is.B |
684 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] shared DH secret: => 32 bytes @ 0x1aac378 |
685 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 0: AA FE 9F 01 D7 CC 22 17 FF 35 CF 9C 70 41 7B 11 ......"..5..pA{. |
686 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 16: D0 3C B6 32 BF 3D 80 BF 73 32 1E 95 F3 20 9E D1 .<.2.=..s2... .. |
687 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] secret assessment value: => 20 bytes @ 0x1ab0d20 |
688 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 0: B2 E0 AB DF 89 C5 1D B2 A3 51 FD A9 C8 3B F8 7F .........Q...;.. |
689 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] 16: 68 50 6C DE hPl. |
690 | 11 | Andreas Steffen | </pre> |
691 | 11 | Andreas Steffen | |
692 | 11 | Andreas Steffen | <pre> |
693 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[PTS] TPM Version Info: Chip Version: 1.2.133.32, Spec Level: 2, Errata Rev: 3, Vendor ID: IFX |
694 | 11 | Andreas Steffen | </pre> |
695 | 11 | Andreas Steffen | |
696 | 11 | Andreas Steffen | <pre> |
697 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] creating PA-TNC message with ID 0x951e0284 |
698 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] creating PA-TNC attribute type 'TCG/TPM Version Information' 0x005597/0x09000000 |
699 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] creating PA-TNC attribute type 'TCG/Attestation Identity Key' 0x005597/0x0e000000 |
700 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
701 | 9 | Andreas Steffen | </pre> |
702 | 9 | Andreas Steffen | |
703 | 9 | Andreas Steffen | <pre> |
704 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] TNC client is handling outbound connection |
705 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
706 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] creating PB-TNC CDATA batch |
707 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] adding IETF/PB-PA message |
708 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[TNC] sending PB-TNC CDATA batch (902 bytes) for Connection ID 2 |
709 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
710 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[ENC] generating IKE_AUTH response 14 [ EAP/REQ/TTLS ] |
711 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 09[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1072 bytes) |
712 | 14 | Andreas Steffen | </pre> |
713 | 14 | Andreas Steffen | |
714 | 14 | Andreas Steffen | <pre> |
715 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 10[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
716 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 10[ENC] parsed IKE_AUTH request 15 [ EAP/RES/TTLS ] |
717 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 10[ENC] generating IKE_AUTH response 15 [ EAP/REQ/TTLS ] |
718 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 10[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
719 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 11[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
720 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 11[ENC] parsed IKE_AUTH request 16 [ EAP/RES/TTLS ] |
721 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 11[ENC] generating IKE_AUTH response 16 [ EAP/REQ/TTLS ] |
722 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 11[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
723 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 12[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
724 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 12[ENC] parsed IKE_AUTH request 17 [ EAP/RES/TTLS ] |
725 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 12[ENC] generating IKE_AUTH response 17 [ EAP/REQ/TTLS ] |
726 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 12[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
727 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 13[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
728 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 13[ENC] parsed IKE_AUTH request 18 [ EAP/RES/TTLS ] |
729 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 13[ENC] generating IKE_AUTH response 18 [ EAP/REQ/TTLS ] |
730 | 1 | Andreas Steffen | Aug 15 14:46:09 raspi4 charon: 13[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
731 | 4 | Andreas Steffen | ... |
732 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 07[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
733 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 07[ENC] parsed IKE_AUTH request 60 [ EAP/RES/TTLS ] |
734 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 07[ENC] generating IKE_AUTH response 60 [ EAP/REQ/TTLS ] |
735 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 07[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
736 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (1104 bytes) |
737 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[ENC] parsed IKE_AUTH request 61 [ EAP/RES/TTLS ] |
738 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
739 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] received TNCCS batch (47615 bytes) |
740 | 9 | Andreas Steffen | </pre> |
741 | 9 | Andreas Steffen | |
742 | 9 | Andreas Steffen | <pre> |
743 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] TNC server is handling inbound connection |
744 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PB-TNC CDATA batch for Connection ID 1 |
745 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
746 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing IETF/PB-PA message (47607 bytes) |
747 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
748 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[IMV] IMV 1 "Attestation" received message for Connection ID 1 from IMC 2 to IMV 1 |
749 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC message with ID 0x2d059578 |
750 | 11 | Andreas Steffen | </pre> |
751 | 11 | Andreas Steffen | |
752 | 15 | Andreas Steffen | h3. Initiator Attestation Measurement Values |
753 | 15 | Andreas Steffen | |
754 | 11 | Andreas Steffen | <pre> |
755 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
756 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
757 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
758 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: dd:ee:60:04:dc:3b:d4:ee:30:04:06:cd:93:18:1c:5a:21:87:b5:9b |
759 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:boot_aggregate' |
760 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
761 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
762 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
763 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: 65:ee:0c:a2:cd:ac:0d:67:f8:1a:fd:53:7b:96:75:6f:3b:b8:0f:82 |
764 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:/init' |
765 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
766 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
767 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
768 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: 6b:a1:a0:58:89:a8:f2:57:53:42:b5:dc:5f:3e:de:54:89:8a:ee:29 |
769 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:/bin/sh' |
770 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
771 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
772 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
773 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: 85:e6:6e:7a:96:98:8b:0a:af:c8:88:46:5d:7a:fe:b5:e9:d3:c2:3e |
774 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:/lib/klibc-sO6SifHCdmbehHGtm0y1yHu6vb0.so' |
775 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
776 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
777 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
778 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: 68:4a:c3:8d:48:55:be:e0:21:93:4f:52:a0:d2:3d:66:86:0c:b2:82 |
779 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:/bin/mkdir' |
780 | 1 | Andreas Steffen | ... |
781 | 2 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
782 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
783 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
784 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: 1a:71:6c:9c:9f:6d:4f:2e:4a:88:42:49:b0:00:8d:5e:ec:05:7e:eb |
785 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:/usr/sbin/service' |
786 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
787 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
788 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] measurement time: Jan 01 01:00:04 1970 |
789 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] PCR 10 extended with: e8:f5:f2:02:d4:c1:18:d5:f7:55:5c:2d:4a:a0:d3:12:d4:13:06:ce |
790 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 'sha1:/bin/cp' |
791 | 16 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[TNC] processing PA-TNC attribute type 'TCG/Simple Evidence Final' 0x005597/0x00400000 |
792 | 11 | Andreas Steffen | </pre> |
793 | 11 | Andreas Steffen | |
794 | 16 | Andreas Steffen | h3. Verifying Initiator Measurements |
795 | 16 | Andreas Steffen | |
796 | 1 | Andreas Steffen | <pre> |
797 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] checking boot aggregate evidence measurement |
798 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 65:ee:0c:a2:cd:ac:0d:67:f8:1a:fd:53:7b:96:75:6f:3b:b8:0f:82 for '/init' not found |
799 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 6b:a1:a0:58:89:a8:f2:57:53:42:b5:dc:5f:3e:de:54:89:8a:ee:29 for '/bin/sh' is ok |
800 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 85:e6:6e:7a:96:98:8b:0a:af:c8:88:46:5d:7a:fe:b5:e9:d3:c2:3e for '/lib/klibc-sO6SifHCdmbehHGtm0y1yHu6vb0.so' is ok |
801 | 1 | Andreas Steffen | Aug 15 14:46:10 raspi4 charon: 08[PTS] 68:4a:c3:8d:48:55:be:e0:21:93:4f:52:a0:d2:3d:66:86:0c:b2:82 for '/bin/mkdir' is ok |
802 | 1 | Andreas Steffen | ... |
803 | 3 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 1a:71:6c:9c:9f:6d:4f:2e:4a:88:42:49:b0:00:8d:5e:ec:05:7e:eb for '/usr/sbin/service' is ok |
804 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] e8:f5:f2:02:d4:c1:18:d5:f7:55:5c:2d:4a:a0:d3:12:d4:13:06:ce for '/bin/cp' is ok |
805 | 11 | Andreas Steffen | </pre> |
806 | 1 | Andreas Steffen | |
807 | 16 | Andreas Steffen | h3. Verifying Initiator TPM Quote Signature |
808 | 16 | Andreas Steffen | |
809 | 11 | Andreas Steffen | <pre> |
810 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] constructed PCR Composite: => 29 bytes @ 0x1b27188 |
811 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 0: 00 03 00 04 00 00 00 00 14 F7 5E 84 36 2B C2 83 ..........^.6+.. |
812 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 16: 28 8E 90 7E B3 39 45 74 33 60 2E B7 8E (..~.9Et3`... |
813 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] constructed PCR Composite hash: 58:f2:83:91:d6:a8:df:3d:3e:c6:33:c7:24:93:9f:9c:22:a2:01:20 |
814 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] constructed TPM Quote Info: => 52 bytes @ 0x1b27e68 |
815 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 0: 00 36 51 55 54 32 D8 9D 1E 70 CE 78 C3 13 F2 79 .6QUT2...p.x...y |
816 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 16: BA 5D 7C E5 05 7C E0 E0 83 77 00 03 00 04 00 01 .]|..|...w...... |
817 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 32: 58 F2 83 91 D6 A8 DF 3D 3E C6 33 C7 24 93 9F 9C X......=>.3.$... |
818 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] 48: 22 A2 01 20 ".. |
819 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IMV] received PCR Composite matches constructed one |
820 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IMV] TPM Quote Info signature verification successful |
821 | 11 | Andreas Steffen | </pre> |
822 | 11 | Andreas Steffen | |
823 | 11 | Andreas Steffen | <pre> |
824 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[PTS] processed 433 IMA file evidence measurements: 377 ok, 56 unknown, 0 differ, 0 failed |
825 | 11 | Andreas Steffen | </pre> |
826 | 11 | Andreas Steffen | |
827 | 11 | Andreas Steffen | <pre> |
828 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IMV] IMV 1 handled TPMRA workitem 18: allow - processed 433 IMA file evidence measurements: 377 ok, 56 unknown, 0 differ, 0 failed |
829 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] creating PA-TNC message with ID 0x57254d62 |
830 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009 |
831 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
832 | 19 | Andreas Steffen | </pre> |
833 | 19 | Andreas Steffen | |
834 | 19 | Andreas Steffen | h3. Sending Assessment Result |
835 | 19 | Andreas Steffen | |
836 | 19 | Andreas Steffen | <pre> |
837 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] IMV 1 provides recommendation 'allow' and evaluation 'compliant' |
838 | 9 | Andreas Steffen | </pre> |
839 | 9 | Andreas Steffen | |
840 | 9 | Andreas Steffen | <pre> |
841 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] TNC server is handling outbound connection |
842 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IMV] policy: recommendation for access requestor 10.10.1.39 is allow |
843 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IMV] policy: imv_policy_manager stop successful |
844 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IMV] IMV 1 "Attestation" changed state of Connection ID 1 to 'Allowed' |
845 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] PB-TNC state transition from 'Server Working' to 'Decided' |
846 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] creating PB-TNC RESULT batch |
847 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] adding IETF/PB-PA message |
848 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] adding IETF/PB-Assessment-Result message |
849 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] adding IETF/PB-Access-Recommendation message |
850 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[TNC] sending PB-TNC RESULT batch (88 bytes) for Connection ID 1 |
851 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
852 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[ENC] generating IKE_AUTH response 61 [ EAP/REQ/TTLS ] |
853 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 08[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (256 bytes) |
854 | 11 | Andreas Steffen | </pre> |
855 | 11 | Andreas Steffen | |
856 | 11 | Andreas Steffen | <pre> |
857 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes) |
858 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[ENC] parsed IKE_AUTH request 62 [ EAP/RES/TTLS ] |
859 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
860 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] received TNCCS batch (80 bytes) |
861 | 9 | Andreas Steffen | </pre> |
862 | 9 | Andreas Steffen | |
863 | 9 | Andreas Steffen | <pre> |
864 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] TNC client is handling inbound connection |
865 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] processing PB-TNC SDATA batch for Connection ID 2 |
866 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] PB-TNC state transition from 'Server Working' to 'Client Working' |
867 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] processing IETF/PB-PA message (72 bytes) |
868 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
869 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[IMC] IMC 2 "Attestation" received message for Connection ID 2 from IMV 1 |
870 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] processing PA-TNC message with ID 0xc8f4500b |
871 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] processing PA-TNC attribute type 'TCG/Request Functional Component Evidence' 0x005597/0x00100000 |
872 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[TNC] processing PA-TNC attribute type 'TCG/Generate Attestation Evidence' 0x005597/0x00200000 |
873 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[IMC] evidence requested for 1 functional components |
874 | 11 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] * ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
875 | 1 | Andreas Steffen | </pre> |
876 | 15 | Andreas Steffen | |
877 | 16 | Andreas Steffen | h3. Responder Attestation Measurement Values |
878 | 11 | Andreas Steffen | |
879 | 11 | Andreas Steffen | <pre> |
880 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] loaded ima measurements '/sys/kernel/security/ima/binary_runtime_measurements' (451 entries) |
881 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
882 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
883 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: dd:ee:60:04:dc:3b:d4:ee:30:04:06:cd:93:18:1c:5a:21:87:b5:9b |
884 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:boot_aggregate' |
885 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
886 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
887 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: 65:ee:0c:a2:cd:ac:0d:67:f8:1a:fd:53:7b:96:75:6f:3b:b8:0f:82 |
888 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:/init' |
889 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
890 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
891 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: 6b:a1:a0:58:89:a8:f2:57:53:42:b5:dc:5f:3e:de:54:89:8a:ee:29 |
892 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:/bin/sh' |
893 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
894 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
895 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: 85:e6:6e:7a:96:98:8b:0a:af:c8:88:46:5d:7a:fe:b5:e9:d3:c2:3e |
896 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:/lib/klibc-sO6SifHCdmbehHGtm0y1yHu6vb0.so' |
897 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
898 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
899 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: 68:4a:c3:8d:48:55:be:e0:21:93:4f:52:a0:d2:3d:66:86:0c:b2:82 |
900 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:/bin/mkdir' |
901 | 4 | Andreas Steffen | ... |
902 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
903 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
904 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: 55:f4:cd:fd:82:d2:99:e1:33:b6:82:67:95:e6:5d:03:5c:bb:d2:c2 |
905 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:/usr/bin/clear_console' |
906 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] ITA-HSR functional component 'Linux IMA' [K.] 'Operating System' |
907 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] measurement time: Jan 01 01:00:04 1970 |
908 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] PCR 10 extended with: 7a:fc:49:eb:8f:e6:74:3f:ac:91:41:a2:c0:ac:92:28:33:fd:7b:33 |
909 | 1 | Andreas Steffen | Aug 15 14:46:16 raspi4 charon: 10[PTS] 'sha1:/usr/libexec/ipsec/stroke' |
910 | 1 | Andreas Steffen | </pre> |
911 | 16 | Andreas Steffen | |
912 | 17 | Andreas Steffen | h3. Generating Responder TPM Quote Signature |
913 | 11 | Andreas Steffen | |
914 | 11 | Andreas Steffen | <pre> |
915 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] Hash of PCR Composite: c4:6a:f4:fa:82:39:a6:7a:80:fe:4e:d2:7e:a5:05:b3:1e:60:4f:ff |
916 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] TPM Quote Info: => 52 bytes @ 0x1ae0580 |
917 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 0: 00 36 51 55 54 32 B2 E0 AB DF 89 C5 1D B2 A3 51 .6QUT2.........Q |
918 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 16: FD A9 C8 3B F8 7F 68 50 6C DE 00 03 00 04 00 01 ...;..hPl....... |
919 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 32: C4 6A F4 FA 82 39 A6 7A 80 FE 4E D2 7E A5 05 B3 .j...9.z..N.~... |
920 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 48: 1E 60 4F FF .`O. |
921 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] TPM Quote Signature: => 256 bytes @ 0x1ae0c00 |
922 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 0: 6C 25 B7 58 F9 5C CA CA 86 6F 9A BD 24 2E 32 D9 l%.X.\...o..$.2. |
923 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 16: 36 DD 4F DF 37 09 1E 60 56 45 0E B4 32 52 A2 6A 6.O.7..`VE..2R.j |
924 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 32: B4 A5 27 59 79 25 F2 DC A1 05 14 5C 0C 71 DD DC ..'Yy%.....\.q.. |
925 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 48: 96 31 9C 69 DD 60 AC 51 70 95 47 48 62 FF 40 DC .1.i.`.Qp.GHb.@. |
926 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 64: FF FF C3 55 5D 1C DF E2 D6 4B 8E 4F BF 0A 47 CC ...U]....K.O..G. |
927 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 80: 1E C5 42 7D 3B 39 C4 4D 6A A0 A4 CD 3E E3 E6 C6 ..B};9.Mj...>... |
928 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 96: A1 DB F1 AF F3 2B 48 0D 74 60 A3 B3 E3 43 5E 22 .....+H.t`...C^" |
929 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 112: 99 EC 5B 23 FD 57 D4 1F 97 32 28 DC 4A 38 36 15 ..[#.W...2(.J86. |
930 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 128: 75 57 53 18 21 29 5C CD 8F C6 66 60 70 7C 47 0F uWS.!)\...f`p|G. |
931 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 144: 9B 7B FE BA 29 80 0C 87 11 41 81 95 6D 74 6B FA .{..)....A..mtk. |
932 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 160: 4D 5F F7 23 C4 60 D2 2A C2 16 08 EA AF 59 CC D2 M_.#.`.*.....Y.. |
933 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 176: 18 EC 20 18 5B 1D 42 72 E1 C8 33 02 A1 37 ED EA .. .[.Br..3..7.. |
934 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 192: B8 CD CA 2B 83 D3 B2 77 1C 45 2D C7 36 FA E6 88 ...+...w.E-.6... |
935 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 208: 93 C3 BE D9 26 31 A5 59 3D 20 24 B1 0F F3 04 5C ....&1.Y= $....\ |
936 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 224: 93 FA 8C 09 3E C3 FF E0 A1 EB 03 58 0B AB 08 89 ....>......X.... |
937 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[PTS] 240: BA A4 22 ED AB D6 BA 7C 65 8D B6 75 5C 7C 67 28 .."....|e..u\|g( |
938 | 18 | Andreas Steffen | </pre> |
939 | 18 | Andreas Steffen | |
940 | 18 | Andreas Steffen | <pre> |
941 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC message with ID 0xed64f7ab |
942 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
943 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
944 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
945 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
946 | 5 | Andreas Steffen | ... |
947 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
948 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Component Evidence' 0x005597/0x00300000 |
949 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PA-TNC attribute type 'TCG/Simple Evidence Final' 0x005597/0x00400000 |
950 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
951 | 9 | Andreas Steffen | </pre> |
952 | 9 | Andreas Steffen | |
953 | 9 | Andreas Steffen | <pre> |
954 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] TNC client is handling outbound connection |
955 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] PB-TNC state transition from 'Client Working' to 'Server Working' |
956 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] creating PB-TNC CDATA batch |
957 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] adding IETF/PB-PA message |
958 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[TNC] sending PB-TNC CDATA batch (49524 bytes) for Connection ID 2 |
959 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
960 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[ENC] generating IKE_AUTH response 62 [ EAP/REQ/TTLS ] |
961 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 10[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes) |
962 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 11[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
963 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 11[ENC] parsed IKE_AUTH request 63 [ EAP/RES/TTLS ] |
964 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 11[ENC] generating IKE_AUTH response 63 [ EAP/REQ/TTLS ] |
965 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 11[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes) |
966 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 12[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
967 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 12[ENC] parsed IKE_AUTH request 64 [ EAP/RES/TTLS ] |
968 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 12[ENC] generating IKE_AUTH response 64 [ EAP/REQ/TTLS ] |
969 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 12[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes) |
970 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 13[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
971 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 13[ENC] parsed IKE_AUTH request 65 [ EAP/RES/TTLS ] |
972 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 13[ENC] generating IKE_AUTH response 65 [ EAP/REQ/TTLS ] |
973 | 1 | Andreas Steffen | Aug 15 14:46:17 raspi4 charon: 13[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes) |
974 | 5 | Andreas Steffen | ... |
975 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 08[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
976 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 08[ENC] parsed IKE_AUTH request 109 [ EAP/RES/TTLS ] |
977 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 08[ENC] generating IKE_AUTH response 109 [ EAP/REQ/TTLS ] |
978 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 08[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1104 bytes) |
979 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 10[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
980 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 10[ENC] parsed IKE_AUTH request 110 [ EAP/RES/TTLS ] |
981 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 10[ENC] generating IKE_AUTH response 110 [ EAP/REQ/TTLS ] |
982 | 1 | Andreas Steffen | Aug 15 14:46:18 raspi4 charon: 10[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (1040 bytes) |
983 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (256 bytes) |
984 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[ENC] parsed IKE_AUTH request 111 [ EAP/RES/TTLS ] |
985 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
986 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] received TNCCS batch (88 bytes) |
987 | 9 | Andreas Steffen | </pre> |
988 | 9 | Andreas Steffen | |
989 | 9 | Andreas Steffen | <pre> |
990 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] TNC client is handling inbound connection |
991 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] processing PB-TNC RESULT batch for Connection ID 2 |
992 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] PB-TNC state transition from 'Server Working' to 'Decided' |
993 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] processing IETF/PB-PA message (48 bytes) |
994 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] processing IETF/PB-Assessment-Result message (16 bytes) |
995 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] processing IETF/PB-Access-Recommendation message (16 bytes) |
996 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] handling PB-PA message type 'TCG/PTS' 0x005597/0x00000001 |
997 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IMC] IMC 2 "Attestation" received message for Connection ID 2 from IMV 1 |
998 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] processing PA-TNC message with ID 0x4077e3ed |
999 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] processing PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009 |
1000 | 11 | Andreas Steffen | </pre> |
1001 | 19 | Andreas Steffen | |
1002 | 19 | Andreas Steffen | h3. Receiving Assessment Result |
1003 | 11 | Andreas Steffen | |
1004 | 11 | Andreas Steffen | <pre> |
1005 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IMC] ***** assessment of IMC 2 "Attestation" from IMV 1 ***** |
1006 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IMC] assessment result is 'compliant' |
1007 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IMC] ***** end of assessment ***** |
1008 | 11 | Andreas Steffen | </pre> |
1009 | 11 | Andreas Steffen | |
1010 | 11 | Andreas Steffen | <pre> |
1011 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] PB-TNC assessment result is 'compliant' |
1012 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] PB-TNC access recommendation is 'Access Allowed' |
1013 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IMC] IMC 1 "OS" changed state of Connection ID 2 to 'Allowed' |
1014 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IMC] IMC 2 "Attestation" changed state of Connection ID 2 to 'Allowed' |
1015 | 9 | Andreas Steffen | </pre> |
1016 | 9 | Andreas Steffen | |
1017 | 9 | Andreas Steffen | <pre> |
1018 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] TNC client is handling outbound connection |
1019 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] PB-TNC state transition from 'Decided' to 'End' |
1020 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] creating PB-TNC CLOSE batch |
1021 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[TNC] sending PB-TNC CLOSE batch (8 bytes) for Connection ID 2 |
1022 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT] |
1023 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[ENC] generating IKE_AUTH response 111 [ EAP/REQ/TTLS ] |
1024 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 11[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (176 bytes) |
1025 | 11 | Andreas Steffen | </pre> |
1026 | 11 | Andreas Steffen | |
1027 | 11 | Andreas Steffen | <pre> |
1028 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (176 bytes) |
1029 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[ENC] parsed IKE_AUTH request 112 [ EAP/RES/TTLS ] |
1030 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT] |
1031 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] received TNCCS batch (8 bytes) |
1032 | 9 | Andreas Steffen | </pre> |
1033 | 9 | Andreas Steffen | |
1034 | 9 | Andreas Steffen | <pre> |
1035 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] TNC server is handling inbound connection |
1036 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] processing PB-TNC CLOSE batch for Connection ID 1 |
1037 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] PB-TNC state transition from 'Decided' to 'End' |
1038 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] final recommendation is 'allow' and evaluation is 'compliant' |
1039 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] policy enforced on peer 'raspi3.example.com' is 'allow' |
1040 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] policy enforcement point added group membership 'allow' |
1041 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[IKE] EAP_TTLS phase2 authentication of 'raspi3.example.com' with EAP_PT_EAP successful |
1042 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[IMV] IMV 1 "Attestation" deleted the state of Connection ID 1 |
1043 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] removed TNCCS Connection ID 1 |
1044 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[IMC] IMC 1 "OS" deleted the state of Connection ID 2 |
1045 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[IMC] IMC 2 "Attestation" deleted the state of Connection ID 2 |
1046 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[TNC] removed TNCCS Connection ID 2 |
1047 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[IKE] EAP method EAP_TTLS succeeded, MSK established |
1048 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[ENC] generating IKE_AUTH response 112 [ EAP/SUCC ] |
1049 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 12[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
1050 | 11 | Andreas Steffen | </pre> |
1051 | 11 | Andreas Steffen | |
1052 | 11 | Andreas Steffen | <pre> |
1053 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (112 bytes) |
1054 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[ENC] parsed IKE_AUTH request 113 [ AUTH ] |
1055 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[IKE] authentication of 'raspi3.example.com' with EAP successful |
1056 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[IKE] authentication of 'raspi4.example.com' (myself) with EAP |
1057 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[IKE] IKE_SA peer[1] established between 10.10.1.40[raspi4.example.com]...10.10.1.39[raspi3.example.com] |
1058 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[IKE] scheduling reauthentication in 10143s |
1059 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[IKE] maximum IKE_SA lifetime 10683s |
1060 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[IKE] CHILD_SA peer{1} established with SPIs ce21eedf_i c12c1aae_o and TS 10.10.1.40/32 === 10.10.1.39/32 |
1061 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[ENC] generating IKE_AUTH response 113 [ AUTH N(USE_TRANSP) SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(NO_ADD_ADDR) ] |
1062 | 1 | Andreas Steffen | Aug 15 14:46:25 raspi4 charon: 13[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (240 bytes) |
1063 | 10 | Andreas Steffen | </pre> |
1064 | 10 | Andreas Steffen | |
1065 | 10 | Andreas Steffen | h2. Terminating the IPsec Connection |
1066 | 10 | Andreas Steffen | |
1067 | 10 | Andreas Steffen | <pre> |
1068 | 1 | Andreas Steffen | Aug 15 14:49:04 raspi4 charon: 05[NET] received packet: from 10.10.1.39[4500] to 10.10.1.40[4500] (80 bytes) |
1069 | 1 | Andreas Steffen | Aug 15 14:49:04 raspi4 charon: 05[ENC] parsed INFORMATIONAL request 114 [ D ] |
1070 | 1 | Andreas Steffen | Aug 15 14:49:04 raspi4 charon: 05[IKE] received DELETE for IKE_SA peer[1] |
1071 | 1 | Andreas Steffen | Aug 15 14:49:04 raspi4 charon: 05[IKE] deleting IKE_SA peer[1] between 10.10.1.40[raspi4.example.com]...10.10.1.39[raspi3.example.com] |
1072 | 1 | Andreas Steffen | Aug 15 14:49:04 raspi4 charon: 05[IKE] IKE_SA deleted |
1073 | 1 | Andreas Steffen | Aug 15 14:49:05 raspi4 charon: 05[ENC] generating INFORMATIONAL response 114 [ ] |
1074 | 1 | Andreas Steffen | Aug 15 14:49:05 raspi4 charon: 05[NET] sending packet: from 10.10.1.40[4500] to 10.10.1.39[4500] (80 bytes) |
1075 | 10 | Andreas Steffen | </pre> |
1076 | 10 | Andreas Steffen | |
1077 | 10 | Andreas Steffen | h2. Stopping the IKEv2 Daemon |
1078 | 10 | Andreas Steffen | |
1079 | 10 | Andreas Steffen | <pre> |
1080 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[DMN] signal of type SIGINT received. Shutting down |
1081 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[IMC] IMC 2 "Attestation" terminated |
1082 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[IMC] IMC 1 "OS" terminated |
1083 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[IMV] IMV 1 "Attestation" terminated |
1084 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[PTS] removed TCG functional component namespace |
1085 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[PTS] removed ITA-HSR functional component namespace |
1086 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[TNC] removed IETF attributes |
1087 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[TNC] removed ITA-HSR attributes |
1088 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[TNC] removed TCG attributes |
1089 | 1 | Andreas Steffen | Aug 15 14:49:13 raspi4 charon: 00[LIB] libimcv terminated |
1090 | 1 | Andreas Steffen | </pre> |