Project

General

Profile

Endpoint Compliance via PT-EAP Protocol » History » Version 26

Andreas Steffen, 07.10.2014 23:21

1 1 Andreas Steffen
h1. Endpoint Compliance via PT-EAP Protocol
2 1 Andreas Steffen
3 1 Andreas Steffen
{{>toc}}
4 1 Andreas Steffen
5 1 Andreas Steffen
h2. Starting the strongSwan Policy Decision Point (PDP)
6 1 Andreas Steffen
7 1 Andreas Steffen
The strongSwan PDP starts and loads its server certificate and the client credentials
8 1 Andreas Steffen
<pre>
9 1 Andreas Steffen
00[DMN] Starting IKE charon daemon (strongSwan 5.2.1dr1, Linux 3.16.1, x86_64)
10 1 Andreas Steffen
00[LIB] openssl FIPS mode(0) - disabled 
11 1 Andreas Steffen
00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
12 1 Andreas Steffen
00[CFG]   loaded ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" from '/etc/ipsec.d/cacerts/strongswanCert.pem'
13 1 Andreas Steffen
00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
14 1 Andreas Steffen
00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
15 1 Andreas Steffen
00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
16 1 Andreas Steffen
00[CFG] loading crls from '/etc/ipsec.d/crls'
17 1 Andreas Steffen
00[CFG] loading secrets from '/etc/ipsec.secrets'
18 1 Andreas Steffen
00[CFG]   loaded RSA private key from '/etc/ipsec.d/private/aaaKey.pem'
19 1 Andreas Steffen
00[CFG]   loaded EAP secret for carol
20 1 Andreas Steffen
00[CFG]   loaded EAP secret for dave 
21 1 Andreas Steffen
</pre>
22 1 Andreas Steffen
23 1 Andreas Steffen
Next the OS and SWID IMVs are loaded
24 1 Andreas Steffen
<pre>
25 1 Andreas Steffen
00[TNC] TNC recommendation policy is 'default'
26 1 Andreas Steffen
00[TNC] loading IMVs from '/etc/tnc_config'
27 1 Andreas Steffen
00[TNC] added IETF attributes
28 1 Andreas Steffen
00[TNC] added ITA-HSR attributes
29 1 Andreas Steffen
00[TNC] added TCG attributes
30 1 Andreas Steffen
00[LIB] libimcv initialized
31 1 Andreas Steffen
00[IMV] IMV 1 "OS" initialized
32 1 Andreas Steffen
00[TNC] IMV 1 supports 1 message type: 'IETF/Operating System' 0x000000/0x00000001
33 1 Andreas Steffen
00[TNC] IMV 1 "OS" loaded from '/usr/local/lib/ipsec/imcvs/imv-os.so'
34 1 Andreas Steffen
00[IMV] IMV 2 "SWID" initialized
35 1 Andreas Steffen
00[TNC] IMV 2 supports 1 message type: 'TCG/SWID' 0x005597/0x00000003
36 1 Andreas Steffen
O00[TNC] IMV 2 "SWID" loaded from '/usr/local/lib/ipsec/imcvs/imv-swid.so'
37 1 Andreas Steffen
</pre>
38 1 Andreas Steffen
39 1 Andreas Steffen
The PDP loads all plugins needed to communicate via its EAP-RADIUS and PT-TLS interfaces and spawns 16 worker threads
40 1 Andreas Steffen
<pre>
41 1 Andreas Steffen
00[IKE] eap method EAP_TTLS selected
42 1 Andreas Steffen
00[LIB] loaded plugins: charon aes des sha1 sha2 md5 pem pkcs1 gmp random nonce x509 curl revocation hmac socket-default kernel-netlink stroke eap-identity eap-ttls eap-md5 eap-tnc tnc-pdp tnc-imv tnc-tnccs tnccs-20 sqlite
43 1 Andreas Steffen
00[JOB] spawning 16 worker threads
44 1 Andreas Steffen
09[CFG] received stroke: add connection 'aaa'
45 1 Andreas Steffen
09[CFG] left nor right host is our side, assuming left=local
46 1 Andreas Steffen
09[CFG]   loaded certificate "C=CH, O=Linux strongSwan, CN=aaa.strongswan.org" from 'aaaCert.pem'
47 1 Andreas Steffen
09[CFG] added configuration 'aaa'
48 1 Andreas Steffen
</pre>
49 1 Andreas Steffen
50 17 Andreas Steffen
h2. PT-EAP Connection by Access Requestor "dave" via EAP-RADIUS
51 1 Andreas Steffen
52 1 Andreas Steffen
<pre>
53 1 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
54 1 Andreas Steffen
04[CFG] created RADIUS connection for user 'dave' NAS 'strongSwan'
55 1 Andreas Steffen
04[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
56 1 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
57 2 Andreas Steffen
11[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
58 1 Andreas Steffen
</pre>
59 1 Andreas Steffen
60 3 Andreas Steffen
Set up an EAP-TTLS connection between AR and PDP
61 1 Andreas Steffen
<pre>
62 1 Andreas Steffen
11[TLS] negotiated TLS 1.2 using suite TLS_DHE_RSA_WITH_AES_128_CBC_SHA
63 1 Andreas Steffen
11[TLS] sending TLS server certificate 'C=CH, O=Linux strongSwan, CN=aaa.strongswan.org'
64 1 Andreas Steffen
11[TLS] sending TLS cert request for 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'
65 4 Andreas Steffen
</pre>
66 2 Andreas Steffen
67 2 Andreas Steffen
<pre>
68 2 Andreas Steffen
11[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
69 2 Andreas Steffen
12[CFG] received RADIUS Access-Request from client '10.1.0.1'
70 2 Andreas Steffen
12[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
71 2 Andreas Steffen
12[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
72 2 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
73 2 Andreas Steffen
13[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
74 2 Andreas Steffen
13[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/ID]
75 2 Andreas Steffen
13[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
76 2 Andreas Steffen
14[CFG] received RADIUS Access-Request from client '10.1.0.1'
77 2 Andreas Steffen
14[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
78 1 Andreas Steffen
</pre>
79 2 Andreas Steffen
80 5 Andreas Steffen
Received EAP-Identity of AR "dave"
81 2 Andreas Steffen
<pre>
82 2 Andreas Steffen
14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/ID]
83 2 Andreas Steffen
14[IKE] received EAP identity 'dave'
84 2 Andreas Steffen
14[IKE] phase2 method EAP_MD5 selected
85 2 Andreas Steffen
14[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/MD5]
86 2 Andreas Steffen
</pre>
87 2 Andreas Steffen
88 2 Andreas Steffen
<pre>
89 2 Andreas Steffen
14[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
90 2 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
91 2 Andreas Steffen
03[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
92 1 Andreas Steffen
</pre>
93 2 Andreas Steffen
94 5 Andreas Steffen
EAP-MD5 based authentication of AR "dave"
95 2 Andreas Steffen
<pre>
96 2 Andreas Steffen
03[IKE] received tunneled EAP-TTLS AVP [EAP/RES/MD5]
97 2 Andreas Steffen
03[IKE] EAP_TTLS phase2 authentication of 'dave' with EAP_MD5 successful
98 2 Andreas Steffen
03[IKE] phase2 method EAP_PT_EAP selected
99 2 Andreas Steffen
03[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
100 2 Andreas Steffen
</pre>
101 2 Andreas Steffen
102 2 Andreas Steffen
<pre>
103 2 Andreas Steffen
03[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
104 2 Andreas Steffen
15[CFG] received RADIUS Access-Request from client '10.1.0.1'
105 1 Andreas Steffen
15[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
106 1 Andreas Steffen
</pre>
107 1 Andreas Steffen
108 17 Andreas Steffen
h3. Creating IF-TNCCS 2.0 connection with ID 1
109 16 Andreas Steffen
110 4 Andreas Steffen
Upon reception of the first PB-TNC client batch, open an IF-TNCCS 2.0 connection
111 3 Andreas Steffen
<pre>
112 3 Andreas Steffen
15[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
113 3 Andreas Steffen
15[IMV] IMV 1 "OS" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh
114 3 Andreas Steffen
15[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
115 3 Andreas Steffen
15[IMV]   user AR identity 'dave' authenticated by password
116 3 Andreas Steffen
15[IMV] IMV 2 "SWID" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh
117 3 Andreas Steffen
15[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
118 3 Andreas Steffen
15[IMV]   user AR identity 'dave' authenticated by password
119 3 Andreas Steffen
15[IMV] IMV 1 "OS" changed state of Connection ID 1 to 'Handshake'
120 3 Andreas Steffen
15[IMV] IMV 2 "SWID" changed state of Connection ID 1 to 'Handshake'
121 3 Andreas Steffen
</pre>
122 3 Andreas Steffen
123 3 Andreas Steffen
<pre>
124 3 Andreas Steffen
15[TNC] received TNCCS batch (91 bytes) for Connection ID 1
125 3 Andreas Steffen
15[TNC] PB-TNC state transition from 'Init' to 'Server Working'
126 3 Andreas Steffen
15[TNC] processing PB-TNC CDATA batch
127 3 Andreas Steffen
15[TNC] processing IETF/PB-PA message (52 bytes)
128 3 Andreas Steffen
15[TNC] setting language preference to 'en'
129 3 Andreas Steffen
</pre>
130 1 Andreas Steffen
131 18 Andreas Steffen
h3. Received Max Attribute Size Request for IF-M Message Type 'TCG/SWID' 
132 15 Andreas Steffen
133 3 Andreas Steffen
<pre>
134 3 Andreas Steffen
15[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
135 3 Andreas Steffen
15[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2
136 3 Andreas Steffen
15[IMV] => 28 bytes @ 0x7a5490
137 3 Andreas Steffen
15[IMV]    0: 01 00 00 00 26 4B C3 0A 00 00 55 97 00 00 00 21  ....&K....U....!
138 3 Andreas Steffen
15[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6              ............
139 3 Andreas Steffen
15[TNC] processing PA-TNC message with ID 0x264bc30a
140 3 Andreas Steffen
15[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
141 3 Andreas Steffen
15[IMV] received a segmentation contract from IMC 2 for PA message type 'TCG/SWID' 0x005597/0x00000003
142 1 Andreas Steffen
15[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 32678 bytes
143 1 Andreas Steffen
</pre>
144 1 Andreas Steffen
145 18 Andreas Steffen
h3. Sending Max Attribute Size Response for IF-M Message Type 'TCG/SWID'
146 15 Andreas Steffen
147 3 Andreas Steffen
<pre>
148 3 Andreas Steffen
15[TNC] creating PA-TNC message with ID 0x45425ec5
149 3 Andreas Steffen
15[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
150 3 Andreas Steffen
15[IMV] created PA-TNC message: => 28 bytes @ 0x7a5b00
151 1 Andreas Steffen
15[IMV]    0: 01 00 00 00 45 42 5E C5 00 00 55 97 00 00 00 22  ....EB^...U...."
152 1 Andreas Steffen
15[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6              ............
153 1 Andreas Steffen
15[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
154 1 Andreas Steffen
</pre>
155 1 Andreas Steffen
156 18 Andreas Steffen
h3. Sending Max Attribute Size Request for IF-M Message Type 'IETF Operating Systen'
157 17 Andreas Steffen
158 5 Andreas Steffen
<pre>
159 1 Andreas Steffen
15[IMV] IMV 1 requests a segmentation contract for PA message type 'IETF/Operating System' 0x000000/0x00000001
160 5 Andreas Steffen
15[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 65446 bytes
161 5 Andreas Steffen
15[TNC] creating PA-TNC message with ID 0x2ae6641f
162 5 Andreas Steffen
15[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
163 5 Andreas Steffen
15[TNC] creating PA-TNC attribute type 'IETF/Attribute Request' 0x000000/0x00000001
164 5 Andreas Steffen
15[IMV] created PA-TNC message: => 96 bytes @ 0x7a7ff0
165 5 Andreas Steffen
15[IMV]    0: 01 00 00 00 2A E6 64 1F 00 00 55 97 00 00 00 21  ....*.d...U....!
166 5 Andreas Steffen
15[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 FF A6 00 00 00 00  ................
167 5 Andreas Steffen
15[IMV]   32: 00 00 00 01 00 00 00 44 00 00 00 00 00 00 00 02  .......D........
168 5 Andreas Steffen
15[IMV]   48: 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 03  ................
169 1 Andreas Steffen
15[IMV]   64: 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 0B  ................
170 5 Andreas Steffen
15[IMV]   80: 00 00 00 00 00 00 00 0C 00 00 90 2A 00 00 00 08  ...........*....
171 1 Andreas Steffen
15[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
172 6 Andreas Steffen
</pre>
173 1 Andreas Steffen
174 7 Andreas Steffen
After appending an Attribute Request for various standard IETF attributes to this PA-TNC message, a first PB-TNC server batch is sent to the TNC client running on the AR
175 6 Andreas Steffen
<pre>
176 6 Andreas Steffen
15[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
177 6 Andreas Steffen
15[TNC] creating PB-TNC SDATA batch
178 6 Andreas Steffen
15[TNC] adding TCG/PB-PDP-Referral message
179 6 Andreas Steffen
15[TNC] adding IETF/PB-PA message
180 6 Andreas Steffen
15[TNC] adding IETF/PB-PA message
181 6 Andreas Steffen
15[TNC] sending PB-TNC SDATA batch (222 bytes) for Connection ID 1
182 6 Andreas Steffen
15[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
183 6 Andreas Steffen
</pre>
184 6 Andreas Steffen
185 1 Andreas Steffen
<pre>
186 1 Andreas Steffen
15[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
187 1 Andreas Steffen
16[CFG] received RADIUS Access-Request from client '10.1.0.1'
188 1 Andreas Steffen
16[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
189 7 Andreas Steffen
</pre>
190 7 Andreas Steffen
191 7 Andreas Steffen
<pre>
192 7 Andreas Steffen
16[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
193 7 Andreas Steffen
16[TNC] received TNCCS batch (248 bytes) for Connection ID 1
194 7 Andreas Steffen
16[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
195 7 Andreas Steffen
16[TNC] processing PB-TNC CDATA batch
196 7 Andreas Steffen
16[TNC] processing IETF/PB-PA message (240 bytes)
197 7 Andreas Steffen
</pre>
198 7 Andreas Steffen
199 7 Andreas Steffen
<pre>
200 7 Andreas Steffen
16[TNC] handling PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
201 7 Andreas Steffen
16[IMV] IMV 1 "OS" received message for Connection ID 1 from IMC 1 to IMV 1
202 7 Andreas Steffen
16[IMV] => 216 bytes @ 0x7a45b0
203 7 Andreas Steffen
16[IMV]    0: 01 00 00 00 FD DE 12 F4 00 00 55 97 00 00 00 22  ..........U...."
204 7 Andreas Steffen
16[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6 00 00 00 00  ................
205 7 Andreas Steffen
16[IMV]   32: 00 00 00 02 00 00 00 17 00 25 72 00 00 44 65 62  .........%r..Deb
206 7 Andreas Steffen
16[IMV]   48: 69 61 6E 00 00 00 00 00 00 00 04 00 00 00 19 0A  ian.............
207 7 Andreas Steffen
16[IMV]   64: 37 2E 35 20 78 38 36 5F 36 34 00 00 00 00 00 00  7.5 x86_64......
208 7 Andreas Steffen
16[IMV]   80: 00 00 00 03 00 00 00 1C 00 00 00 07 00 00 00 05  ................
209 7 Andreas Steffen
16[IMV]   96: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05  ................
210 7 Andreas Steffen
16[IMV]  112: 00 00 00 24 03 01 00 00 32 30 31 34 2D 31 30 2D  ...$....2014-10-
211 7 Andreas Steffen
16[IMV]  128: 30 36 54 31 39 3A 33 31 3A 30 30 5A 00 00 00 00  06T19:31:00Z....
212 7 Andreas Steffen
16[IMV]  144: 00 00 00 0B 00 00 00 10 00 00 00 01 00 00 00 00  ................
213 7 Andreas Steffen
16[IMV]  160: 00 00 00 0C 00 00 00 10 00 00 00 00 00 00 90 2A  ...............*
214 7 Andreas Steffen
16[IMV]  176: 00 00 00 08 00 00 00 2C 61 61 62 62 63 63 64 64  .......,aabbccdd
215 7 Andreas Steffen
16[IMV]  192: 65 65 66 66 31 31 32 32 33 33 34 34 35 35 36 36  eeff112233445566
216 7 Andreas Steffen
16[IMV]  208: 37 37 38 38 39 39 30 30                          77889900
217 7 Andreas Steffen
16[TNC] processing PA-TNC message with ID 0xfdde12f4
218 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
219 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002
220 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004
221 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003
222 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005
223 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b
224 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c
225 1 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008
226 1 Andreas Steffen
</pre>
227 7 Andreas Steffen
228 18 Andreas Steffen
h3. Received Max Attribute Size Response for IF-M Message Type 'IETF/Operating System' 
229 15 Andreas Steffen
230 7 Andreas Steffen
<pre>
231 7 Andreas Steffen
16[IMV] received a segmentation contract response for PA message type 'IETF/Operating System' 0x000000/0x00000001
232 7 Andreas Steffen
16[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 32678 bytes
233 7 Andreas Steffen
</pre>
234 7 Andreas Steffen
235 26 Andreas Steffen
h3. Received Standard IETF Operating System Attributes
236 26 Andreas Steffen
237 7 Andreas Steffen
<pre>
238 7 Andreas Steffen
16[IMV] operating system name is 'Debian' from vendor Debian Project
239 7 Andreas Steffen
16[IMV] operating system version is '7.5 x86_64'
240 7 Andreas Steffen
16[IMV] operating system numeric version is 7.5
241 7 Andreas Steffen
16[IMV] operational status: operational, result: successful
242 7 Andreas Steffen
16[IMV] last boot: Oct 06 19:31:00 UTC 2014
243 7 Andreas Steffen
16[IMV] IPv4 forwarding is enabled
244 7 Andreas Steffen
16[IMV] factory default password is disabled
245 7 Andreas Steffen
16[IMV] device ID is aabbccddeeff11223344556677889900
246 6 Andreas Steffen
</pre>
247 8 Andreas Steffen
248 8 Andreas Steffen
<pre>
249 8 Andreas Steffen
16[IMV] assigned session ID 2 to Connection ID 1
250 8 Andreas Steffen
16[IMV] running policy script: 2>&1 ipsec imv_policy_manager start 2
251 8 Andreas Steffen
16[IMV] policy: imv_policy_manager start successful
252 8 Andreas Steffen
16[IMV] DREFM workitem 1
253 8 Andreas Steffen
16[IMV] FWDEN workitem 2
254 8 Andreas Steffen
16[IMV] SWIDT workitem 3
255 8 Andreas Steffen
</pre>
256 8 Andreas Steffen
257 8 Andreas Steffen
<pre>
258 8 Andreas Steffen
16[IMV] IMV 1 handles FWDEN workitem 2
259 8 Andreas Steffen
16[IMV] IMV 1 handled FWDEN workitem 2: isolate - forwarding enabled
260 8 Andreas Steffen
16[TNC] creating PA-TNC message with ID 0x3fb2eb38
261 8 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
262 8 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'IETF/Remediation Instructions' 0x000000/0x0000000a
263 8 Andreas Steffen
16[IMV] created PA-TNC message: => 117 bytes @ 0x7ab630
264 8 Andreas Steffen
16[IMV]    0: 01 00 00 00 3F B2 EB 38 00 00 00 00 00 00 00 09  ....?..8........
265 8 Andreas Steffen
16[IMV]   16: 00 00 00 10 00 00 00 02 00 00 00 00 00 00 00 0A  ................
266 8 Andreas Steffen
16[IMV]   32: 00 00 00 5D 00 00 00 00 00 00 00 02 00 00 00 42  ...]...........B
267 8 Andreas Steffen
16[IMV]   48: 49 50 20 50 61 63 6B 65 74 20 46 6F 72 77 61 72  IP Packet Forwar
268 8 Andreas Steffen
16[IMV]   64: 64 69 6E 67 0A 20 20 50 6C 65 61 73 65 20 64 69  ding.  Please di
269 8 Andreas Steffen
16[IMV]   80: 73 61 62 6C 65 20 74 68 65 20 66 6F 72 77 61 72  sable the forwar
270 8 Andreas Steffen
16[IMV]   96: 64 69 6E 67 20 6F 66 20 49 50 20 70 61 63 6B 65  ding of IP packe
271 8 Andreas Steffen
16[IMV]  112: 74 73 02 65 6E                                   ts.en
272 8 Andreas Steffen
16[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
273 8 Andreas Steffen
16[TNC] IMV 1 is setting reason string to 'Improper OS settings were detected'
274 8 Andreas Steffen
16[TNC] IMV 1 is setting reason language to 'en'
275 1 Andreas Steffen
16[TNC] IMV 1 provides recommendation 'isolate' and evaluation 'non-compliant major'
276 1 Andreas Steffen
</pre>
277 1 Andreas Steffen
278 18 Andreas Steffen
h3. Sending Max Attribute Size Request for IF-M message type 'TCG/SWID'
279 15 Andreas Steffen
280 9 Andreas Steffen
<pre>
281 9 Andreas Steffen
16[IMV] IMV 2 requests a segmentation contract for PA message type 'TCG/SWID' 0x005597/0x00000003
282 9 Andreas Steffen
16[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes
283 9 Andreas Steffen
</pre>
284 9 Andreas Steffen
285 9 Andreas Steffen
<pre>
286 9 Andreas Steffen
16[IMV] IMV 2 handles SWIDT workitem 3
287 9 Andreas Steffen
16[IMV] IMV 2 issues SWID request 3
288 9 Andreas Steffen
</pre>
289 9 Andreas Steffen
290 9 Andreas Steffen
<pre>
291 9 Andreas Steffen
16[TNC] creating PA-TNC message with ID 0x8fc76ae4
292 9 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
293 9 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'TCG/SWID Request' 0x005597/0x00000011
294 9 Andreas Steffen
16[IMV] created PA-TNC message: => 52 bytes @ 0x7eaaa0
295 9 Andreas Steffen
16[IMV]    0: 01 00 00 00 8F C7 6A E4 00 00 55 97 00 00 00 21  ......j...U....!
296 9 Andreas Steffen
16[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 FF A6 00 00 55 97  ..............U.
297 9 Andreas Steffen
16[IMV]   32: 00 00 00 11 00 00 00 18 00 00 00 00 00 00 00 03  ................
298 9 Andreas Steffen
16[IMV]   48: 00 00 00 00                                      ....
299 9 Andreas Steffen
16[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
300 9 Andreas Steffen
</pre>
301 9 Andreas Steffen
302 9 Andreas Steffen
<pre>
303 9 Andreas Steffen
16[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
304 9 Andreas Steffen
16[TNC] creating PB-TNC SDATA batch
305 9 Andreas Steffen
16[TNC] adding IETF/PB-PA message
306 9 Andreas Steffen
16[TNC] adding IETF/PB-PA message
307 9 Andreas Steffen
16[TNC] sending PB-TNC SDATA batch (225 bytes) for Connection ID 1
308 9 Andreas Steffen
16[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
309 8 Andreas Steffen
</pre>
310 10 Andreas Steffen
311 10 Andreas Steffen
<pre>
312 10 Andreas Steffen
16[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
313 10 Andreas Steffen
02[CFG] received RADIUS Access-Request from client '10.1.0.1'
314 10 Andreas Steffen
02[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
315 10 Andreas Steffen
02[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
316 10 Andreas Steffen
01[CFG] received RADIUS Access-Request from client '10.1.0.1'
317 10 Andreas Steffen
01[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
318 10 Andreas Steffen
01[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
319 10 Andreas Steffen
        ... 30 more RADIUS exchanges
320 10 Andreas Steffen
14[CFG] received RADIUS Access-Request from client '10.1.0.1'
321 10 Andreas Steffen
14[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
322 10 Andreas Steffen
</pre>
323 10 Andreas Steffen
324 10 Andreas Steffen
<pre>
325 10 Andreas Steffen
14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
326 10 Andreas Steffen
14[TNC] received TNCCS batch (32754 bytes) for Connection ID 1
327 10 Andreas Steffen
14[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
328 10 Andreas Steffen
14[TNC] processing PB-TNC CDATA batch
329 10 Andreas Steffen
14[TNC] processing IETF/PB-PA message (32746 bytes)
330 10 Andreas Steffen
</pre>
331 10 Andreas Steffen
332 10 Andreas Steffen
<pre>
333 10 Andreas Steffen
14[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
334 10 Andreas Steffen
14[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
335 10 Andreas Steffen
14[IMV] => 32722 bytes @ 0x81f620
336 10 Andreas Steffen
14[IMV]    0: 01 00 00 00 C6 E7 09 AA 00 00 55 97 00 00 00 22  ..........U...."
337 10 Andreas Steffen
14[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6 00 00 55 97  ..............U.
338 10 Andreas Steffen
14[IMV]   32: 00 00 00 23 00 00 7F B6 C0 00 00 01 00 00 55 97  ...#..........U.
339 10 Andreas Steffen
14[IMV]   48: 00 00 00 14 00 01 C4 84 00 00 01 74 00 00 00 03  ...........t....
340 10 Andreas Steffen
14[IMV]   64: F1 07 0C 90 00 00 00 01 00 00 00 00 01 35 3C 53  .............5<S
341 10 Andreas Steffen
14[IMV]   80: 6F 66 74 77 61 72 65 49 64 65 6E 74 69 74 79 20  oftwareIdentity 
342 10 Andreas Steffen
14[IMV]   96: 6E 61 6D 65 3D 22 61 63 70 69 2D 73 75 70 70 6F  name="acpi-suppo
343 10 Andreas Steffen
14[IMV]  112: 72 74 2D 62 61 73 65 22 20 75 6E 69 71 75 65 49  rt-base" uniqueI
344 10 Andreas Steffen
14[IMV]  128: 64 3D 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38  d="debian_7.5-x8
345 10 Andreas Steffen
14[IMV]  144: 36 5F 36 34 2D 61 63 70 69 2D 73 75 70 70 6F 72  6_64-acpi-suppor
346 10 Andreas Steffen
14[IMV]  160: 74 2D 62 61 73 65 2D 30 2E 31 34 30 2D 35 22 20  t-base-0.140-5" 
347 10 Andreas Steffen
14[IMV]  176: 76 65 72 73 69 6F 6E 3D 22 30 2E 31 34 30 2D 35  version="0.140-5
348 10 Andreas Steffen
14[IMV]  192: 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D 65 3D  " versionScheme=
349 10 Andreas Steffen
14[IMV]  208: 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22 20 78  "alphanumeric" x
350 10 Andreas Steffen
14[IMV]  224: 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F 2F 73 74 61  mlns="http://sta
351 10 Andreas Steffen
14[IMV]  240: 6E 64 61 72 64 73 2E 69 73 6F 2E 6F 72 67 2F 69  ndards.iso.org/i
352 10 Andreas Steffen
14[IMV]  256: 73 6F 2F 31 39 37 37 30 2F 2D 32 2F 32 30 31 34  so/19770/-2/2014
353 10 Andreas Steffen
14[IMV]  272: 2F 73 63 68 65 6D 61 2E 78 73 64 22 3E 3C 45 6E  /schema.xsd"><En
354 10 Andreas Steffen
14[IMV]  288: 74 69 74 79 20 6E 61 6D 65 3D 22 73 74 72 6F 6E  tity name="stron
355 10 Andreas Steffen
14[IMV]  304: 67 53 77 61 6E 22 20 72 65 67 69 64 3D 22 72 65  gSwan" regid="re
356 10 Andreas Steffen
14[IMV]  320: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
357 10 Andreas Steffen
14[IMV]  336: 73 74 72 6F 6E 67 73 77 61 6E 22 20 72 6F 6C 65  strongswan" role
358 10 Andreas Steffen
14[IMV]  352: 3D 22 74 61 67 63 72 65 61 74 6F 72 22 20 2F 3E  ="tagcreator" />
359 10 Andreas Steffen
14[IMV]  368: 3C 2F 53 6F 66 74 77 61 72 65 49 64 65 6E 74 69  </SoftwareIdenti
360 10 Andreas Steffen
14[IMV]  384: 74 79 3E 00 00 00 00 01 31 3C 53 6F 66 74 77 61  ty>.....1<Softwa
361 10 Andreas Steffen
14[IMV]  400: 72 65 49 64 65 6E 74 69 74 79 20 6E 61 6D 65 3D  reIdentity name=
362 10 Andreas Steffen
14[IMV]  416: 22 61 63 70 69 64 22 20 75 6E 69 71 75 65 49 64  "acpid" uniqueId
363 10 Andreas Steffen
         ...
364 10 Andreas Steffen
14[IMV] 32624: 20 2F 3E 3C 2F 53 6F 66 74 77 61 72 65 49 64 65   /></SoftwareIde
365 10 Andreas Steffen
14[IMV] 32640: 6E 74 69 74 79 3E 00 00 00 00 01 2F 3C 53 6F 66  ntity>...../<Sof
366 10 Andreas Steffen
14[IMV] 32656: 74 77 61 72 65 49 64 65 6E 74 69 74 79 20 6E 61  twareIdentity na
367 10 Andreas Steffen
14[IMV] 32672: 6D 65 3D 22 6C 69 62 61 70 72 31 22 20 75 6E 69  me="libapr1" uni
368 10 Andreas Steffen
14[IMV] 32688: 71 75 65 49 64 3D 22 64 65 62 69 61 6E 5F 37 2E  queId="debian_7.
369 10 Andreas Steffen
14[IMV] 32704: 35 2D 78 38 36 5F 36 34 2D 6C 69 62 61 70 72 31  5-x86_64-libapr1
370 10 Andreas Steffen
14[IMV] 32720: 2D 31                                            -1
371 10 Andreas Steffen
14[TNC] processing PA-TNC message with ID 0xc6e709aa
372 1 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
373 10 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
374 10 Andreas Steffen
</pre>
375 10 Andreas Steffen
376 18 Andreas Steffen
h3. Received Max Attribute Size Response for IF-M Message Type 'TCG/SWID ' 
377 14 Andreas Steffen
378 1 Andreas Steffen
<pre>
379 1 Andreas Steffen
14[IMV] received a segmentation contract response for PA message type 'TCG/SWID' 0x005597/0x00000003
380 1 Andreas Steffen
14[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 32678 bytes
381 10 Andreas Steffen
</pre>
382 10 Andreas Steffen
383 24 Andreas Steffen
h3. Received First Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
384 15 Andreas Steffen
385 10 Andreas Steffen
<pre>
386 10 Andreas Steffen
14[TNC] received first segment for base attribute ID 1 (32678 bytes)
387 10 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/SWID Tag Inventory' 0x005597/0x00000014
388 10 Andreas Steffen
14[LIB] 70 bytes insufficient to parse 303 bytes of data
389 1 Andreas Steffen
14[IMV] received SWID tag inventory with 106 items for request 3 at eid 1 of epoch 0xf1070c90, 266 items to follow
390 1 Andreas Steffen
14[IMV] <SoftwareIdentity name="acpi-support-base" uniqueId="debian_7.5-x86_64-acpi-support-base-0.140-5" version="0.140-5" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
391 10 Andreas Steffen
14[IMV] <SoftwareIdentity name="acpid" uniqueId="debian_7.5-x86_64-acpid-1:2.0.16-1+deb7u1" version="1:2.0.16-1+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
392 10 Andreas Steffen
        ... 103 more SWID tags
393 10 Andreas Steffen
14[IMV] <SoftwareIdentity name="libapache2-mod-wsgi" uniqueId="debian_7.5-x86_64-libapache2-mod-wsgi-3.3-4" version="3.3-4" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
394 12 Andreas Steffen
</pre>
395 18 Andreas Steffen
396 18 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
397 12 Andreas Steffen
398 12 Andreas Steffen
<pre>
399 12 Andreas Steffen
14[TNC] creating PA-TNC message with ID 0x636ebdaa
400 12 Andreas Steffen
14[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
401 12 Andreas Steffen
14[IMV] created PA-TNC message: => 24 bytes @ 0x7b2e10
402 12 Andreas Steffen
14[IMV]    0: 01 00 00 00 63 6E BD AA 00 00 55 97 00 00 00 24  ....cn....U....$
403 12 Andreas Steffen
14[IMV]   16: 00 00 00 10 00 00 00 01                          ........
404 12 Andreas Steffen
14[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
405 12 Andreas Steffen
</pre>
406 12 Andreas Steffen
407 12 Andreas Steffen
<pre>
408 12 Andreas Steffen
14[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
409 12 Andreas Steffen
14[TNC] creating PB-TNC SDATA batch
410 12 Andreas Steffen
14[TNC] adding IETF/PB-PA message
411 12 Andreas Steffen
14[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 1
412 12 Andreas Steffen
14[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
413 10 Andreas Steffen
</pre>
414 13 Andreas Steffen
415 13 Andreas Steffen
<pre>
416 13 Andreas Steffen
14[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
417 13 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
418 13 Andreas Steffen
03[CFG] ignoring RADIUS Access-Request 0x3f, already processing
419 13 Andreas Steffen
15[CFG] received RADIUS Access-Request from client '10.1.0.1'
420 13 Andreas Steffen
15[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
421 1 Andreas Steffen
15[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
422 14 Andreas Steffen
         ... 31 more RADIUS exchanges
423 13 Andreas Steffen
12[CFG] received RADIUS Access-Request from client '10.1.0.1'
424 13 Andreas Steffen
12[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
425 13 Andreas Steffen
</pre>
426 13 Andreas Steffen
427 13 Andreas Steffen
<pre>
428 13 Andreas Steffen
12[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
429 13 Andreas Steffen
12[TNC] received TNCCS batch (32734 bytes) for Connection ID 1
430 13 Andreas Steffen
12[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
431 13 Andreas Steffen
12[TNC] processing PB-TNC CDATA batch
432 1 Andreas Steffen
12[TNC] processing IETF/PB-PA message (32726 bytes)
433 14 Andreas Steffen
</pre>
434 14 Andreas Steffen
435 14 Andreas Steffen
<pre>
436 14 Andreas Steffen
12[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
437 14 Andreas Steffen
12[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
438 14 Andreas Steffen
12[IMV] => 32702 bytes @ 0x80b530
439 14 Andreas Steffen
12[IMV]    0: 01 00 00 00 A7 75 C2 64 00 00 55 97 00 00 00 23  .....u.d..U....#
440 14 Andreas Steffen
12[IMV]   16: 00 00 7F B6 80 00 00 01 2E 34 2E 36 2D 33 2B 64  .........4.6-3+d
441 14 Andreas Steffen
12[IMV]   32: 65 62 37 75 31 22 20 76 65 72 73 69 6F 6E 3D 22  eb7u1" version="
442 14 Andreas Steffen
12[IMV]   48: 31 2E 34 2E 36 2D 33 2B 64 65 62 37 75 31 22 20  1.4.6-3+deb7u1" 
443 14 Andreas Steffen
12[IMV]   64: 76 65 72 73 69 6F 6E 53 63 68 65 6D 65 3D 22 61  versionScheme="a
444 14 Andreas Steffen
12[IMV]   80: 6C 70 68 61 6E 75 6D 65 72 69 63 22 20 78 6D 6C  lphanumeric" xml
445 14 Andreas Steffen
12[IMV]   96: 6E 73 3D 22 68 74 74 70 3A 2F 2F 73 74 61 6E 64  ns="http://stand
446 14 Andreas Steffen
12[IMV]  112: 61 72 64 73 2E 69 73 6F 2E 6F 72 67 2F 69 73 6F  ards.iso.org/iso
447 14 Andreas Steffen
12[IMV]  128: 2F 31 39 37 37 30 2F 2D 32 2F 32 30 31 34 2F 73  /19770/-2/2014/s
448 14 Andreas Steffen
12[IMV]  144: 63 68 65 6D 61 2E 78 73 64 22 3E 3C 45 6E 74 69  chema.xsd"><Enti
449 14 Andreas Steffen
12[IMV]  160: 74 79 20 6E 61 6D 65 3D 22 73 74 72 6F 6E 67 53  ty name="strongS
450 14 Andreas Steffen
12[IMV]  176: 77 61 6E 22 20 72 65 67 69 64 3D 22 72 65 67 69  wan" regid="regi
451 14 Andreas Steffen
12[IMV]  192: 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E 73 74  d.2004-03.org.st
452 14 Andreas Steffen
12[IMV]  208: 72 6F 6E 67 73 77 61 6E 22 20 72 6F 6C 65 3D 22  rongswan" role="
453 14 Andreas Steffen
12[IMV]  224: 74 61 67 63 72 65 61 74 6F 72 22 20 2F 3E 3C 2F  tagcreator" /></
454 14 Andreas Steffen
12[IMV]  240: 53 6F 66 74 77 61 72 65 49 64 65 6E 74 69 74 79  SoftwareIdentity
455 14 Andreas Steffen
12[IMV]  256: 3E 00 00 00 00 01 37 3C 53 6F 66 74 77 61 72 65  >.....7<Software
456 14 Andreas Steffen
12[IMV]  272: 49 64 65 6E 74 69 74 79 20 6E 61 6D 65 3D 22 6C  Identity name="l
457 14 Andreas Steffen
12[IMV]  288: 69 62 61 70 72 31 2D 64 65 76 22 20 75 6E 69 71  ibapr1-dev" uniq
458 14 Andreas Steffen
         ...
459 14 Andreas Steffen
12[IMV] 32416: 01 31 3C 53 6F 66 74 77 61 72 65 49 64 65 6E 74  .1<SoftwareIdent
460 14 Andreas Steffen
12[IMV] 32432: 69 74 79 20 6E 61 6D 65 3D 22 6C 69 62 6C 6F 67  ity name="liblog
461 14 Andreas Steffen
12[IMV] 32448: 34 63 78 78 31 30 22 20 75 6E 69 71 75 65 49 64  4cxx10" uniqueId
462 14 Andreas Steffen
12[IMV] 32464: 3D 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36  ="debian_7.5-x86
463 14 Andreas Steffen
12[IMV] 32480: 5F 36 34 2D 6C 69 62 6C 6F 67 34 63 78 78 31 30  _64-liblog4cxx10
464 14 Andreas Steffen
12[IMV] 32496: 2D 30 2E 31 30 2E 30 2D 31 2E 32 22 20 76 65 72  -0.10.0-1.2" ver
465 14 Andreas Steffen
12[IMV] 32512: 73 69 6F 6E 3D 22 30 2E 31 30 2E 30 2D 31 2E 32  sion="0.10.0-1.2
466 14 Andreas Steffen
12[IMV] 32528: 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D 65 3D  " versionScheme=
467 14 Andreas Steffen
12[IMV] 32544: 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22 20 78  "alphanumeric" x
468 14 Andreas Steffen
12[IMV] 32560: 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F 2F 73 74 61  mlns="http://sta
469 14 Andreas Steffen
12[IMV] 32576: 6E 64 61 72 64 73 2E 69 73 6F 2E 6F 72 67 2F 69  ndards.iso.org/i
470 14 Andreas Steffen
12[IMV] 32592: 73 6F 2F 31 39 37 37 30 2F 2D 32 2F 32 30 31 34  so/19770/-2/2014
471 14 Andreas Steffen
12[IMV] 32608: 2F 73 63 68 65 6D 61 2E 78 73 64 22 3E 3C 45 6E  /schema.xsd"><En
472 14 Andreas Steffen
12[IMV] 32624: 74 69 74 79 20 6E 61 6D 65 3D 22 73 74 72 6F 6E  tity name="stron
473 14 Andreas Steffen
12[IMV] 32640: 67 53 77 61 6E 22 20 72 65 67 69 64 3D 22 72 65  gSwan" regid="re
474 14 Andreas Steffen
12[IMV] 32656: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
475 1 Andreas Steffen
12[IMV] 32672: 73 74 72 6F 6E 67 73 77 61 6E 22 20 72 6F 6C 65  strongswan" role
476 1 Andreas Steffen
12[IMV] 32688: 3D 22 74 61 67 63 72 65 61 74 6F 72 22 20        ="tagcreator" 
477 14 Andreas Steffen
12[TNC] processing PA-TNC message with ID 0xa775c264
478 14 Andreas Steffen
12[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
479 14 Andreas Steffen
</pre>
480 14 Andreas Steffen
481 24 Andreas Steffen
h3. Received Next Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
482 14 Andreas Steffen
483 20 Andreas Steffen
<pre>
484 14 Andreas Steffen
12[TNC] received next segment for base attribute ID 1 (32678 bytes)
485 14 Andreas Steffen
12[LIB] 284 bytes insufficient to parse 305 bytes of data
486 14 Andreas Steffen
12[IMV] received SWID tag inventory with 102 items for request 3 at eid 1 of epoch 0xf1070c90, 164 items to follow
487 14 Andreas Steffen
12[IMV] <SoftwareIdentity name="libapr1" uniqueId="debian_7.5-x86_64-libapr1-1.4.6-3+deb7u1" version="1.4.6-3+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
488 14 Andreas Steffen
12[IMV] <SoftwareIdentity name="libapr1-dev" uniqueId="debian_7.5-x86_64-libapr1-dev-1.4.6-3+deb7u1" version="1.4.6-3+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
489 1 Andreas Steffen
        ... 99 more SWID tags
490 1 Andreas Steffen
12[IMV] <SoftwareIdentity name="liblocale-gettext-perl" uniqueId="debian_7.5-x86_64-liblocale-gettext-perl-1.05-7+b1" version="1.05-7+b1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
491 19 Andreas Steffen
</pre>
492 19 Andreas Steffen
493 19 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
494 19 Andreas Steffen
495 19 Andreas Steffen
<pre>
496 19 Andreas Steffen
12[TNC] creating PA-TNC message with ID 0x5382f1b3
497 19 Andreas Steffen
12[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
498 19 Andreas Steffen
12[IMV] created PA-TNC message: => 24 bytes @ 0x7c6f20
499 19 Andreas Steffen
12[IMV]    0: 01 00 00 00 53 82 F1 B3 00 00 55 97 00 00 00 24  ....S.....U....$
500 19 Andreas Steffen
12[IMV]   16: 00 00 00 10 00 00 00 01                          ........
501 19 Andreas Steffen
12[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
502 19 Andreas Steffen
</pre>
503 19 Andreas Steffen
504 19 Andreas Steffen
<pre>
505 19 Andreas Steffen
12[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
506 19 Andreas Steffen
12[TNC] creating PB-TNC SDATA batch
507 19 Andreas Steffen
12[TNC] adding IETF/PB-PA message
508 19 Andreas Steffen
12[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 1
509 19 Andreas Steffen
12[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
510 19 Andreas Steffen
</pre>
511 19 Andreas Steffen
512 19 Andreas Steffen
<pre>
513 19 Andreas Steffen
12[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
514 19 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
515 19 Andreas Steffen
13[CFG] ignoring RADIUS Access-Request 0x60, already processing
516 19 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
517 19 Andreas Steffen
03[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
518 19 Andreas Steffen
03[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
519 19 Andreas Steffen
        ... 31 more RADIUS exchanges
520 19 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
521 19 Andreas Steffen
04[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
522 19 Andreas Steffen
</pre>
523 19 Andreas Steffen
524 19 Andreas Steffen
<pre>
525 19 Andreas Steffen
04[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
526 19 Andreas Steffen
04[TNC] received TNCCS batch (32734 bytes) for Connection ID 1
527 19 Andreas Steffen
04[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
528 19 Andreas Steffen
04[TNC] processing PB-TNC CDATA batch
529 19 Andreas Steffen
04[TNC] processing IETF/PB-PA message (32726 bytes)
530 19 Andreas Steffen
</pre>
531 19 Andreas Steffen
532 19 Andreas Steffen
<pre>
533 19 Andreas Steffen
04[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
534 19 Andreas Steffen
04[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
535 19 Andreas Steffen
04[IMV] => 32702 bytes @ 0x82b510
536 19 Andreas Steffen
04[IMV]    0: 01 00 00 00 08 CC 13 66 00 00 55 97 00 00 00 23  .......f..U....#
537 19 Andreas Steffen
04[IMV]   16: 00 00 7F B6 80 00 00 01 2F 3E 3C 2F 53 6F 66 74  ......../></Soft
538 19 Andreas Steffen
04[IMV]   32: 77 61 72 65 49 64 65 6E 74 69 74 79 3E 00 00 00  wareIdentity>...
539 19 Andreas Steffen
04[IMV]   48: 00 01 39 3C 53 6F 66 74 77 61 72 65 49 64 65 6E  ..9<SoftwareIden
540 19 Andreas Steffen
04[IMV]   64: 74 69 74 79 20 6E 61 6D 65 3D 22 6C 69 62 6C 6F  tity name="liblo
541 19 Andreas Steffen
04[IMV]   80: 67 34 63 78 78 31 30 2D 64 65 76 22 20 75 6E 69  g4cxx10-dev" uni
542 19 Andreas Steffen
         ...
543 19 Andreas Steffen
04[IMV] 32288: 74 69 74 79 3E 00 00 00 00 01 43 3C 53 6F 66 74  tity>.....C<Soft
544 19 Andreas Steffen
04[IMV] 32304: 77 61 72 65 49 64 65 6E 74 69 74 79 20 6E 61 6D  wareIdentity nam
545 19 Andreas Steffen
04[IMV] 32320: 65 3D 22 6D 75 6C 74 69 61 72 63 68 2D 73 75 70  e="multiarch-sup
546 19 Andreas Steffen
04[IMV] 32336: 70 6F 72 74 22 20 75 6E 69 71 75 65 49 64 3D 22  port" uniqueId="
547 19 Andreas Steffen
04[IMV] 32352: 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36 5F 36  debian_7.5-x86_6
548 19 Andreas Steffen
04[IMV] 32368: 34 2D 6D 75 6C 74 69 61 72 63 68 2D 73 75 70 70  4-multiarch-supp
549 19 Andreas Steffen
04[IMV] 32384: 6F 72 74 2D 32 2E 31 33 2D 33 38 2B 64 65 62 37  ort-2.13-38+deb7
550 19 Andreas Steffen
04[IMV] 32400: 75 31 22 20 76 65 72 73 69 6F 6E 3D 22 32 2E 31  u1" version="2.1
551 19 Andreas Steffen
04[IMV] 32416: 33 2D 33 38 2B 64 65 62 37 75 31 22 20 76 65 72  3-38+deb7u1" ver
552 19 Andreas Steffen
04[IMV] 32432: 73 69 6F 6E 53 63 68 65 6D 65 3D 22 61 6C 70 68  sionScheme="alph
553 19 Andreas Steffen
04[IMV] 32448: 61 6E 75 6D 65 72 69 63 22 20 78 6D 6C 6E 73 3D  anumeric" xmlns=
554 19 Andreas Steffen
04[IMV] 32464: 22 68 74 74 70 3A 2F 2F 73 74 61 6E 64 61 72 64  "http://standard
555 19 Andreas Steffen
04[IMV] 32480: 73 2E 69 73 6F 2E 6F 72 67 2F 69 73 6F 2F 31 39  s.iso.org/iso/19
556 19 Andreas Steffen
04[IMV] 32496: 37 37 30 2F 2D 32 2F 32 30 31 34 2F 73 63 68 65  770/-2/2014/sche
557 19 Andreas Steffen
04[IMV] 32512: 6D 61 2E 78 73 64 22 3E 3C 45 6E 74 69 74 79 20  ma.xsd"><Entity 
558 19 Andreas Steffen
04[IMV] 32528: 6E 61 6D 65 3D 22 73 74 72 6F 6E 67 53 77 61 6E  name="strongSwan
559 19 Andreas Steffen
04[IMV] 32544: 22 20 72 65 67 69 64 3D 22 72 65 67 69 64 2E 32  " regid="regid.2
560 19 Andreas Steffen
04[IMV] 32560: 30 30 34 2D 30 33 2E 6F 72 67 2E 73 74 72 6F 6E  004-03.org.stron
561 19 Andreas Steffen
04[IMV] 32576: 67 73 77 61 6E 22 20 72 6F 6C 65 3D 22 74 61 67  gswan" role="tag
562 19 Andreas Steffen
04[IMV] 32592: 63 72 65 61 74 6F 72 22 20 2F 3E 3C 2F 53 6F 66  creator" /></Sof
563 19 Andreas Steffen
04[IMV] 32608: 74 77 61 72 65 49 64 65 6E 74 69 74 79 3E 00 00  twareIdentity>..
564 19 Andreas Steffen
04[IMV] 32624: 00 00 01 47 3C 53 6F 66 74 77 61 72 65 49 64 65  ...G<SoftwareIde
565 19 Andreas Steffen
04[IMV] 32640: 6E 74 69 74 79 20 6E 61 6D 65 3D 22 6D 79 73 71  ntity name="mysq
566 19 Andreas Steffen
04[IMV] 32656: 6C 2D 63 6F 6D 6D 6F 6E 22 20 75 6E 69 71 75 65  l-common" unique
567 19 Andreas Steffen
04[IMV] 32672: 49 64 3D 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78  Id="debian_7.5-x
568 19 Andreas Steffen
04[IMV] 32688: 38 36 5F 36 34 2D 6D 79 73 71 6C 2D 63 6F        86_64-mysql-co
569 19 Andreas Steffen
04[TNC] processing PA-TNC message with ID 0x08cc1366
570 19 Andreas Steffen
04[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
571 19 Andreas Steffen
</pre>
572 19 Andreas Steffen
573 24 Andreas Steffen
h3. Received Next Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
574 19 Andreas Steffen
575 19 Andreas Steffen
<pre>
576 19 Andreas Steffen
04[TNC] received next segment for base attribute ID 1 (32678 bytes)
577 19 Andreas Steffen
04[LIB] 74 bytes insufficient to parse 327 bytes of data
578 19 Andreas Steffen
04[IMV] received SWID tag inventory with 106 items for request 3 at eid 1 of epoch 0xf1070c90, 58 items to follow
579 19 Andreas Steffen
04[IMV] <SoftwareIdentity name="liblog4cxx10" uniqueId="debian_7.5-x86_64-liblog4cxx10-0.10.0-1.2" version="0.10.0-1.2" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
580 1 Andreas Steffen
04[IMV] <SoftwareIdentity name="liblog4cxx10-dev" uniqueId="debian_7.5-x86_64-liblog4cxx10-dev-0.10.0-1.2" version="0.10.0-1.2" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
581 20 Andreas Steffen
      ... 103 more SWID tags
582 20 Andreas Steffen
04[IMV] <SoftwareIdentity name="multiarch-support" uniqueId="debian_7.5-x86_64-multiarch-support-2.13-38+deb7u1" version="2.13-38+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
583 20 Andreas Steffen
</pre>
584 20 Andreas Steffen
585 20 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
586 20 Andreas Steffen
587 20 Andreas Steffen
<pre>
588 20 Andreas Steffen
04[TNC] creating PA-TNC message with ID 0x76280e6a
589 20 Andreas Steffen
04[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
590 20 Andreas Steffen
04[IMV] created PA-TNC message: => 24 bytes @ 0x7a7860
591 20 Andreas Steffen
04[IMV]    0: 01 00 00 00 76 28 0E 6A 00 00 55 97 00 00 00 24  ....v(.j..U....$
592 20 Andreas Steffen
04[IMV]   16: 00 00 00 10 00 00 00 01                          ........
593 20 Andreas Steffen
04[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
594 20 Andreas Steffen
</pre>
595 20 Andreas Steffen
596 20 Andreas Steffen
<pre>
597 20 Andreas Steffen
04[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
598 20 Andreas Steffen
04[TNC] creating PB-TNC SDATA batch
599 20 Andreas Steffen
04[TNC] adding IETF/PB-PA message
600 20 Andreas Steffen
04[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 1
601 20 Andreas Steffen
04[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
602 20 Andreas Steffen
</pre>
603 20 Andreas Steffen
604 20 Andreas Steffen
<pre>
605 20 Andreas Steffen
04[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
606 20 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
607 20 Andreas Steffen
11[CFG] ignoring RADIUS Access-Request 0x81, already processing
608 20 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
609 20 Andreas Steffen
13[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
610 20 Andreas Steffen
13[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
611 20 Andreas Steffen
        ... 15 more RADIUS exchanges
612 20 Andreas Steffen
16[CFG] received RADIUS Access-Request from client '10.1.0.1'
613 20 Andreas Steffen
16[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
614 20 Andreas Steffen
</pre>
615 20 Andreas Steffen
616 20 Andreas Steffen
<pre>
617 20 Andreas Steffen
16[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
618 20 Andreas Steffen
16[TNC] received TNCCS batch (17866 bytes) for Connection ID 1
619 20 Andreas Steffen
16[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
620 20 Andreas Steffen
16[TNC] processing PB-TNC CDATA batch
621 20 Andreas Steffen
16[TNC] processing IETF/PB-PA message (17858 bytes)
622 20 Andreas Steffen
</pre>
623 20 Andreas Steffen
624 20 Andreas Steffen
<pre>
625 21 Andreas Steffen
16[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
626 21 Andreas Steffen
16[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
627 21 Andreas Steffen
16[IMV]    0: 01 00 00 00 15 7F 65 95 00 00 55 97 00 00 00 23  ......e...U....#
628 21 Andreas Steffen
16[IMV]   16: 00 00 45 A2 00 00 00 01 6D 6D 6F 6E 2D 35 2E 35  ..E.....mmon-5.5
629 21 Andreas Steffen
16[IMV]   32: 2E 33 35 2B 64 66 73 67 2D 30 2B 77 68 65 65 7A  .35+dfsg-0+wheez
630 21 Andreas Steffen
16[IMV]   48: 79 31 22 20 76 65 72 73 69 6F 6E 3D 22 35 2E 35  y1" version="5.5
631 21 Andreas Steffen
16[IMV]   64: 2E 33 35 2B 64 66 73 67 2D 30 2B 77 68 65 65 7A  .35+dfsg-0+wheez
632 21 Andreas Steffen
16[IMV]   80: 79 31 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D  y1" versionSchem
633 21 Andreas Steffen
16[IMV]   96: 65 3D 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22  e="alphanumeric"
634 21 Andreas Steffen
16[IMV]  112: 20 78 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F 2F 73   xmlns="http://s
635 21 Andreas Steffen
16[IMV]  128: 74 61 6E 64 61 72 64 73 2E 69 73 6F 2E 6F 72 67  tandards.iso.org
636 21 Andreas Steffen
16[IMV]  144: 2F 69 73 6F 2F 31 39 37 37 30 2F 2D 32 2F 32 30  /iso/19770/-2/20
637 21 Andreas Steffen
16[IMV]  160: 31 34 2F 73 63 68 65 6D 61 2E 78 73 64 22 3E 3C  14/schema.xsd"><
638 21 Andreas Steffen
16[IMV]  176: 45 6E 74 69 74 79 20 6E 61 6D 65 3D 22 73 74 72  Entity name="str
639 21 Andreas Steffen
16[IMV]  192: 6F 6E 67 53 77 61 6E 22 20 72 65 67 69 64 3D 22  ongSwan" regid="
640 21 Andreas Steffen
16[IMV]  208: 72 65 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72  regid.2004-03.or
641 21 Andreas Steffen
16[IMV]  224: 67 2E 73 74 72 6F 6E 67 73 77 61 6E 22 20 72 6F  g.strongswan" ro
642 21 Andreas Steffen
16[IMV]  240: 6C 65 3D 22 74 61 67 63 72 65 61 74 6F 72 22 20  le="tagcreator" 
643 21 Andreas Steffen
16[IMV]  256: 2F 3E 3C 2F 53 6F 66 74 77 61 72 65 49 64 65 6E  /></SoftwareIden
644 21 Andreas Steffen
16[IMV]  272: 74 69 74 79 3E 00 00 00 00 01 21 3C 53 6F 66 74  tity>.....!<Soft
645 21 Andreas Steffen
16[IMV]  288: 77 61 72 65 49 64 65 6E 74 69 74 79 20 6E 61 6D  wareIdentity nam
646 21 Andreas Steffen
16[IMV]  304: 65 3D 22 6E 61 6E 6F 22 20 75 6E 69 71 75 65 49  e="nano" uniqueI
647 21 Andreas Steffen
   ...
648 21 Andreas Steffen
16[IMV] 17520: 00 01 37 3C 53 6F 66 74 77 61 72 65 49 64 65 6E  ..7<SoftwareIden
649 21 Andreas Steffen
16[IMV] 17536: 74 69 74 79 20 6E 61 6D 65 3D 22 7A 6C 69 62 31  tity name="zlib1
650 21 Andreas Steffen
16[IMV] 17552: 67 2D 64 65 76 22 20 75 6E 69 71 75 65 49 64 3D  g-dev" uniqueId=
651 21 Andreas Steffen
16[IMV] 17568: 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36 5F  "debian_7.5-x86_
652 21 Andreas Steffen
16[IMV] 17584: 36 34 2D 7A 6C 69 62 31 67 2D 64 65 76 2D 31 3A  64-zlib1g-dev-1:
653 21 Andreas Steffen
16[IMV] 17600: 31 2E 32 2E 37 2E 64 66 73 67 2D 31 33 22 20 76  1.2.7.dfsg-13" v
654 21 Andreas Steffen
16[IMV] 17616: 65 72 73 69 6F 6E 3D 22 31 3A 31 2E 32 2E 37 2E  ersion="1:1.2.7.
655 21 Andreas Steffen
16[IMV] 17632: 64 66 73 67 2D 31 33 22 20 76 65 72 73 69 6F 6E  dfsg-13" version
656 21 Andreas Steffen
16[IMV] 17648: 53 63 68 65 6D 65 3D 22 61 6C 70 68 61 6E 75 6D  Scheme="alphanum
657 21 Andreas Steffen
16[IMV] 17664: 65 72 69 63 22 20 78 6D 6C 6E 73 3D 22 68 74 74  eric" xmlns="htt
658 21 Andreas Steffen
16[IMV] 17680: 70 3A 2F 2F 73 74 61 6E 64 61 72 64 73 2E 69 73  p://standards.is
659 21 Andreas Steffen
16[IMV] 17696: 6F 2E 6F 72 67 2F 69 73 6F 2F 31 39 37 37 30 2F  o.org/iso/19770/
660 21 Andreas Steffen
16[IMV] 17712: 2D 32 2F 32 30 31 34 2F 73 63 68 65 6D 61 2E 78  -2/2014/schema.x
661 21 Andreas Steffen
16[IMV] 17728: 73 64 22 3E 3C 45 6E 74 69 74 79 20 6E 61 6D 65  sd"><Entity name
662 21 Andreas Steffen
16[IMV] 17744: 3D 22 73 74 72 6F 6E 67 53 77 61 6E 22 20 72 65  ="strongSwan" re
663 21 Andreas Steffen
16[IMV] 17760: 67 69 64 3D 22 72 65 67 69 64 2E 32 30 30 34 2D  gid="regid.2004-
664 21 Andreas Steffen
16[IMV] 17776: 30 33 2E 6F 72 67 2E 73 74 72 6F 6E 67 73 77 61  03.org.strongswa
665 21 Andreas Steffen
16[IMV] 17792: 6E 22 20 72 6F 6C 65 3D 22 74 61 67 63 72 65 61  n" role="tagcrea
666 21 Andreas Steffen
16[IMV] 17808: 74 6F 72 22 20 2F 3E 3C 2F 53 6F 66 74 77 61 72  tor" /></Softwar
667 21 Andreas Steffen
16[IMV] 17824: 65 49 64 65 6E 74 69 74 79 3E                    eIdentity>
668 21 Andreas Steffen
16[TNC] processing PA-TNC message with ID 0x157f6595
669 21 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
670 21 Andreas Steffen
</pre>
671 21 Andreas Steffen
672 24 Andreas Steffen
h3. Received Last Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
673 21 Andreas Steffen
674 21 Andreas Steffen
<pre>
675 21 Andreas Steffen
16[TNC] received last segment for base attribute ID 1 (17810 bytes)
676 21 Andreas Steffen
16[IMV] received SWID tag inventory with 58 items for request 3 at eid 1 of epoch 0xf1070c90, 0 items to follow
677 21 Andreas Steffen
16[IMV] <SoftwareIdentity name="mysql-common" uniqueId="debian_7.5-x86_64-mysql-common-5.5.35+dfsg-0+wheezy1" version="5.5.35+dfsg-0+wheezy1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
678 21 Andreas Steffen
16[IMV] <SoftwareIdentity name="nano" uniqueId="debian_7.5-x86_64-nano-2.2.6-1+b1" version="2.2.6-1+b1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
679 21 Andreas Steffen
        ...
680 21 Andreas Steffen
16[IMV] <SoftwareIdentity name="zlib1g-dev" uniqueId="debian_7.5-x86_64-zlib1g-dev-1:1.2.7.dfsg-13" version="1:1.2.7.dfsg-13" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
681 21 Andreas Steffen
</pre>
682 21 Andreas Steffen
683 21 Andreas Steffen
<pre>
684 21 Andreas Steffen
16[IMV] IMV 2 handled SWIDT workitem 3: allow - received inventory of 0 SWID tag IDs and 372 SWID tags
685 21 Andreas Steffen
16[TNC] creating PA-TNC message with ID 0x39b02ad7
686 21 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
687 21 Andreas Steffen
16[IMV] created PA-TNC message: => 24 bytes @ 0x7a7600
688 21 Andreas Steffen
16[IMV]    0: 01 00 00 00 39 B0 2A D7 00 00 00 00 00 00 00 09  ....9.*.........
689 21 Andreas Steffen
16[IMV]   16: 00 00 00 10 00 00 00 00                          ........
690 21 Andreas Steffen
16[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
691 21 Andreas Steffen
16[TNC] IMV 2 provides recommendation 'allow' and evaluation 'compliant'
692 21 Andreas Steffen
16[IMV] running policy script: 2>&1 ipsec imv_policy_manager stop 2
693 21 Andreas Steffen
16[IMV] policy: imv_policy_manager stop successful
694 21 Andreas Steffen
16[IMV] IMV 1 "OS" changed state of Connection ID 1 to 'Isolated'
695 21 Andreas Steffen
16[IMV] IMV 2 "SWID" changed state of Connection ID 1 to 'Isolated'
696 21 Andreas Steffen
</pre>
697 21 Andreas Steffen
698 21 Andreas Steffen
<pre>
699 21 Andreas Steffen
16[TNC] PB-TNC state transition from 'Server Working' to 'Decided'
700 21 Andreas Steffen
16[TNC] creating PB-TNC RESULT batch
701 21 Andreas Steffen
16[TNC] adding IETF/PB-PA message
702 21 Andreas Steffen
16[TNC] adding IETF/PB-Assessment-Result message
703 21 Andreas Steffen
16[TNC] adding IETF/PB-Access-Recommendation message
704 21 Andreas Steffen
16[TNC] adding IETF/PB-Reason-String message
705 21 Andreas Steffen
16[TNC] sending PB-TNC RESULT batch (141 bytes) for Connection ID 1
706 21 Andreas Steffen
16[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
707 21 Andreas Steffen
</pre>
708 21 Andreas Steffen
709 21 Andreas Steffen
<pre>
710 21 Andreas Steffen
16[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
711 21 Andreas Steffen
02[CFG] received RADIUS Access-Request from client '10.1.0.1'
712 21 Andreas Steffen
02[CFG] ignoring RADIUS Access-Request 0x93, already processing
713 21 Andreas Steffen
01[CFG] received RADIUS Access-Request from client '10.1.0.1'
714 21 Andreas Steffen
01[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
715 21 Andreas Steffen
</pre>
716 21 Andreas Steffen
717 21 Andreas Steffen
<pre>
718 21 Andreas Steffen
01[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
719 21 Andreas Steffen
01[TNC] received TNCCS batch (8 bytes) for Connection ID 1
720 21 Andreas Steffen
01[TNC] PB-TNC state transition from 'Decided' to 'End'
721 21 Andreas Steffen
01[TNC] processing PB-TNC CLOSE batch
722 21 Andreas Steffen
01[TNC] final recommendation is 'isolate' and evaluation is 'non-compliant major'
723 21 Andreas Steffen
01[TNC] policy enforced on peer 'dave' is 'isolate'
724 21 Andreas Steffen
01[TNC] policy enforcement point added group membership 'isolate'
725 21 Andreas Steffen
01[IKE] EAP_TTLS phase2 authentication of 'dave' with EAP_PT_EAP successful
726 21 Andreas Steffen
01[IMV] IMV 1 "OS" deleted the state of Connection ID 1
727 21 Andreas Steffen
01[IMV] IMV 2 "SWID" deleted the state of Connection ID 1
728 21 Andreas Steffen
01[TNC] removed TNCCS Connection ID 1
729 21 Andreas Steffen
01[TLS] sending TLS close notify
730 21 Andreas Steffen
</pre>
731 21 Andreas Steffen
732 22 Andreas Steffen
h2. PT-EAP Connection by Access Requestor "carol" via EAP-RADIUS
733 22 Andreas Steffen
734 21 Andreas Steffen
<pre>
735 21 Andreas Steffen
01[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
736 21 Andreas Steffen
10[CFG] received RADIUS Access-Request from client '10.1.0.1'
737 21 Andreas Steffen
10[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
738 21 Andreas Steffen
10[CFG] sending RADIUS Access-Accept to client '10.1.0.1'
739 21 Andreas Steffen
10[CFG] removed RADIUS connection for user 'dave' NAS 'strongSwan'
740 22 Andreas Steffen
</pre>
741 22 Andreas Steffen
742 22 Andreas Steffen
Set up an EAP-TTLS connection between AR and PDP
743 22 Andreas Steffen
<pre>
744 22 Andreas Steffen
09[CFG] received RADIUS Access-Request from client '10.1.0.1'
745 22 Andreas Steffen
09[CFG] created RADIUS connection for user 'carol' NAS 'strongSwan'
746 22 Andreas Steffen
09[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
747 22 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
748 1 Andreas Steffen
11[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
749 1 Andreas Steffen
11[TLS] negotiated TLS 1.2 using suite TLS_DHE_RSA_WITH_AES_128_CBC_SHA
750 1 Andreas Steffen
11[TLS] sending TLS server certificate 'C=CH, O=Linux strongSwan, CN=aaa.strongswan.org'
751 1 Andreas Steffen
11[TLS] sending TLS cert request for 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'
752 24 Andreas Steffen
</pre>
753 24 Andreas Steffen
754 24 Andreas Steffen
<pre>
755 24 Andreas Steffen
11[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
756 24 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
757 24 Andreas Steffen
04[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
758 24 Andreas Steffen
04[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
759 24 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
760 24 Andreas Steffen
13[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
761 24 Andreas Steffen
13[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/ID]
762 24 Andreas Steffen
13[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
763 24 Andreas Steffen
12[CFG] received RADIUS Access-Request from client '10.1.0.1'
764 24 Andreas Steffen
12[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
765 24 Andreas Steffen
</pre>
766 24 Andreas Steffen
767 24 Andreas Steffen
Received EAP-Identity of AR "carol"
768 24 Andreas Steffen
<pre>
769 24 Andreas Steffen
12[IKE] received tunneled EAP-TTLS AVP [EAP/RES/ID]
770 24 Andreas Steffen
12[IKE] received EAP identity 'carol'
771 24 Andreas Steffen
12[IKE] phase2 method EAP_MD5 selected
772 24 Andreas Steffen
12[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/MD5]
773 24 Andreas Steffen
</pre>
774 24 Andreas Steffen
775 24 Andreas Steffen
<pre>
776 24 Andreas Steffen
12[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
777 24 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
778 24 Andreas Steffen
03[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
779 24 Andreas Steffen
</pre>
780 24 Andreas Steffen
781 24 Andreas Steffen
EAP-MD5 based authentication of AR "carol"
782 24 Andreas Steffen
<pre>
783 24 Andreas Steffen
03[IKE] received tunneled EAP-TTLS AVP [EAP/RES/MD5]
784 24 Andreas Steffen
03[IKE] EAP_TTLS phase2 authentication of 'carol' with EAP_MD5 successful
785 24 Andreas Steffen
03[IKE] phase2 method EAP_PT_EAP selected
786 24 Andreas Steffen
03[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
787 24 Andreas Steffen
</pre>
788 24 Andreas Steffen
789 24 Andreas Steffen
<pre>
790 24 Andreas Steffen
03[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
791 24 Andreas Steffen
Oct  6 20:49:46 alice charon: 14[CFG] received RADIUS Access-Request from client '10.1.0.1'
792 24 Andreas Steffen
Oct  6 20:49:46 alice charon: 14[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
793 13 Andreas Steffen
</pre>
794 25 Andreas Steffen
795 25 Andreas Steffen
h3. Creating IF-TNCCS 2.0 connection with ID 2
796 25 Andreas Steffen
797 25 Andreas Steffen
Upon reception of the first PB-TNC client batch, open an IF-TNCCS 2.0 connection
798 25 Andreas Steffen
<pre>
799 25 Andreas Steffen
14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
800 25 Andreas Steffen
14[TNC] assigned TNCCS Connection ID 2
801 25 Andreas Steffen
14[IMV] IMV 1 "OS" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh
802 25 Andreas Steffen
14[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
803 25 Andreas Steffen
14[IMV]   user AR identity 'carol' authenticated by password
804 25 Andreas Steffen
14[IMV] IMV 2 "SWID" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh
805 25 Andreas Steffen
14[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
806 25 Andreas Steffen
14[IMV]   user AR identity 'carol' authenticated by password
807 25 Andreas Steffen
14[IMV] IMV 1 "OS" changed state of Connection ID 2 to 'Handshake'
808 25 Andreas Steffen
14[IMV] IMV 2 "SWID" changed state of Connection ID 2 to 'Handshake'
809 25 Andreas Steffen
</pre>
810 25 Andreas Steffen
811 25 Andreas Steffen
<pre>
812 25 Andreas Steffen
14[TNC] received TNCCS batch (311 bytes) for Connection ID 2
813 25 Andreas Steffen
14[TNC] PB-TNC state transition from 'Init' to 'Server Working'
814 25 Andreas Steffen
14[TNC] processing PB-TNC CDATA batch
815 25 Andreas Steffen
14[TNC] processing IETF/PB-Language-Preference message (31 bytes)
816 25 Andreas Steffen
14[TNC] processing IETF/PB-PA message (220 bytes)
817 25 Andreas Steffen
14[TNC] processing IETF/PB-PA message (52 bytes)
818 25 Andreas Steffen
14[TNC] setting language preference to 'en'
819 25 Andreas Steffen
</pre>
820 25 Andreas Steffen
821 25 Andreas Steffen
<pre>
822 25 Andreas Steffen
14[TNC] handling PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
823 25 Andreas Steffen
14[IMV] IMV 1 "OS" received message for Connection ID 2 from IMC 1
824 25 Andreas Steffen
14[IMV] => 196 bytes @ 0x7b0410
825 25 Andreas Steffen
14[IMV]    0: 01 00 00 00 7C 05 FC 15 00 00 00 00 00 00 00 02  ....|...........
826 25 Andreas Steffen
14[IMV]   16: 00 00 00 17 00 25 72 00 00 44 65 62 69 61 6E 00  .....%r..Debian.
827 25 Andreas Steffen
14[IMV]   32: 00 00 00 00 00 00 04 00 00 00 19 0A 37 2E 35 20  ............7.5 
828 25 Andreas Steffen
14[IMV]   48: 78 38 36 5F 36 34 00 00 00 00 00 00 00 00 00 03  x86_64..........
829 25 Andreas Steffen
14[IMV]   64: 00 00 00 1C 00 00 00 07 00 00 00 05 00 00 00 00  ................
830 25 Andreas Steffen
14[IMV]   80: 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 24  ...............$
831 25 Andreas Steffen
14[IMV]   96: 03 01 00 00 32 30 31 34 2D 31 30 2D 30 36 54 31  ....2014-10-06T1
832 25 Andreas Steffen
14[IMV]  112: 39 3A 33 31 3A 30 30 5A 00 00 00 00 00 00 00 0B  9:31:00Z........
833 25 Andreas Steffen
14[IMV]  128: 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 0C  ................
834 25 Andreas Steffen
14[IMV]  144: 00 00 00 10 00 00 00 00 00 00 90 2A 00 00 00 08  ...........*....
835 25 Andreas Steffen
14[IMV]  160: 00 00 00 2C 30 36 30 64 63 61 36 66 61 35 36 61  ...,060dca6fa56a
836 25 Andreas Steffen
14[IMV]  176: 34 33 66 34 61 62 32 32 63 61 34 30 35 33 38 37  43f4ab22ca405387
837 25 Andreas Steffen
14[IMV]  192: 32 33 39 65                                      239e
838 25 Andreas Steffen
14[TNC] processing PA-TNC message with ID 0x7c05fc15
839 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002
840 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004
841 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003
842 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005
843 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b
844 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c
845 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008
846 25 Andreas Steffen
</pre>
847 25 Andreas Steffen
848 26 Andreas Steffen
h3. Received Standard IETF Operating System Attributes
849 26 Andreas Steffen
850 25 Andreas Steffen
<pre>
851 25 Andreas Steffen
14[IMV] operating system name is 'Debian' from vendor Debian Project
852 25 Andreas Steffen
14[IMV] operating system version is '7.5 x86_64'
853 25 Andreas Steffen
14[IMV] operating system numeric version is 7.5
854 25 Andreas Steffen
14[IMV] operational status: operational, result: successful
855 25 Andreas Steffen
14[IMV] last boot: Oct 06 19:31:00 UTC 2014
856 25 Andreas Steffen
14[IMV] IPv4 forwarding is disabled
857 25 Andreas Steffen
14[IMV] factory default password is disabled
858 25 Andreas Steffen
14[IMV] device ID is 060dca6fa56a43f4ab22ca405387239e
859 26 Andreas Steffen
</pre>
860 26 Andreas Steffen
861 26 Andreas Steffen
h3. Received Max Attribute Size Request for IF-M Message Type 'TCG/SWID' 
862 26 Andreas Steffen
863 26 Andreas Steffen
<pre>
864 26 Andreas Steffen
14[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
865 26 Andreas Steffen
14[IMV] IMV 2 "SWID" received message for Connection ID 2 from IMC 2
866 26 Andreas Steffen
14[IMV] => 28 bytes @ 0x799eb0
867 26 Andreas Steffen
14[IMV]    0: 01 00 00 00 2C FB F1 DF 00 00 55 97 00 00 00 21  ....,.....U....!
868 26 Andreas Steffen
14[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 3F A6              ..........?.
869 26 Andreas Steffen
14[TNC] processing PA-TNC message with ID 0x2cfbf1df
870 26 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
871 26 Andreas Steffen
14[IMV] received a segmentation contract from IMC 2 for PA message type 'TCG/SWID' 0x005597/0x00000003
872 26 Andreas Steffen
14[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 16294 bytes
873 25 Andreas Steffen
</pre>