Project

General

Profile

Endpoint Compliance via PT-EAP Protocol » History » Version 37

Andreas Steffen, 08.10.2014 15:05

1 1 Andreas Steffen
h1. Endpoint Compliance via PT-EAP Protocol
2 1 Andreas Steffen
3 1 Andreas Steffen
{{>toc}}
4 1 Andreas Steffen
5 1 Andreas Steffen
h2. Starting the strongSwan Policy Decision Point (PDP)
6 1 Andreas Steffen
7 1 Andreas Steffen
The strongSwan PDP starts and loads its server certificate and the client credentials
8 1 Andreas Steffen
<pre>
9 1 Andreas Steffen
00[DMN] Starting IKE charon daemon (strongSwan 5.2.1dr1, Linux 3.16.1, x86_64)
10 1 Andreas Steffen
00[LIB] openssl FIPS mode(0) - disabled 
11 1 Andreas Steffen
00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
12 1 Andreas Steffen
00[CFG]   loaded ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" from '/etc/ipsec.d/cacerts/strongswanCert.pem'
13 1 Andreas Steffen
00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
14 1 Andreas Steffen
00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
15 1 Andreas Steffen
00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
16 1 Andreas Steffen
00[CFG] loading crls from '/etc/ipsec.d/crls'
17 1 Andreas Steffen
00[CFG] loading secrets from '/etc/ipsec.secrets'
18 1 Andreas Steffen
00[CFG]   loaded RSA private key from '/etc/ipsec.d/private/aaaKey.pem'
19 1 Andreas Steffen
00[CFG]   loaded EAP secret for carol
20 1 Andreas Steffen
00[CFG]   loaded EAP secret for dave 
21 1 Andreas Steffen
</pre>
22 1 Andreas Steffen
23 1 Andreas Steffen
Next the OS and SWID IMVs are loaded
24 1 Andreas Steffen
<pre>
25 1 Andreas Steffen
00[TNC] TNC recommendation policy is 'default'
26 1 Andreas Steffen
00[TNC] loading IMVs from '/etc/tnc_config'
27 1 Andreas Steffen
00[TNC] added IETF attributes
28 1 Andreas Steffen
00[TNC] added ITA-HSR attributes
29 1 Andreas Steffen
00[TNC] added TCG attributes
30 1 Andreas Steffen
00[LIB] libimcv initialized
31 1 Andreas Steffen
00[IMV] IMV 1 "OS" initialized
32 1 Andreas Steffen
00[TNC] IMV 1 supports 1 message type: 'IETF/Operating System' 0x000000/0x00000001
33 1 Andreas Steffen
00[TNC] IMV 1 "OS" loaded from '/usr/local/lib/ipsec/imcvs/imv-os.so'
34 1 Andreas Steffen
00[IMV] IMV 2 "SWID" initialized
35 1 Andreas Steffen
00[TNC] IMV 2 supports 1 message type: 'TCG/SWID' 0x005597/0x00000003
36 1 Andreas Steffen
O00[TNC] IMV 2 "SWID" loaded from '/usr/local/lib/ipsec/imcvs/imv-swid.so'
37 1 Andreas Steffen
</pre>
38 1 Andreas Steffen
39 1 Andreas Steffen
The PDP loads all plugins needed to communicate via its EAP-RADIUS and PT-TLS interfaces and spawns 16 worker threads
40 1 Andreas Steffen
<pre>
41 1 Andreas Steffen
00[IKE] eap method EAP_TTLS selected
42 1 Andreas Steffen
00[LIB] loaded plugins: charon aes des sha1 sha2 md5 pem pkcs1 gmp random nonce x509 curl revocation hmac socket-default kernel-netlink stroke eap-identity eap-ttls eap-md5 eap-tnc tnc-pdp tnc-imv tnc-tnccs tnccs-20 sqlite
43 1 Andreas Steffen
00[JOB] spawning 16 worker threads
44 1 Andreas Steffen
09[CFG] received stroke: add connection 'aaa'
45 1 Andreas Steffen
09[CFG] left nor right host is our side, assuming left=local
46 1 Andreas Steffen
09[CFG]   loaded certificate "C=CH, O=Linux strongSwan, CN=aaa.strongswan.org" from 'aaaCert.pem'
47 1 Andreas Steffen
09[CFG] added configuration 'aaa'
48 1 Andreas Steffen
</pre>
49 1 Andreas Steffen
50 17 Andreas Steffen
h2. PT-EAP Connection by Access Requestor "dave" via EAP-RADIUS
51 1 Andreas Steffen
52 1 Andreas Steffen
<pre>
53 1 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
54 1 Andreas Steffen
04[CFG] created RADIUS connection for user 'dave' NAS 'strongSwan'
55 1 Andreas Steffen
04[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
56 1 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
57 2 Andreas Steffen
11[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
58 1 Andreas Steffen
</pre>
59 1 Andreas Steffen
60 3 Andreas Steffen
Set up an EAP-TTLS connection between AR and PDP
61 1 Andreas Steffen
<pre>
62 1 Andreas Steffen
11[TLS] negotiated TLS 1.2 using suite TLS_DHE_RSA_WITH_AES_128_CBC_SHA
63 1 Andreas Steffen
11[TLS] sending TLS server certificate 'C=CH, O=Linux strongSwan, CN=aaa.strongswan.org'
64 1 Andreas Steffen
11[TLS] sending TLS cert request for 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'
65 4 Andreas Steffen
</pre>
66 2 Andreas Steffen
67 2 Andreas Steffen
<pre>
68 2 Andreas Steffen
11[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
69 2 Andreas Steffen
12[CFG] received RADIUS Access-Request from client '10.1.0.1'
70 2 Andreas Steffen
12[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
71 2 Andreas Steffen
12[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
72 2 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
73 2 Andreas Steffen
13[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
74 2 Andreas Steffen
13[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/ID]
75 2 Andreas Steffen
13[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
76 2 Andreas Steffen
14[CFG] received RADIUS Access-Request from client '10.1.0.1'
77 2 Andreas Steffen
14[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
78 1 Andreas Steffen
</pre>
79 2 Andreas Steffen
80 5 Andreas Steffen
Received EAP-Identity of AR "dave"
81 2 Andreas Steffen
<pre>
82 2 Andreas Steffen
14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/ID]
83 2 Andreas Steffen
14[IKE] received EAP identity 'dave'
84 2 Andreas Steffen
14[IKE] phase2 method EAP_MD5 selected
85 2 Andreas Steffen
14[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/MD5]
86 2 Andreas Steffen
</pre>
87 2 Andreas Steffen
88 2 Andreas Steffen
<pre>
89 2 Andreas Steffen
14[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
90 2 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
91 2 Andreas Steffen
03[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
92 1 Andreas Steffen
</pre>
93 2 Andreas Steffen
94 5 Andreas Steffen
EAP-MD5 based authentication of AR "dave"
95 2 Andreas Steffen
<pre>
96 2 Andreas Steffen
03[IKE] received tunneled EAP-TTLS AVP [EAP/RES/MD5]
97 2 Andreas Steffen
03[IKE] EAP_TTLS phase2 authentication of 'dave' with EAP_MD5 successful
98 2 Andreas Steffen
03[IKE] phase2 method EAP_PT_EAP selected
99 2 Andreas Steffen
03[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
100 2 Andreas Steffen
</pre>
101 2 Andreas Steffen
102 2 Andreas Steffen
<pre>
103 2 Andreas Steffen
03[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
104 2 Andreas Steffen
15[CFG] received RADIUS Access-Request from client '10.1.0.1'
105 1 Andreas Steffen
15[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
106 1 Andreas Steffen
</pre>
107 1 Andreas Steffen
108 17 Andreas Steffen
h3. Creating IF-TNCCS 2.0 connection with ID 1
109 16 Andreas Steffen
110 4 Andreas Steffen
Upon reception of the first PB-TNC client batch, open an IF-TNCCS 2.0 connection
111 3 Andreas Steffen
<pre>
112 3 Andreas Steffen
15[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
113 3 Andreas Steffen
15[IMV] IMV 1 "OS" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh
114 3 Andreas Steffen
15[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
115 3 Andreas Steffen
15[IMV]   user AR identity 'dave' authenticated by password
116 3 Andreas Steffen
15[IMV] IMV 2 "SWID" created a state for IF-TNCCS 2.0 Connection ID 1: +long +excl -soh
117 3 Andreas Steffen
15[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
118 3 Andreas Steffen
15[IMV]   user AR identity 'dave' authenticated by password
119 3 Andreas Steffen
15[IMV] IMV 1 "OS" changed state of Connection ID 1 to 'Handshake'
120 3 Andreas Steffen
15[IMV] IMV 2 "SWID" changed state of Connection ID 1 to 'Handshake'
121 3 Andreas Steffen
</pre>
122 3 Andreas Steffen
123 3 Andreas Steffen
<pre>
124 3 Andreas Steffen
15[TNC] received TNCCS batch (91 bytes) for Connection ID 1
125 3 Andreas Steffen
15[TNC] PB-TNC state transition from 'Init' to 'Server Working'
126 3 Andreas Steffen
15[TNC] processing PB-TNC CDATA batch
127 3 Andreas Steffen
15[TNC] processing IETF/PB-PA message (52 bytes)
128 3 Andreas Steffen
15[TNC] setting language preference to 'en'
129 3 Andreas Steffen
</pre>
130 1 Andreas Steffen
131 18 Andreas Steffen
h3. Received Max Attribute Size Request for IF-M Message Type 'TCG/SWID' 
132 15 Andreas Steffen
133 3 Andreas Steffen
<pre>
134 3 Andreas Steffen
15[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
135 3 Andreas Steffen
15[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2
136 3 Andreas Steffen
15[IMV] => 28 bytes @ 0x7a5490
137 3 Andreas Steffen
15[IMV]    0: 01 00 00 00 26 4B C3 0A 00 00 55 97 00 00 00 21  ....&K....U....!
138 3 Andreas Steffen
15[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6              ............
139 3 Andreas Steffen
15[TNC] processing PA-TNC message with ID 0x264bc30a
140 3 Andreas Steffen
15[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
141 3 Andreas Steffen
15[IMV] received a segmentation contract from IMC 2 for PA message type 'TCG/SWID' 0x005597/0x00000003
142 1 Andreas Steffen
15[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 32678 bytes
143 1 Andreas Steffen
</pre>
144 1 Andreas Steffen
145 18 Andreas Steffen
h3. Sending Max Attribute Size Response for IF-M Message Type 'TCG/SWID'
146 15 Andreas Steffen
147 3 Andreas Steffen
<pre>
148 3 Andreas Steffen
15[TNC] creating PA-TNC message with ID 0x45425ec5
149 3 Andreas Steffen
15[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
150 3 Andreas Steffen
15[IMV] created PA-TNC message: => 28 bytes @ 0x7a5b00
151 1 Andreas Steffen
15[IMV]    0: 01 00 00 00 45 42 5E C5 00 00 55 97 00 00 00 22  ....EB^...U...."
152 1 Andreas Steffen
15[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6              ............
153 1 Andreas Steffen
15[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
154 1 Andreas Steffen
</pre>
155 1 Andreas Steffen
156 18 Andreas Steffen
h3. Sending Max Attribute Size Request for IF-M Message Type 'IETF Operating Systen'
157 17 Andreas Steffen
158 5 Andreas Steffen
<pre>
159 1 Andreas Steffen
15[IMV] IMV 1 requests a segmentation contract for PA message type 'IETF/Operating System' 0x000000/0x00000001
160 5 Andreas Steffen
15[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 65446 bytes
161 5 Andreas Steffen
15[TNC] creating PA-TNC message with ID 0x2ae6641f
162 5 Andreas Steffen
15[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
163 5 Andreas Steffen
15[TNC] creating PA-TNC attribute type 'IETF/Attribute Request' 0x000000/0x00000001
164 5 Andreas Steffen
15[IMV] created PA-TNC message: => 96 bytes @ 0x7a7ff0
165 5 Andreas Steffen
15[IMV]    0: 01 00 00 00 2A E6 64 1F 00 00 55 97 00 00 00 21  ....*.d...U....!
166 5 Andreas Steffen
15[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 FF A6 00 00 00 00  ................
167 5 Andreas Steffen
15[IMV]   32: 00 00 00 01 00 00 00 44 00 00 00 00 00 00 00 02  .......D........
168 5 Andreas Steffen
15[IMV]   48: 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 03  ................
169 1 Andreas Steffen
15[IMV]   64: 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 0B  ................
170 5 Andreas Steffen
15[IMV]   80: 00 00 00 00 00 00 00 0C 00 00 90 2A 00 00 00 08  ...........*....
171 1 Andreas Steffen
15[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
172 6 Andreas Steffen
</pre>
173 1 Andreas Steffen
174 7 Andreas Steffen
After appending an Attribute Request for various standard IETF attributes to this PA-TNC message, a first PB-TNC server batch is sent to the TNC client running on the AR
175 6 Andreas Steffen
<pre>
176 6 Andreas Steffen
15[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
177 6 Andreas Steffen
15[TNC] creating PB-TNC SDATA batch
178 6 Andreas Steffen
15[TNC] adding TCG/PB-PDP-Referral message
179 6 Andreas Steffen
15[TNC] adding IETF/PB-PA message
180 6 Andreas Steffen
15[TNC] adding IETF/PB-PA message
181 6 Andreas Steffen
15[TNC] sending PB-TNC SDATA batch (222 bytes) for Connection ID 1
182 6 Andreas Steffen
15[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
183 6 Andreas Steffen
</pre>
184 6 Andreas Steffen
185 1 Andreas Steffen
<pre>
186 1 Andreas Steffen
15[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
187 1 Andreas Steffen
16[CFG] received RADIUS Access-Request from client '10.1.0.1'
188 1 Andreas Steffen
16[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
189 7 Andreas Steffen
</pre>
190 7 Andreas Steffen
191 7 Andreas Steffen
<pre>
192 7 Andreas Steffen
16[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
193 7 Andreas Steffen
16[TNC] received TNCCS batch (248 bytes) for Connection ID 1
194 7 Andreas Steffen
16[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
195 7 Andreas Steffen
16[TNC] processing PB-TNC CDATA batch
196 7 Andreas Steffen
16[TNC] processing IETF/PB-PA message (240 bytes)
197 7 Andreas Steffen
</pre>
198 7 Andreas Steffen
199 7 Andreas Steffen
<pre>
200 7 Andreas Steffen
16[TNC] handling PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
201 7 Andreas Steffen
16[IMV] IMV 1 "OS" received message for Connection ID 1 from IMC 1 to IMV 1
202 7 Andreas Steffen
16[IMV] => 216 bytes @ 0x7a45b0
203 7 Andreas Steffen
16[IMV]    0: 01 00 00 00 FD DE 12 F4 00 00 55 97 00 00 00 22  ..........U...."
204 7 Andreas Steffen
16[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6 00 00 00 00  ................
205 7 Andreas Steffen
16[IMV]   32: 00 00 00 02 00 00 00 17 00 25 72 00 00 44 65 62  .........%r..Deb
206 7 Andreas Steffen
16[IMV]   48: 69 61 6E 00 00 00 00 00 00 00 04 00 00 00 19 0A  ian.............
207 7 Andreas Steffen
16[IMV]   64: 37 2E 35 20 78 38 36 5F 36 34 00 00 00 00 00 00  7.5 x86_64......
208 7 Andreas Steffen
16[IMV]   80: 00 00 00 03 00 00 00 1C 00 00 00 07 00 00 00 05  ................
209 7 Andreas Steffen
16[IMV]   96: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05  ................
210 7 Andreas Steffen
16[IMV]  112: 00 00 00 24 03 01 00 00 32 30 31 34 2D 31 30 2D  ...$....2014-10-
211 7 Andreas Steffen
16[IMV]  128: 30 36 54 31 39 3A 33 31 3A 30 30 5A 00 00 00 00  06T19:31:00Z....
212 7 Andreas Steffen
16[IMV]  144: 00 00 00 0B 00 00 00 10 00 00 00 01 00 00 00 00  ................
213 7 Andreas Steffen
16[IMV]  160: 00 00 00 0C 00 00 00 10 00 00 00 00 00 00 90 2A  ...............*
214 7 Andreas Steffen
16[IMV]  176: 00 00 00 08 00 00 00 2C 61 61 62 62 63 63 64 64  .......,aabbccdd
215 7 Andreas Steffen
16[IMV]  192: 65 65 66 66 31 31 32 32 33 33 34 34 35 35 36 36  eeff112233445566
216 7 Andreas Steffen
16[IMV]  208: 37 37 38 38 39 39 30 30                          77889900
217 7 Andreas Steffen
16[TNC] processing PA-TNC message with ID 0xfdde12f4
218 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
219 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002
220 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004
221 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003
222 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005
223 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b
224 7 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c
225 1 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008
226 1 Andreas Steffen
</pre>
227 7 Andreas Steffen
228 18 Andreas Steffen
h3. Received Max Attribute Size Response for IF-M Message Type 'IETF/Operating System' 
229 15 Andreas Steffen
230 7 Andreas Steffen
<pre>
231 7 Andreas Steffen
16[IMV] received a segmentation contract response for PA message type 'IETF/Operating System' 0x000000/0x00000001
232 7 Andreas Steffen
16[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 32678 bytes
233 7 Andreas Steffen
</pre>
234 7 Andreas Steffen
235 27 Andreas Steffen
h3. Received Standard 'IETF/Operating System' Attributes
236 26 Andreas Steffen
237 7 Andreas Steffen
<pre>
238 7 Andreas Steffen
16[IMV] operating system name is 'Debian' from vendor Debian Project
239 7 Andreas Steffen
16[IMV] operating system version is '7.5 x86_64'
240 7 Andreas Steffen
16[IMV] operating system numeric version is 7.5
241 7 Andreas Steffen
16[IMV] operational status: operational, result: successful
242 7 Andreas Steffen
16[IMV] last boot: Oct 06 19:31:00 UTC 2014
243 7 Andreas Steffen
16[IMV] IPv4 forwarding is enabled
244 7 Andreas Steffen
16[IMV] factory default password is disabled
245 7 Andreas Steffen
16[IMV] device ID is aabbccddeeff11223344556677889900
246 6 Andreas Steffen
</pre>
247 1 Andreas Steffen
248 27 Andreas Steffen
h3. Assign Session ID 2 to Connection with ID 1 and apply TNC Policy
249 27 Andreas Steffen
250 8 Andreas Steffen
<pre>
251 8 Andreas Steffen
16[IMV] assigned session ID 2 to Connection ID 1
252 8 Andreas Steffen
16[IMV] running policy script: 2>&1 ipsec imv_policy_manager start 2
253 8 Andreas Steffen
16[IMV] policy: imv_policy_manager start successful
254 8 Andreas Steffen
16[IMV] DREFM workitem 1
255 8 Andreas Steffen
16[IMV] FWDEN workitem 2
256 8 Andreas Steffen
16[IMV] SWIDT workitem 3
257 8 Andreas Steffen
</pre>
258 8 Andreas Steffen
259 8 Andreas Steffen
<pre>
260 8 Andreas Steffen
16[IMV] IMV 1 handles FWDEN workitem 2
261 8 Andreas Steffen
16[IMV] IMV 1 handled FWDEN workitem 2: isolate - forwarding enabled
262 8 Andreas Steffen
16[TNC] creating PA-TNC message with ID 0x3fb2eb38
263 8 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
264 8 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'IETF/Remediation Instructions' 0x000000/0x0000000a
265 8 Andreas Steffen
16[IMV] created PA-TNC message: => 117 bytes @ 0x7ab630
266 8 Andreas Steffen
16[IMV]    0: 01 00 00 00 3F B2 EB 38 00 00 00 00 00 00 00 09  ....?..8........
267 8 Andreas Steffen
16[IMV]   16: 00 00 00 10 00 00 00 02 00 00 00 00 00 00 00 0A  ................
268 8 Andreas Steffen
16[IMV]   32: 00 00 00 5D 00 00 00 00 00 00 00 02 00 00 00 42  ...]...........B
269 8 Andreas Steffen
16[IMV]   48: 49 50 20 50 61 63 6B 65 74 20 46 6F 72 77 61 72  IP Packet Forwar
270 8 Andreas Steffen
16[IMV]   64: 64 69 6E 67 0A 20 20 50 6C 65 61 73 65 20 64 69  ding.  Please di
271 8 Andreas Steffen
16[IMV]   80: 73 61 62 6C 65 20 74 68 65 20 66 6F 72 77 61 72  sable the forwar
272 8 Andreas Steffen
16[IMV]   96: 64 69 6E 67 20 6F 66 20 49 50 20 70 61 63 6B 65  ding of IP packe
273 8 Andreas Steffen
16[IMV]  112: 74 73 02 65 6E                                   ts.en
274 8 Andreas Steffen
16[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
275 8 Andreas Steffen
16[TNC] IMV 1 is setting reason string to 'Improper OS settings were detected'
276 8 Andreas Steffen
16[TNC] IMV 1 is setting reason language to 'en'
277 1 Andreas Steffen
16[TNC] IMV 1 provides recommendation 'isolate' and evaluation 'non-compliant major'
278 1 Andreas Steffen
</pre>
279 1 Andreas Steffen
280 18 Andreas Steffen
h3. Sending Max Attribute Size Request for IF-M message type 'TCG/SWID'
281 15 Andreas Steffen
282 9 Andreas Steffen
<pre>
283 9 Andreas Steffen
16[IMV] IMV 2 requests a segmentation contract for PA message type 'TCG/SWID' 0x005597/0x00000003
284 9 Andreas Steffen
16[IMV]   maximum attribute size of 100000000 bytes with maximum segment size of 65446 bytes
285 9 Andreas Steffen
</pre>
286 9 Andreas Steffen
287 34 Andreas Steffen
h3. Sending SWID Request for a Complete Tag Inventory
288 34 Andreas Steffen
289 9 Andreas Steffen
<pre>
290 9 Andreas Steffen
16[IMV] IMV 2 handles SWIDT workitem 3
291 9 Andreas Steffen
16[IMV] IMV 2 issues SWID request 3
292 9 Andreas Steffen
</pre>
293 9 Andreas Steffen
294 9 Andreas Steffen
<pre>
295 9 Andreas Steffen
16[TNC] creating PA-TNC message with ID 0x8fc76ae4
296 9 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
297 9 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'TCG/SWID Request' 0x005597/0x00000011
298 9 Andreas Steffen
16[IMV] created PA-TNC message: => 52 bytes @ 0x7eaaa0
299 9 Andreas Steffen
16[IMV]    0: 01 00 00 00 8F C7 6A E4 00 00 55 97 00 00 00 21  ......j...U....!
300 9 Andreas Steffen
16[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 FF A6 00 00 55 97  ..............U.
301 9 Andreas Steffen
16[IMV]   32: 00 00 00 11 00 00 00 18 00 00 00 00 00 00 00 03  ................
302 9 Andreas Steffen
16[IMV]   48: 00 00 00 00                                      ....
303 9 Andreas Steffen
16[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
304 9 Andreas Steffen
</pre>
305 9 Andreas Steffen
306 9 Andreas Steffen
<pre>
307 9 Andreas Steffen
16[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
308 9 Andreas Steffen
16[TNC] creating PB-TNC SDATA batch
309 9 Andreas Steffen
16[TNC] adding IETF/PB-PA message
310 9 Andreas Steffen
16[TNC] adding IETF/PB-PA message
311 9 Andreas Steffen
16[TNC] sending PB-TNC SDATA batch (225 bytes) for Connection ID 1
312 9 Andreas Steffen
16[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
313 8 Andreas Steffen
</pre>
314 10 Andreas Steffen
315 10 Andreas Steffen
<pre>
316 10 Andreas Steffen
16[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
317 10 Andreas Steffen
02[CFG] received RADIUS Access-Request from client '10.1.0.1'
318 10 Andreas Steffen
02[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
319 10 Andreas Steffen
02[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
320 10 Andreas Steffen
01[CFG] received RADIUS Access-Request from client '10.1.0.1'
321 10 Andreas Steffen
01[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
322 10 Andreas Steffen
01[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
323 10 Andreas Steffen
        ... 30 more RADIUS exchanges
324 10 Andreas Steffen
14[CFG] received RADIUS Access-Request from client '10.1.0.1'
325 10 Andreas Steffen
14[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
326 10 Andreas Steffen
</pre>
327 10 Andreas Steffen
328 10 Andreas Steffen
<pre>
329 10 Andreas Steffen
14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
330 10 Andreas Steffen
14[TNC] received TNCCS batch (32754 bytes) for Connection ID 1
331 10 Andreas Steffen
14[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
332 10 Andreas Steffen
14[TNC] processing PB-TNC CDATA batch
333 10 Andreas Steffen
14[TNC] processing IETF/PB-PA message (32746 bytes)
334 10 Andreas Steffen
</pre>
335 10 Andreas Steffen
336 10 Andreas Steffen
<pre>
337 10 Andreas Steffen
14[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
338 10 Andreas Steffen
14[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
339 10 Andreas Steffen
14[IMV] => 32722 bytes @ 0x81f620
340 10 Andreas Steffen
14[IMV]    0: 01 00 00 00 C6 E7 09 AA 00 00 55 97 00 00 00 22  ..........U...."
341 10 Andreas Steffen
14[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 7F A6 00 00 55 97  ..............U.
342 10 Andreas Steffen
14[IMV]   32: 00 00 00 23 00 00 7F B6 C0 00 00 01 00 00 55 97  ...#..........U.
343 10 Andreas Steffen
14[IMV]   48: 00 00 00 14 00 01 C4 84 00 00 01 74 00 00 00 03  ...........t....
344 10 Andreas Steffen
14[IMV]   64: F1 07 0C 90 00 00 00 01 00 00 00 00 01 35 3C 53  .............5<S
345 10 Andreas Steffen
14[IMV]   80: 6F 66 74 77 61 72 65 49 64 65 6E 74 69 74 79 20  oftwareIdentity 
346 10 Andreas Steffen
14[IMV]   96: 6E 61 6D 65 3D 22 61 63 70 69 2D 73 75 70 70 6F  name="acpi-suppo
347 10 Andreas Steffen
14[IMV]  112: 72 74 2D 62 61 73 65 22 20 75 6E 69 71 75 65 49  rt-base" uniqueI
348 10 Andreas Steffen
14[IMV]  128: 64 3D 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38  d="debian_7.5-x8
349 10 Andreas Steffen
14[IMV]  144: 36 5F 36 34 2D 61 63 70 69 2D 73 75 70 70 6F 72  6_64-acpi-suppor
350 10 Andreas Steffen
14[IMV]  160: 74 2D 62 61 73 65 2D 30 2E 31 34 30 2D 35 22 20  t-base-0.140-5" 
351 10 Andreas Steffen
14[IMV]  176: 76 65 72 73 69 6F 6E 3D 22 30 2E 31 34 30 2D 35  version="0.140-5
352 10 Andreas Steffen
14[IMV]  192: 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D 65 3D  " versionScheme=
353 10 Andreas Steffen
14[IMV]  208: 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22 20 78  "alphanumeric" x
354 10 Andreas Steffen
14[IMV]  224: 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F 2F 73 74 61  mlns="http://sta
355 10 Andreas Steffen
14[IMV]  240: 6E 64 61 72 64 73 2E 69 73 6F 2E 6F 72 67 2F 69  ndards.iso.org/i
356 10 Andreas Steffen
14[IMV]  256: 73 6F 2F 31 39 37 37 30 2F 2D 32 2F 32 30 31 34  so/19770/-2/2014
357 10 Andreas Steffen
14[IMV]  272: 2F 73 63 68 65 6D 61 2E 78 73 64 22 3E 3C 45 6E  /schema.xsd"><En
358 10 Andreas Steffen
14[IMV]  288: 74 69 74 79 20 6E 61 6D 65 3D 22 73 74 72 6F 6E  tity name="stron
359 10 Andreas Steffen
14[IMV]  304: 67 53 77 61 6E 22 20 72 65 67 69 64 3D 22 72 65  gSwan" regid="re
360 10 Andreas Steffen
14[IMV]  320: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
361 10 Andreas Steffen
14[IMV]  336: 73 74 72 6F 6E 67 73 77 61 6E 22 20 72 6F 6C 65  strongswan" role
362 10 Andreas Steffen
14[IMV]  352: 3D 22 74 61 67 63 72 65 61 74 6F 72 22 20 2F 3E  ="tagcreator" />
363 10 Andreas Steffen
14[IMV]  368: 3C 2F 53 6F 66 74 77 61 72 65 49 64 65 6E 74 69  </SoftwareIdenti
364 10 Andreas Steffen
14[IMV]  384: 74 79 3E 00 00 00 00 01 31 3C 53 6F 66 74 77 61  ty>.....1<Softwa
365 10 Andreas Steffen
14[IMV]  400: 72 65 49 64 65 6E 74 69 74 79 20 6E 61 6D 65 3D  reIdentity name=
366 10 Andreas Steffen
14[IMV]  416: 22 61 63 70 69 64 22 20 75 6E 69 71 75 65 49 64  "acpid" uniqueId
367 10 Andreas Steffen
         ...
368 10 Andreas Steffen
14[IMV] 32624: 20 2F 3E 3C 2F 53 6F 66 74 77 61 72 65 49 64 65   /></SoftwareIde
369 10 Andreas Steffen
14[IMV] 32640: 6E 74 69 74 79 3E 00 00 00 00 01 2F 3C 53 6F 66  ntity>...../<Sof
370 10 Andreas Steffen
14[IMV] 32656: 74 77 61 72 65 49 64 65 6E 74 69 74 79 20 6E 61  twareIdentity na
371 10 Andreas Steffen
14[IMV] 32672: 6D 65 3D 22 6C 69 62 61 70 72 31 22 20 75 6E 69  me="libapr1" uni
372 10 Andreas Steffen
14[IMV] 32688: 71 75 65 49 64 3D 22 64 65 62 69 61 6E 5F 37 2E  queId="debian_7.
373 10 Andreas Steffen
14[IMV] 32704: 35 2D 78 38 36 5F 36 34 2D 6C 69 62 61 70 72 31  5-x86_64-libapr1
374 10 Andreas Steffen
14[IMV] 32720: 2D 31                                            -1
375 10 Andreas Steffen
14[TNC] processing PA-TNC message with ID 0xc6e709aa
376 1 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
377 10 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
378 10 Andreas Steffen
</pre>
379 10 Andreas Steffen
380 18 Andreas Steffen
h3. Received Max Attribute Size Response for IF-M Message Type 'TCG/SWID ' 
381 14 Andreas Steffen
382 1 Andreas Steffen
<pre>
383 1 Andreas Steffen
14[IMV] received a segmentation contract response for PA message type 'TCG/SWID' 0x005597/0x00000003
384 1 Andreas Steffen
14[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 32678 bytes
385 10 Andreas Steffen
</pre>
386 10 Andreas Steffen
387 24 Andreas Steffen
h3. Received First Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
388 15 Andreas Steffen
389 10 Andreas Steffen
<pre>
390 10 Andreas Steffen
14[TNC] received first segment for base attribute ID 1 (32678 bytes)
391 10 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/SWID Tag Inventory' 0x005597/0x00000014
392 10 Andreas Steffen
14[LIB] 70 bytes insufficient to parse 303 bytes of data
393 1 Andreas Steffen
14[IMV] received SWID tag inventory with 106 items for request 3 at eid 1 of epoch 0xf1070c90, 266 items to follow
394 1 Andreas Steffen
14[IMV] <SoftwareIdentity name="acpi-support-base" uniqueId="debian_7.5-x86_64-acpi-support-base-0.140-5" version="0.140-5" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
395 10 Andreas Steffen
14[IMV] <SoftwareIdentity name="acpid" uniqueId="debian_7.5-x86_64-acpid-1:2.0.16-1+deb7u1" version="1:2.0.16-1+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
396 33 Andreas Steffen
        ... 103 more SWID Tags
397 10 Andreas Steffen
14[IMV] <SoftwareIdentity name="libapache2-mod-wsgi" uniqueId="debian_7.5-x86_64-libapache2-mod-wsgi-3.3-4" version="3.3-4" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
398 12 Andreas Steffen
</pre>
399 18 Andreas Steffen
400 18 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
401 12 Andreas Steffen
402 12 Andreas Steffen
<pre>
403 12 Andreas Steffen
14[TNC] creating PA-TNC message with ID 0x636ebdaa
404 12 Andreas Steffen
14[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
405 12 Andreas Steffen
14[IMV] created PA-TNC message: => 24 bytes @ 0x7b2e10
406 12 Andreas Steffen
14[IMV]    0: 01 00 00 00 63 6E BD AA 00 00 55 97 00 00 00 24  ....cn....U....$
407 12 Andreas Steffen
14[IMV]   16: 00 00 00 10 00 00 00 01                          ........
408 12 Andreas Steffen
14[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
409 12 Andreas Steffen
</pre>
410 12 Andreas Steffen
411 12 Andreas Steffen
<pre>
412 12 Andreas Steffen
14[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
413 12 Andreas Steffen
14[TNC] creating PB-TNC SDATA batch
414 12 Andreas Steffen
14[TNC] adding IETF/PB-PA message
415 12 Andreas Steffen
14[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 1
416 12 Andreas Steffen
14[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
417 10 Andreas Steffen
</pre>
418 13 Andreas Steffen
419 13 Andreas Steffen
<pre>
420 13 Andreas Steffen
14[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
421 13 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
422 13 Andreas Steffen
03[CFG] ignoring RADIUS Access-Request 0x3f, already processing
423 13 Andreas Steffen
15[CFG] received RADIUS Access-Request from client '10.1.0.1'
424 13 Andreas Steffen
15[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
425 1 Andreas Steffen
15[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
426 14 Andreas Steffen
         ... 31 more RADIUS exchanges
427 13 Andreas Steffen
12[CFG] received RADIUS Access-Request from client '10.1.0.1'
428 13 Andreas Steffen
12[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
429 13 Andreas Steffen
</pre>
430 13 Andreas Steffen
431 13 Andreas Steffen
<pre>
432 13 Andreas Steffen
12[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
433 13 Andreas Steffen
12[TNC] received TNCCS batch (32734 bytes) for Connection ID 1
434 13 Andreas Steffen
12[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
435 13 Andreas Steffen
12[TNC] processing PB-TNC CDATA batch
436 1 Andreas Steffen
12[TNC] processing IETF/PB-PA message (32726 bytes)
437 14 Andreas Steffen
</pre>
438 14 Andreas Steffen
439 14 Andreas Steffen
<pre>
440 14 Andreas Steffen
12[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
441 14 Andreas Steffen
12[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
442 14 Andreas Steffen
12[IMV] => 32702 bytes @ 0x80b530
443 14 Andreas Steffen
12[IMV]    0: 01 00 00 00 A7 75 C2 64 00 00 55 97 00 00 00 23  .....u.d..U....#
444 14 Andreas Steffen
12[IMV]   16: 00 00 7F B6 80 00 00 01 2E 34 2E 36 2D 33 2B 64  .........4.6-3+d
445 14 Andreas Steffen
12[IMV]   32: 65 62 37 75 31 22 20 76 65 72 73 69 6F 6E 3D 22  eb7u1" version="
446 14 Andreas Steffen
12[IMV]   48: 31 2E 34 2E 36 2D 33 2B 64 65 62 37 75 31 22 20  1.4.6-3+deb7u1" 
447 14 Andreas Steffen
12[IMV]   64: 76 65 72 73 69 6F 6E 53 63 68 65 6D 65 3D 22 61  versionScheme="a
448 14 Andreas Steffen
12[IMV]   80: 6C 70 68 61 6E 75 6D 65 72 69 63 22 20 78 6D 6C  lphanumeric" xml
449 14 Andreas Steffen
12[IMV]   96: 6E 73 3D 22 68 74 74 70 3A 2F 2F 73 74 61 6E 64  ns="http://stand
450 14 Andreas Steffen
12[IMV]  112: 61 72 64 73 2E 69 73 6F 2E 6F 72 67 2F 69 73 6F  ards.iso.org/iso
451 14 Andreas Steffen
12[IMV]  128: 2F 31 39 37 37 30 2F 2D 32 2F 32 30 31 34 2F 73  /19770/-2/2014/s
452 14 Andreas Steffen
12[IMV]  144: 63 68 65 6D 61 2E 78 73 64 22 3E 3C 45 6E 74 69  chema.xsd"><Enti
453 14 Andreas Steffen
12[IMV]  160: 74 79 20 6E 61 6D 65 3D 22 73 74 72 6F 6E 67 53  ty name="strongS
454 14 Andreas Steffen
12[IMV]  176: 77 61 6E 22 20 72 65 67 69 64 3D 22 72 65 67 69  wan" regid="regi
455 14 Andreas Steffen
12[IMV]  192: 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E 73 74  d.2004-03.org.st
456 14 Andreas Steffen
12[IMV]  208: 72 6F 6E 67 73 77 61 6E 22 20 72 6F 6C 65 3D 22  rongswan" role="
457 14 Andreas Steffen
12[IMV]  224: 74 61 67 63 72 65 61 74 6F 72 22 20 2F 3E 3C 2F  tagcreator" /></
458 14 Andreas Steffen
12[IMV]  240: 53 6F 66 74 77 61 72 65 49 64 65 6E 74 69 74 79  SoftwareIdentity
459 14 Andreas Steffen
12[IMV]  256: 3E 00 00 00 00 01 37 3C 53 6F 66 74 77 61 72 65  >.....7<Software
460 14 Andreas Steffen
12[IMV]  272: 49 64 65 6E 74 69 74 79 20 6E 61 6D 65 3D 22 6C  Identity name="l
461 14 Andreas Steffen
12[IMV]  288: 69 62 61 70 72 31 2D 64 65 76 22 20 75 6E 69 71  ibapr1-dev" uniq
462 14 Andreas Steffen
         ...
463 14 Andreas Steffen
12[IMV] 32416: 01 31 3C 53 6F 66 74 77 61 72 65 49 64 65 6E 74  .1<SoftwareIdent
464 14 Andreas Steffen
12[IMV] 32432: 69 74 79 20 6E 61 6D 65 3D 22 6C 69 62 6C 6F 67  ity name="liblog
465 14 Andreas Steffen
12[IMV] 32448: 34 63 78 78 31 30 22 20 75 6E 69 71 75 65 49 64  4cxx10" uniqueId
466 14 Andreas Steffen
12[IMV] 32464: 3D 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36  ="debian_7.5-x86
467 14 Andreas Steffen
12[IMV] 32480: 5F 36 34 2D 6C 69 62 6C 6F 67 34 63 78 78 31 30  _64-liblog4cxx10
468 14 Andreas Steffen
12[IMV] 32496: 2D 30 2E 31 30 2E 30 2D 31 2E 32 22 20 76 65 72  -0.10.0-1.2" ver
469 14 Andreas Steffen
12[IMV] 32512: 73 69 6F 6E 3D 22 30 2E 31 30 2E 30 2D 31 2E 32  sion="0.10.0-1.2
470 14 Andreas Steffen
12[IMV] 32528: 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D 65 3D  " versionScheme=
471 14 Andreas Steffen
12[IMV] 32544: 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22 20 78  "alphanumeric" x
472 14 Andreas Steffen
12[IMV] 32560: 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F 2F 73 74 61  mlns="http://sta
473 14 Andreas Steffen
12[IMV] 32576: 6E 64 61 72 64 73 2E 69 73 6F 2E 6F 72 67 2F 69  ndards.iso.org/i
474 14 Andreas Steffen
12[IMV] 32592: 73 6F 2F 31 39 37 37 30 2F 2D 32 2F 32 30 31 34  so/19770/-2/2014
475 14 Andreas Steffen
12[IMV] 32608: 2F 73 63 68 65 6D 61 2E 78 73 64 22 3E 3C 45 6E  /schema.xsd"><En
476 14 Andreas Steffen
12[IMV] 32624: 74 69 74 79 20 6E 61 6D 65 3D 22 73 74 72 6F 6E  tity name="stron
477 14 Andreas Steffen
12[IMV] 32640: 67 53 77 61 6E 22 20 72 65 67 69 64 3D 22 72 65  gSwan" regid="re
478 14 Andreas Steffen
12[IMV] 32656: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
479 1 Andreas Steffen
12[IMV] 32672: 73 74 72 6F 6E 67 73 77 61 6E 22 20 72 6F 6C 65  strongswan" role
480 1 Andreas Steffen
12[IMV] 32688: 3D 22 74 61 67 63 72 65 61 74 6F 72 22 20        ="tagcreator" 
481 14 Andreas Steffen
12[TNC] processing PA-TNC message with ID 0xa775c264
482 14 Andreas Steffen
12[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
483 14 Andreas Steffen
</pre>
484 14 Andreas Steffen
485 24 Andreas Steffen
h3. Received Next Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
486 14 Andreas Steffen
487 20 Andreas Steffen
<pre>
488 14 Andreas Steffen
12[TNC] received next segment for base attribute ID 1 (32678 bytes)
489 14 Andreas Steffen
12[LIB] 284 bytes insufficient to parse 305 bytes of data
490 14 Andreas Steffen
12[IMV] received SWID tag inventory with 102 items for request 3 at eid 1 of epoch 0xf1070c90, 164 items to follow
491 14 Andreas Steffen
12[IMV] <SoftwareIdentity name="libapr1" uniqueId="debian_7.5-x86_64-libapr1-1.4.6-3+deb7u1" version="1.4.6-3+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
492 14 Andreas Steffen
12[IMV] <SoftwareIdentity name="libapr1-dev" uniqueId="debian_7.5-x86_64-libapr1-dev-1.4.6-3+deb7u1" version="1.4.6-3+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
493 33 Andreas Steffen
        ... 99 more SWID Tags
494 1 Andreas Steffen
12[IMV] <SoftwareIdentity name="liblocale-gettext-perl" uniqueId="debian_7.5-x86_64-liblocale-gettext-perl-1.05-7+b1" version="1.05-7+b1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
495 19 Andreas Steffen
</pre>
496 19 Andreas Steffen
497 19 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
498 19 Andreas Steffen
499 19 Andreas Steffen
<pre>
500 19 Andreas Steffen
12[TNC] creating PA-TNC message with ID 0x5382f1b3
501 19 Andreas Steffen
12[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
502 19 Andreas Steffen
12[IMV] created PA-TNC message: => 24 bytes @ 0x7c6f20
503 19 Andreas Steffen
12[IMV]    0: 01 00 00 00 53 82 F1 B3 00 00 55 97 00 00 00 24  ....S.....U....$
504 19 Andreas Steffen
12[IMV]   16: 00 00 00 10 00 00 00 01                          ........
505 19 Andreas Steffen
12[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
506 19 Andreas Steffen
</pre>
507 19 Andreas Steffen
508 19 Andreas Steffen
<pre>
509 19 Andreas Steffen
12[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
510 19 Andreas Steffen
12[TNC] creating PB-TNC SDATA batch
511 19 Andreas Steffen
12[TNC] adding IETF/PB-PA message
512 19 Andreas Steffen
12[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 1
513 19 Andreas Steffen
12[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
514 19 Andreas Steffen
</pre>
515 19 Andreas Steffen
516 19 Andreas Steffen
<pre>
517 19 Andreas Steffen
12[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
518 19 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
519 19 Andreas Steffen
13[CFG] ignoring RADIUS Access-Request 0x60, already processing
520 19 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
521 19 Andreas Steffen
03[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
522 19 Andreas Steffen
03[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
523 19 Andreas Steffen
        ... 31 more RADIUS exchanges
524 19 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
525 19 Andreas Steffen
04[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
526 19 Andreas Steffen
</pre>
527 19 Andreas Steffen
528 19 Andreas Steffen
<pre>
529 19 Andreas Steffen
04[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
530 19 Andreas Steffen
04[TNC] received TNCCS batch (32734 bytes) for Connection ID 1
531 19 Andreas Steffen
04[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
532 19 Andreas Steffen
04[TNC] processing PB-TNC CDATA batch
533 19 Andreas Steffen
04[TNC] processing IETF/PB-PA message (32726 bytes)
534 19 Andreas Steffen
</pre>
535 19 Andreas Steffen
536 19 Andreas Steffen
<pre>
537 19 Andreas Steffen
04[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
538 19 Andreas Steffen
04[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
539 19 Andreas Steffen
04[IMV] => 32702 bytes @ 0x82b510
540 19 Andreas Steffen
04[IMV]    0: 01 00 00 00 08 CC 13 66 00 00 55 97 00 00 00 23  .......f..U....#
541 19 Andreas Steffen
04[IMV]   16: 00 00 7F B6 80 00 00 01 2F 3E 3C 2F 53 6F 66 74  ......../></Soft
542 19 Andreas Steffen
04[IMV]   32: 77 61 72 65 49 64 65 6E 74 69 74 79 3E 00 00 00  wareIdentity>...
543 19 Andreas Steffen
04[IMV]   48: 00 01 39 3C 53 6F 66 74 77 61 72 65 49 64 65 6E  ..9<SoftwareIden
544 19 Andreas Steffen
04[IMV]   64: 74 69 74 79 20 6E 61 6D 65 3D 22 6C 69 62 6C 6F  tity name="liblo
545 19 Andreas Steffen
04[IMV]   80: 67 34 63 78 78 31 30 2D 64 65 76 22 20 75 6E 69  g4cxx10-dev" uni
546 19 Andreas Steffen
         ...
547 19 Andreas Steffen
04[IMV] 32288: 74 69 74 79 3E 00 00 00 00 01 43 3C 53 6F 66 74  tity>.....C<Soft
548 19 Andreas Steffen
04[IMV] 32304: 77 61 72 65 49 64 65 6E 74 69 74 79 20 6E 61 6D  wareIdentity nam
549 19 Andreas Steffen
04[IMV] 32320: 65 3D 22 6D 75 6C 74 69 61 72 63 68 2D 73 75 70  e="multiarch-sup
550 19 Andreas Steffen
04[IMV] 32336: 70 6F 72 74 22 20 75 6E 69 71 75 65 49 64 3D 22  port" uniqueId="
551 19 Andreas Steffen
04[IMV] 32352: 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36 5F 36  debian_7.5-x86_6
552 19 Andreas Steffen
04[IMV] 32368: 34 2D 6D 75 6C 74 69 61 72 63 68 2D 73 75 70 70  4-multiarch-supp
553 19 Andreas Steffen
04[IMV] 32384: 6F 72 74 2D 32 2E 31 33 2D 33 38 2B 64 65 62 37  ort-2.13-38+deb7
554 19 Andreas Steffen
04[IMV] 32400: 75 31 22 20 76 65 72 73 69 6F 6E 3D 22 32 2E 31  u1" version="2.1
555 19 Andreas Steffen
04[IMV] 32416: 33 2D 33 38 2B 64 65 62 37 75 31 22 20 76 65 72  3-38+deb7u1" ver
556 19 Andreas Steffen
04[IMV] 32432: 73 69 6F 6E 53 63 68 65 6D 65 3D 22 61 6C 70 68  sionScheme="alph
557 19 Andreas Steffen
04[IMV] 32448: 61 6E 75 6D 65 72 69 63 22 20 78 6D 6C 6E 73 3D  anumeric" xmlns=
558 19 Andreas Steffen
04[IMV] 32464: 22 68 74 74 70 3A 2F 2F 73 74 61 6E 64 61 72 64  "http://standard
559 19 Andreas Steffen
04[IMV] 32480: 73 2E 69 73 6F 2E 6F 72 67 2F 69 73 6F 2F 31 39  s.iso.org/iso/19
560 19 Andreas Steffen
04[IMV] 32496: 37 37 30 2F 2D 32 2F 32 30 31 34 2F 73 63 68 65  770/-2/2014/sche
561 19 Andreas Steffen
04[IMV] 32512: 6D 61 2E 78 73 64 22 3E 3C 45 6E 74 69 74 79 20  ma.xsd"><Entity 
562 19 Andreas Steffen
04[IMV] 32528: 6E 61 6D 65 3D 22 73 74 72 6F 6E 67 53 77 61 6E  name="strongSwan
563 19 Andreas Steffen
04[IMV] 32544: 22 20 72 65 67 69 64 3D 22 72 65 67 69 64 2E 32  " regid="regid.2
564 19 Andreas Steffen
04[IMV] 32560: 30 30 34 2D 30 33 2E 6F 72 67 2E 73 74 72 6F 6E  004-03.org.stron
565 19 Andreas Steffen
04[IMV] 32576: 67 73 77 61 6E 22 20 72 6F 6C 65 3D 22 74 61 67  gswan" role="tag
566 19 Andreas Steffen
04[IMV] 32592: 63 72 65 61 74 6F 72 22 20 2F 3E 3C 2F 53 6F 66  creator" /></Sof
567 19 Andreas Steffen
04[IMV] 32608: 74 77 61 72 65 49 64 65 6E 74 69 74 79 3E 00 00  twareIdentity>..
568 19 Andreas Steffen
04[IMV] 32624: 00 00 01 47 3C 53 6F 66 74 77 61 72 65 49 64 65  ...G<SoftwareIde
569 19 Andreas Steffen
04[IMV] 32640: 6E 74 69 74 79 20 6E 61 6D 65 3D 22 6D 79 73 71  ntity name="mysq
570 19 Andreas Steffen
04[IMV] 32656: 6C 2D 63 6F 6D 6D 6F 6E 22 20 75 6E 69 71 75 65  l-common" unique
571 19 Andreas Steffen
04[IMV] 32672: 49 64 3D 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78  Id="debian_7.5-x
572 19 Andreas Steffen
04[IMV] 32688: 38 36 5F 36 34 2D 6D 79 73 71 6C 2D 63 6F        86_64-mysql-co
573 19 Andreas Steffen
04[TNC] processing PA-TNC message with ID 0x08cc1366
574 19 Andreas Steffen
04[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
575 19 Andreas Steffen
</pre>
576 19 Andreas Steffen
577 24 Andreas Steffen
h3. Received Next Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
578 19 Andreas Steffen
579 19 Andreas Steffen
<pre>
580 19 Andreas Steffen
04[TNC] received next segment for base attribute ID 1 (32678 bytes)
581 19 Andreas Steffen
04[LIB] 74 bytes insufficient to parse 327 bytes of data
582 19 Andreas Steffen
04[IMV] received SWID tag inventory with 106 items for request 3 at eid 1 of epoch 0xf1070c90, 58 items to follow
583 19 Andreas Steffen
04[IMV] <SoftwareIdentity name="liblog4cxx10" uniqueId="debian_7.5-x86_64-liblog4cxx10-0.10.0-1.2" version="0.10.0-1.2" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
584 1 Andreas Steffen
04[IMV] <SoftwareIdentity name="liblog4cxx10-dev" uniqueId="debian_7.5-x86_64-liblog4cxx10-dev-0.10.0-1.2" version="0.10.0-1.2" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
585 33 Andreas Steffen
      ... 103 more SWID Tags
586 20 Andreas Steffen
04[IMV] <SoftwareIdentity name="multiarch-support" uniqueId="debian_7.5-x86_64-multiarch-support-2.13-38+deb7u1" version="2.13-38+deb7u1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
587 20 Andreas Steffen
</pre>
588 20 Andreas Steffen
589 20 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
590 20 Andreas Steffen
591 20 Andreas Steffen
<pre>
592 20 Andreas Steffen
04[TNC] creating PA-TNC message with ID 0x76280e6a
593 20 Andreas Steffen
04[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
594 20 Andreas Steffen
04[IMV] created PA-TNC message: => 24 bytes @ 0x7a7860
595 20 Andreas Steffen
04[IMV]    0: 01 00 00 00 76 28 0E 6A 00 00 55 97 00 00 00 24  ....v(.j..U....$
596 20 Andreas Steffen
04[IMV]   16: 00 00 00 10 00 00 00 01                          ........
597 20 Andreas Steffen
04[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
598 20 Andreas Steffen
</pre>
599 20 Andreas Steffen
600 20 Andreas Steffen
<pre>
601 20 Andreas Steffen
04[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
602 20 Andreas Steffen
04[TNC] creating PB-TNC SDATA batch
603 20 Andreas Steffen
04[TNC] adding IETF/PB-PA message
604 20 Andreas Steffen
04[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 1
605 20 Andreas Steffen
04[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
606 20 Andreas Steffen
</pre>
607 20 Andreas Steffen
608 20 Andreas Steffen
<pre>
609 20 Andreas Steffen
04[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
610 20 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
611 20 Andreas Steffen
11[CFG] ignoring RADIUS Access-Request 0x81, already processing
612 20 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
613 20 Andreas Steffen
13[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
614 20 Andreas Steffen
13[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
615 20 Andreas Steffen
        ... 15 more RADIUS exchanges
616 20 Andreas Steffen
16[CFG] received RADIUS Access-Request from client '10.1.0.1'
617 20 Andreas Steffen
16[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
618 20 Andreas Steffen
</pre>
619 20 Andreas Steffen
620 20 Andreas Steffen
<pre>
621 20 Andreas Steffen
16[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
622 20 Andreas Steffen
16[TNC] received TNCCS batch (17866 bytes) for Connection ID 1
623 20 Andreas Steffen
16[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
624 20 Andreas Steffen
16[TNC] processing PB-TNC CDATA batch
625 20 Andreas Steffen
16[TNC] processing IETF/PB-PA message (17858 bytes)
626 20 Andreas Steffen
</pre>
627 20 Andreas Steffen
628 20 Andreas Steffen
<pre>
629 21 Andreas Steffen
16[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
630 21 Andreas Steffen
16[IMV] IMV 2 "SWID" received message for Connection ID 1 from IMC 2 to IMV 2
631 21 Andreas Steffen
16[IMV]    0: 01 00 00 00 15 7F 65 95 00 00 55 97 00 00 00 23  ......e...U....#
632 21 Andreas Steffen
16[IMV]   16: 00 00 45 A2 00 00 00 01 6D 6D 6F 6E 2D 35 2E 35  ..E.....mmon-5.5
633 21 Andreas Steffen
16[IMV]   32: 2E 33 35 2B 64 66 73 67 2D 30 2B 77 68 65 65 7A  .35+dfsg-0+wheez
634 21 Andreas Steffen
16[IMV]   48: 79 31 22 20 76 65 72 73 69 6F 6E 3D 22 35 2E 35  y1" version="5.5
635 21 Andreas Steffen
16[IMV]   64: 2E 33 35 2B 64 66 73 67 2D 30 2B 77 68 65 65 7A  .35+dfsg-0+wheez
636 21 Andreas Steffen
16[IMV]   80: 79 31 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D  y1" versionSchem
637 21 Andreas Steffen
16[IMV]   96: 65 3D 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22  e="alphanumeric"
638 21 Andreas Steffen
16[IMV]  112: 20 78 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F 2F 73   xmlns="http://s
639 21 Andreas Steffen
16[IMV]  128: 74 61 6E 64 61 72 64 73 2E 69 73 6F 2E 6F 72 67  tandards.iso.org
640 21 Andreas Steffen
16[IMV]  144: 2F 69 73 6F 2F 31 39 37 37 30 2F 2D 32 2F 32 30  /iso/19770/-2/20
641 21 Andreas Steffen
16[IMV]  160: 31 34 2F 73 63 68 65 6D 61 2E 78 73 64 22 3E 3C  14/schema.xsd"><
642 21 Andreas Steffen
16[IMV]  176: 45 6E 74 69 74 79 20 6E 61 6D 65 3D 22 73 74 72  Entity name="str
643 21 Andreas Steffen
16[IMV]  192: 6F 6E 67 53 77 61 6E 22 20 72 65 67 69 64 3D 22  ongSwan" regid="
644 21 Andreas Steffen
16[IMV]  208: 72 65 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72  regid.2004-03.or
645 21 Andreas Steffen
16[IMV]  224: 67 2E 73 74 72 6F 6E 67 73 77 61 6E 22 20 72 6F  g.strongswan" ro
646 21 Andreas Steffen
16[IMV]  240: 6C 65 3D 22 74 61 67 63 72 65 61 74 6F 72 22 20  le="tagcreator" 
647 21 Andreas Steffen
16[IMV]  256: 2F 3E 3C 2F 53 6F 66 74 77 61 72 65 49 64 65 6E  /></SoftwareIden
648 21 Andreas Steffen
16[IMV]  272: 74 69 74 79 3E 00 00 00 00 01 21 3C 53 6F 66 74  tity>.....!<Soft
649 21 Andreas Steffen
16[IMV]  288: 77 61 72 65 49 64 65 6E 74 69 74 79 20 6E 61 6D  wareIdentity nam
650 21 Andreas Steffen
16[IMV]  304: 65 3D 22 6E 61 6E 6F 22 20 75 6E 69 71 75 65 49  e="nano" uniqueI
651 21 Andreas Steffen
   ...
652 21 Andreas Steffen
16[IMV] 17520: 00 01 37 3C 53 6F 66 74 77 61 72 65 49 64 65 6E  ..7<SoftwareIden
653 21 Andreas Steffen
16[IMV] 17536: 74 69 74 79 20 6E 61 6D 65 3D 22 7A 6C 69 62 31  tity name="zlib1
654 21 Andreas Steffen
16[IMV] 17552: 67 2D 64 65 76 22 20 75 6E 69 71 75 65 49 64 3D  g-dev" uniqueId=
655 21 Andreas Steffen
16[IMV] 17568: 22 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36 5F  "debian_7.5-x86_
656 21 Andreas Steffen
16[IMV] 17584: 36 34 2D 7A 6C 69 62 31 67 2D 64 65 76 2D 31 3A  64-zlib1g-dev-1:
657 21 Andreas Steffen
16[IMV] 17600: 31 2E 32 2E 37 2E 64 66 73 67 2D 31 33 22 20 76  1.2.7.dfsg-13" v
658 21 Andreas Steffen
16[IMV] 17616: 65 72 73 69 6F 6E 3D 22 31 3A 31 2E 32 2E 37 2E  ersion="1:1.2.7.
659 21 Andreas Steffen
16[IMV] 17632: 64 66 73 67 2D 31 33 22 20 76 65 72 73 69 6F 6E  dfsg-13" version
660 21 Andreas Steffen
16[IMV] 17648: 53 63 68 65 6D 65 3D 22 61 6C 70 68 61 6E 75 6D  Scheme="alphanum
661 21 Andreas Steffen
16[IMV] 17664: 65 72 69 63 22 20 78 6D 6C 6E 73 3D 22 68 74 74  eric" xmlns="htt
662 21 Andreas Steffen
16[IMV] 17680: 70 3A 2F 2F 73 74 61 6E 64 61 72 64 73 2E 69 73  p://standards.is
663 21 Andreas Steffen
16[IMV] 17696: 6F 2E 6F 72 67 2F 69 73 6F 2F 31 39 37 37 30 2F  o.org/iso/19770/
664 21 Andreas Steffen
16[IMV] 17712: 2D 32 2F 32 30 31 34 2F 73 63 68 65 6D 61 2E 78  -2/2014/schema.x
665 21 Andreas Steffen
16[IMV] 17728: 73 64 22 3E 3C 45 6E 74 69 74 79 20 6E 61 6D 65  sd"><Entity name
666 21 Andreas Steffen
16[IMV] 17744: 3D 22 73 74 72 6F 6E 67 53 77 61 6E 22 20 72 65  ="strongSwan" re
667 21 Andreas Steffen
16[IMV] 17760: 67 69 64 3D 22 72 65 67 69 64 2E 32 30 30 34 2D  gid="regid.2004-
668 21 Andreas Steffen
16[IMV] 17776: 30 33 2E 6F 72 67 2E 73 74 72 6F 6E 67 73 77 61  03.org.strongswa
669 21 Andreas Steffen
16[IMV] 17792: 6E 22 20 72 6F 6C 65 3D 22 74 61 67 63 72 65 61  n" role="tagcrea
670 21 Andreas Steffen
16[IMV] 17808: 74 6F 72 22 20 2F 3E 3C 2F 53 6F 66 74 77 61 72  tor" /></Softwar
671 21 Andreas Steffen
16[IMV] 17824: 65 49 64 65 6E 74 69 74 79 3E                    eIdentity>
672 21 Andreas Steffen
16[TNC] processing PA-TNC message with ID 0x157f6595
673 21 Andreas Steffen
16[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
674 21 Andreas Steffen
</pre>
675 21 Andreas Steffen
676 24 Andreas Steffen
h3. Received Last Segment of Base Attribute 'TCG/SWID Tag Inventory' with ID 1
677 21 Andreas Steffen
678 21 Andreas Steffen
<pre>
679 21 Andreas Steffen
16[TNC] received last segment for base attribute ID 1 (17810 bytes)
680 21 Andreas Steffen
16[IMV] received SWID tag inventory with 58 items for request 3 at eid 1 of epoch 0xf1070c90, 0 items to follow
681 21 Andreas Steffen
16[IMV] <SoftwareIdentity name="mysql-common" uniqueId="debian_7.5-x86_64-mysql-common-5.5.35+dfsg-0+wheezy1" version="5.5.35+dfsg-0+wheezy1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
682 21 Andreas Steffen
16[IMV] <SoftwareIdentity name="nano" uniqueId="debian_7.5-x86_64-nano-2.2.6-1+b1" version="2.2.6-1+b1" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
683 33 Andreas Steffen
        ... 55 more SWID Tags
684 21 Andreas Steffen
16[IMV] <SoftwareIdentity name="zlib1g-dev" uniqueId="debian_7.5-x86_64-zlib1g-dev-1:1.2.7.dfsg-13" version="1:1.2.7.dfsg-13" versionScheme="alphanumeric" xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd"><Entity name="strongSwan" regid="regid.2004-03.org.strongswan" role="tagcreator" /></SoftwareIdentity>
685 21 Andreas Steffen
</pre>
686 21 Andreas Steffen
687 21 Andreas Steffen
<pre>
688 21 Andreas Steffen
16[IMV] IMV 2 handled SWIDT workitem 3: allow - received inventory of 0 SWID tag IDs and 372 SWID tags
689 21 Andreas Steffen
16[TNC] creating PA-TNC message with ID 0x39b02ad7
690 21 Andreas Steffen
16[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
691 21 Andreas Steffen
16[IMV] created PA-TNC message: => 24 bytes @ 0x7a7600
692 21 Andreas Steffen
16[IMV]    0: 01 00 00 00 39 B0 2A D7 00 00 00 00 00 00 00 09  ....9.*.........
693 21 Andreas Steffen
16[IMV]   16: 00 00 00 10 00 00 00 00                          ........
694 21 Andreas Steffen
16[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
695 21 Andreas Steffen
16[TNC] IMV 2 provides recommendation 'allow' and evaluation 'compliant'
696 21 Andreas Steffen
16[IMV] running policy script: 2>&1 ipsec imv_policy_manager stop 2
697 21 Andreas Steffen
16[IMV] policy: imv_policy_manager stop successful
698 21 Andreas Steffen
16[IMV] IMV 1 "OS" changed state of Connection ID 1 to 'Isolated'
699 21 Andreas Steffen
16[IMV] IMV 2 "SWID" changed state of Connection ID 1 to 'Isolated'
700 21 Andreas Steffen
</pre>
701 21 Andreas Steffen
702 21 Andreas Steffen
<pre>
703 21 Andreas Steffen
16[TNC] PB-TNC state transition from 'Server Working' to 'Decided'
704 21 Andreas Steffen
16[TNC] creating PB-TNC RESULT batch
705 21 Andreas Steffen
16[TNC] adding IETF/PB-PA message
706 21 Andreas Steffen
16[TNC] adding IETF/PB-Assessment-Result message
707 21 Andreas Steffen
16[TNC] adding IETF/PB-Access-Recommendation message
708 21 Andreas Steffen
16[TNC] adding IETF/PB-Reason-String message
709 21 Andreas Steffen
16[TNC] sending PB-TNC RESULT batch (141 bytes) for Connection ID 1
710 21 Andreas Steffen
16[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
711 21 Andreas Steffen
</pre>
712 21 Andreas Steffen
713 21 Andreas Steffen
<pre>
714 21 Andreas Steffen
16[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
715 21 Andreas Steffen
02[CFG] received RADIUS Access-Request from client '10.1.0.1'
716 21 Andreas Steffen
02[CFG] ignoring RADIUS Access-Request 0x93, already processing
717 21 Andreas Steffen
01[CFG] received RADIUS Access-Request from client '10.1.0.1'
718 21 Andreas Steffen
01[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
719 21 Andreas Steffen
</pre>
720 21 Andreas Steffen
721 21 Andreas Steffen
<pre>
722 21 Andreas Steffen
01[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
723 21 Andreas Steffen
01[TNC] received TNCCS batch (8 bytes) for Connection ID 1
724 21 Andreas Steffen
01[TNC] PB-TNC state transition from 'Decided' to 'End'
725 21 Andreas Steffen
01[TNC] processing PB-TNC CLOSE batch
726 21 Andreas Steffen
01[TNC] final recommendation is 'isolate' and evaluation is 'non-compliant major'
727 21 Andreas Steffen
01[TNC] policy enforced on peer 'dave' is 'isolate'
728 21 Andreas Steffen
01[TNC] policy enforcement point added group membership 'isolate'
729 21 Andreas Steffen
01[IKE] EAP_TTLS phase2 authentication of 'dave' with EAP_PT_EAP successful
730 21 Andreas Steffen
01[IMV] IMV 1 "OS" deleted the state of Connection ID 1
731 21 Andreas Steffen
01[IMV] IMV 2 "SWID" deleted the state of Connection ID 1
732 21 Andreas Steffen
01[TNC] removed TNCCS Connection ID 1
733 21 Andreas Steffen
01[TLS] sending TLS close notify
734 21 Andreas Steffen
</pre>
735 21 Andreas Steffen
736 21 Andreas Steffen
<pre>
737 21 Andreas Steffen
01[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
738 21 Andreas Steffen
10[CFG] received RADIUS Access-Request from client '10.1.0.1'
739 21 Andreas Steffen
10[CFG] found RADIUS connection for user 'dave' NAS 'strongSwan'
740 21 Andreas Steffen
10[CFG] sending RADIUS Access-Accept to client '10.1.0.1'
741 21 Andreas Steffen
10[CFG] removed RADIUS connection for user 'dave' NAS 'strongSwan'
742 1 Andreas Steffen
</pre>
743 1 Andreas Steffen
744 37 Andreas Steffen
h2. PT-EAP Connection by Access Requestor "carol" via EAP-RADIUS
745 37 Andreas Steffen
746 22 Andreas Steffen
Set up an EAP-TTLS connection between AR and PDP
747 22 Andreas Steffen
<pre>
748 22 Andreas Steffen
09[CFG] received RADIUS Access-Request from client '10.1.0.1'
749 22 Andreas Steffen
09[CFG] created RADIUS connection for user 'carol' NAS 'strongSwan'
750 22 Andreas Steffen
09[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
751 22 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
752 1 Andreas Steffen
11[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
753 1 Andreas Steffen
11[TLS] negotiated TLS 1.2 using suite TLS_DHE_RSA_WITH_AES_128_CBC_SHA
754 1 Andreas Steffen
11[TLS] sending TLS server certificate 'C=CH, O=Linux strongSwan, CN=aaa.strongswan.org'
755 1 Andreas Steffen
11[TLS] sending TLS cert request for 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'
756 24 Andreas Steffen
</pre>
757 24 Andreas Steffen
758 24 Andreas Steffen
<pre>
759 24 Andreas Steffen
11[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
760 24 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
761 24 Andreas Steffen
04[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
762 24 Andreas Steffen
04[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
763 24 Andreas Steffen
13[CFG] received RADIUS Access-Request from client '10.1.0.1'
764 24 Andreas Steffen
13[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
765 24 Andreas Steffen
13[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/ID]
766 24 Andreas Steffen
13[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
767 24 Andreas Steffen
12[CFG] received RADIUS Access-Request from client '10.1.0.1'
768 24 Andreas Steffen
12[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
769 24 Andreas Steffen
</pre>
770 24 Andreas Steffen
771 24 Andreas Steffen
Received EAP-Identity of AR "carol"
772 24 Andreas Steffen
<pre>
773 24 Andreas Steffen
12[IKE] received tunneled EAP-TTLS AVP [EAP/RES/ID]
774 24 Andreas Steffen
12[IKE] received EAP identity 'carol'
775 24 Andreas Steffen
12[IKE] phase2 method EAP_MD5 selected
776 24 Andreas Steffen
12[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/MD5]
777 24 Andreas Steffen
</pre>
778 24 Andreas Steffen
779 24 Andreas Steffen
<pre>
780 24 Andreas Steffen
12[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
781 24 Andreas Steffen
03[CFG] received RADIUS Access-Request from client '10.1.0.1'
782 24 Andreas Steffen
03[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
783 24 Andreas Steffen
</pre>
784 24 Andreas Steffen
785 24 Andreas Steffen
EAP-MD5 based authentication of AR "carol"
786 24 Andreas Steffen
<pre>
787 24 Andreas Steffen
03[IKE] received tunneled EAP-TTLS AVP [EAP/RES/MD5]
788 24 Andreas Steffen
03[IKE] EAP_TTLS phase2 authentication of 'carol' with EAP_MD5 successful
789 24 Andreas Steffen
03[IKE] phase2 method EAP_PT_EAP selected
790 24 Andreas Steffen
03[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
791 24 Andreas Steffen
</pre>
792 24 Andreas Steffen
793 24 Andreas Steffen
<pre>
794 24 Andreas Steffen
03[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
795 24 Andreas Steffen
Oct  6 20:49:46 alice charon: 14[CFG] received RADIUS Access-Request from client '10.1.0.1'
796 24 Andreas Steffen
Oct  6 20:49:46 alice charon: 14[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
797 13 Andreas Steffen
</pre>
798 25 Andreas Steffen
799 25 Andreas Steffen
h3. Creating IF-TNCCS 2.0 connection with ID 2
800 25 Andreas Steffen
801 25 Andreas Steffen
Upon reception of the first PB-TNC client batch, open an IF-TNCCS 2.0 connection
802 25 Andreas Steffen
<pre>
803 25 Andreas Steffen
14[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
804 25 Andreas Steffen
14[TNC] assigned TNCCS Connection ID 2
805 25 Andreas Steffen
14[IMV] IMV 1 "OS" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh
806 25 Andreas Steffen
14[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
807 25 Andreas Steffen
14[IMV]   user AR identity 'carol' authenticated by password
808 25 Andreas Steffen
14[IMV] IMV 2 "SWID" created a state for IF-TNCCS 2.0 Connection ID 2: +long +excl -soh
809 25 Andreas Steffen
14[IMV]   over IF-T for Tunneled EAP 2.0 with maximum PA-TNC message size of 65490 bytes
810 25 Andreas Steffen
14[IMV]   user AR identity 'carol' authenticated by password
811 25 Andreas Steffen
14[IMV] IMV 1 "OS" changed state of Connection ID 2 to 'Handshake'
812 25 Andreas Steffen
14[IMV] IMV 2 "SWID" changed state of Connection ID 2 to 'Handshake'
813 25 Andreas Steffen
</pre>
814 25 Andreas Steffen
815 25 Andreas Steffen
<pre>
816 25 Andreas Steffen
14[TNC] received TNCCS batch (311 bytes) for Connection ID 2
817 25 Andreas Steffen
14[TNC] PB-TNC state transition from 'Init' to 'Server Working'
818 25 Andreas Steffen
14[TNC] processing PB-TNC CDATA batch
819 25 Andreas Steffen
14[TNC] processing IETF/PB-Language-Preference message (31 bytes)
820 25 Andreas Steffen
14[TNC] processing IETF/PB-PA message (220 bytes)
821 25 Andreas Steffen
14[TNC] processing IETF/PB-PA message (52 bytes)
822 25 Andreas Steffen
14[TNC] setting language preference to 'en'
823 25 Andreas Steffen
</pre>
824 25 Andreas Steffen
825 25 Andreas Steffen
<pre>
826 25 Andreas Steffen
14[TNC] handling PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
827 25 Andreas Steffen
14[IMV] IMV 1 "OS" received message for Connection ID 2 from IMC 1
828 25 Andreas Steffen
14[IMV] => 196 bytes @ 0x7b0410
829 25 Andreas Steffen
14[IMV]    0: 01 00 00 00 7C 05 FC 15 00 00 00 00 00 00 00 02  ....|...........
830 25 Andreas Steffen
14[IMV]   16: 00 00 00 17 00 25 72 00 00 44 65 62 69 61 6E 00  .....%r..Debian.
831 25 Andreas Steffen
14[IMV]   32: 00 00 00 00 00 00 04 00 00 00 19 0A 37 2E 35 20  ............7.5 
832 25 Andreas Steffen
14[IMV]   48: 78 38 36 5F 36 34 00 00 00 00 00 00 00 00 00 03  x86_64..........
833 25 Andreas Steffen
14[IMV]   64: 00 00 00 1C 00 00 00 07 00 00 00 05 00 00 00 00  ................
834 25 Andreas Steffen
14[IMV]   80: 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 24  ...............$
835 25 Andreas Steffen
14[IMV]   96: 03 01 00 00 32 30 31 34 2D 31 30 2D 30 36 54 31  ....2014-10-06T1
836 25 Andreas Steffen
14[IMV]  112: 39 3A 33 31 3A 30 30 5A 00 00 00 00 00 00 00 0B  9:31:00Z........
837 25 Andreas Steffen
14[IMV]  128: 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 0C  ................
838 25 Andreas Steffen
14[IMV]  144: 00 00 00 10 00 00 00 00 00 00 90 2A 00 00 00 08  ...........*....
839 25 Andreas Steffen
14[IMV]  160: 00 00 00 2C 30 36 30 64 63 61 36 66 61 35 36 61  ...,060dca6fa56a
840 25 Andreas Steffen
14[IMV]  176: 34 33 66 34 61 62 32 32 63 61 34 30 35 33 38 37  43f4ab22ca405387
841 25 Andreas Steffen
14[IMV]  192: 32 33 39 65                                      239e
842 25 Andreas Steffen
14[TNC] processing PA-TNC message with ID 0x7c05fc15
843 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Product Information' 0x000000/0x00000002
844 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/String Version' 0x000000/0x00000004
845 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Numeric Version' 0x000000/0x00000003
846 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Operational Status' 0x000000/0x00000005
847 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Forwarding Enabled' 0x000000/0x0000000b
848 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'IETF/Factory Default Password Enabled' 0x000000/0x0000000c
849 25 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'ITA-HSR/Device ID' 0x00902a/0x00000008
850 1 Andreas Steffen
</pre>
851 25 Andreas Steffen
852 27 Andreas Steffen
h3. Received Standard 'IETF/Operating System' Attributes
853 26 Andreas Steffen
854 25 Andreas Steffen
<pre>
855 25 Andreas Steffen
14[IMV] operating system name is 'Debian' from vendor Debian Project
856 25 Andreas Steffen
14[IMV] operating system version is '7.5 x86_64'
857 25 Andreas Steffen
14[IMV] operating system numeric version is 7.5
858 25 Andreas Steffen
14[IMV] operational status: operational, result: successful
859 25 Andreas Steffen
14[IMV] last boot: Oct 06 19:31:00 UTC 2014
860 25 Andreas Steffen
14[IMV] IPv4 forwarding is disabled
861 25 Andreas Steffen
14[IMV] factory default password is disabled
862 25 Andreas Steffen
14[IMV] device ID is 060dca6fa56a43f4ab22ca405387239e
863 26 Andreas Steffen
</pre>
864 26 Andreas Steffen
865 26 Andreas Steffen
h3. Received Max Attribute Size Request for IF-M Message Type 'TCG/SWID' 
866 26 Andreas Steffen
867 26 Andreas Steffen
<pre>
868 26 Andreas Steffen
14[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
869 26 Andreas Steffen
14[IMV] IMV 2 "SWID" received message for Connection ID 2 from IMC 2
870 26 Andreas Steffen
14[IMV] => 28 bytes @ 0x799eb0
871 26 Andreas Steffen
14[IMV]    0: 01 00 00 00 2C FB F1 DF 00 00 55 97 00 00 00 21  ....,.....U....!
872 26 Andreas Steffen
14[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 3F A6              ..........?.
873 26 Andreas Steffen
14[TNC] processing PA-TNC message with ID 0x2cfbf1df
874 26 Andreas Steffen
14[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
875 1 Andreas Steffen
14[IMV] received a segmentation contract from IMC 2 for PA message type 'TCG/SWID' 0x005597/0x00000003
876 29 Andreas Steffen
14[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 16294 bytes
877 27 Andreas Steffen
</pre>
878 27 Andreas Steffen
879 27 Andreas Steffen
h3. Sending Max Attribute Size Response for IF-M Message Type 'TCG/SWID'
880 27 Andreas Steffen
881 27 Andreas Steffen
<pre>
882 27 Andreas Steffen
14[TNC] creating PA-TNC message with ID 0x65090b6e
883 27 Andreas Steffen
14[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
884 27 Andreas Steffen
14[IMV] created PA-TNC message: => 28 bytes @ 0x884a30
885 27 Andreas Steffen
14[IMV]    0: 01 00 00 00 65 09 0B 6E 00 00 55 97 00 00 00 22  ....e..n..U...."
886 27 Andreas Steffen
14[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 3F A6              ..........?.
887 27 Andreas Steffen
14[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
888 27 Andreas Steffen
</pre>
889 27 Andreas Steffen
890 27 Andreas Steffen
h3. Sending Max Attribute Size Request for IF-M Message Type 'IETF Operating Systen'
891 27 Andreas Steffen
892 27 Andreas Steffen
<pre>
893 27 Andreas Steffen
14[IMV] IMV 1 requests a segmentation contract for PA message type 'IETF/Operating System' 0x000000/0x00000001
894 29 Andreas Steffen
14[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 65446 bytes
895 27 Andreas Steffen
</pre>
896 27 Andreas Steffen
897 27 Andreas Steffen
h3. Assign Session ID 3 to Connection with ID 2 and apply TNC Policy
898 27 Andreas Steffen
899 27 Andreas Steffen
<pre>
900 27 Andreas Steffen
14[IMV] assigned session ID 3 to Connection ID 2
901 27 Andreas Steffen
14[IMV] running policy script: 2>&1 ipsec imv_policy_manager start 3
902 27 Andreas Steffen
14[IMV] policy: imv_policy_manager start successful
903 27 Andreas Steffen
14[IMV] FMEAS workitem 4
904 27 Andreas Steffen
14[IMV] FMEAS workitem 5
905 27 Andreas Steffen
14[IMV] FWDEN workitem 6
906 27 Andreas Steffen
14[IMV] FMEAS workitem 7
907 27 Andreas Steffen
14[IMV] FMETA workitem 8
908 27 Andreas Steffen
14[IMV] SWIDT workitem 9
909 27 Andreas Steffen
14[IMV] TCPOP workitem 10
910 27 Andreas Steffen
14[IMV] UDPOP workitem 11
911 27 Andreas Steffen
</pre>
912 27 Andreas Steffen
913 27 Andreas Steffen
<pre>
914 27 Andreas Steffen
14[IMV] IMV 1 handles FWDEN workitem 6
915 27 Andreas Steffen
14[IMV] IMV 1 handled FWDEN workitem 6: allow - forwarding not enabled
916 27 Andreas Steffen
14[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
917 27 Andreas Steffen
14[IMV] created PA-TNC message: => 24 bytes @ 0x7cdd60
918 27 Andreas Steffen
14[IMV]    0: 01 00 00 00 CF 25 60 EB 00 00 00 00 00 00 00 09  .....%`.........
919 27 Andreas Steffen
14[IMV]   16: 00 00 00 10 00 00 00 00                          ........
920 27 Andreas Steffen
14[TNC] creating PB-PA message type 'IETF/Operating System' 0x000000/0x00000001
921 27 Andreas Steffen
14[TNC] IMV 1 provides recommendation 'allow' and evaluation 'compliant'
922 1 Andreas Steffen
</pre>
923 1 Andreas Steffen
924 36 Andreas Steffen
h3. Sending Max Attribute Size Request for IF-M Message Type 'TCG/SWID'
925 29 Andreas Steffen
926 1 Andreas Steffen
<pre>
927 29 Andreas Steffen
14[IMV] IMV 2 requests a segmentation contract for PA message type 'TCG/SWID' 0x005597/0x00000003
928 29 Andreas Steffen
14[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 65446 bytes
929 29 Andreas Steffen
</pre>
930 29 Andreas Steffen
931 34 Andreas Steffen
h3. Sending SWID Request for a Complete Tag ID Inventory
932 34 Andreas Steffen
933 29 Andreas Steffen
<pre>
934 29 Andreas Steffen
14[IMV] IMV 2 handles SWIDT workitem 9
935 29 Andreas Steffen
14[IMV] IMV 2 issues SWID request 9
936 29 Andreas Steffen
</pre>
937 29 Andreas Steffen
938 29 Andreas Steffen
<pre>
939 29 Andreas Steffen
14[TNC] creating PA-TNC message with ID 0xd876bbb9
940 29 Andreas Steffen
14[TNC] creating PA-TNC attribute type 'TCG/Max Attribute Size Request' 0x005597/0x00000021
941 29 Andreas Steffen
14[TNC] creating PA-TNC attribute type 'TCG/SWID Request' 0x005597/0x00000011
942 29 Andreas Steffen
14[IMV] created PA-TNC message: => 52 bytes @ 0x7d5340
943 29 Andreas Steffen
14[IMV]    0: 01 00 00 00 D8 76 BB B9 00 00 55 97 00 00 00 21  .....v....U....!
944 29 Andreas Steffen
14[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 FF A6 00 00 55 97  ..............U.
945 29 Andreas Steffen
14[IMV]   32: 00 00 00 11 00 00 00 18 80 00 00 00 00 00 00 09  ................
946 29 Andreas Steffen
14[IMV]   48: 00 00 00 00                                      ....
947 29 Andreas Steffen
14[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
948 29 Andreas Steffen
</pre>
949 29 Andreas Steffen
950 29 Andreas Steffen
<pre>
951 29 Andreas Steffen
14[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
952 29 Andreas Steffen
14[TNC] creating PB-TNC SDATA batch
953 29 Andreas Steffen
14[TNC] adding TCG/PB-PDP-Referral message
954 29 Andreas Steffen
14[TNC] adding IETF/PB-PA message
955 29 Andreas Steffen
14[TNC] adding IETF/PB-PA message
956 29 Andreas Steffen
14[TNC] adding IETF/PB-PA message
957 29 Andreas Steffen
14[TNC] sending PB-TNC SDATA batch (226 bytes) for Connection ID 2
958 29 Andreas Steffen
14[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
959 29 Andreas Steffen
</pre>
960 29 Andreas Steffen
961 29 Andreas Steffen
<pre>
962 29 Andreas Steffen
14[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
963 29 Andreas Steffen
15[CFG] received RADIUS Access-Request from client '10.1.0.1'
964 29 Andreas Steffen
15[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
965 29 Andreas Steffen
15[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
966 29 Andreas Steffen
        ... 15 more RADIUS exchanges
967 29 Andreas Steffen
10[CFG] received RADIUS Access-Request from client '10.1.0.1'
968 29 Andreas Steffen
10[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
969 29 Andreas Steffen
</pre>
970 29 Andreas Steffen
971 29 Andreas Steffen
<pre>
972 29 Andreas Steffen
10[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
973 29 Andreas Steffen
10[TNC] received TNCCS batch (16370 bytes) for Connection ID 2
974 29 Andreas Steffen
10[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
975 29 Andreas Steffen
10[TNC] processing PB-TNC CDATA batch
976 29 Andreas Steffen
10[TNC] processing IETF/PB-PA message (16362 bytes)
977 29 Andreas Steffen
</pre>
978 29 Andreas Steffen
979 29 Andreas Steffen
<pre>
980 30 Andreas Steffen
10[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
981 30 Andreas Steffen
10[IMV] IMV 2 "SWID" received message for Connection ID 2 from IMC 2 to IMV 2
982 30 Andreas Steffen
10[IMV] => 16338 bytes @ 0x80b5b0
983 30 Andreas Steffen
10[IMV]    0: 01 00 00 00 BB 06 8F 24 00 00 55 97 00 00 00 22  .......$..U...."
984 30 Andreas Steffen
10[IMV]   16: 00 00 00 14 05 F5 E1 00 00 00 3F A6 00 00 55 97  ..........?...U.
985 30 Andreas Steffen
10[IMV]   32: 00 00 00 23 00 00 3F B6 C0 00 00 01 00 00 55 97  ...#..?.......U.
986 30 Andreas Steffen
10[IMV]   48: 00 00 00 12 00 00 6D F1 00 00 01 75 00 00 00 09  ......m....u....
987 30 Andreas Steffen
10[IMV]   64: A3 23 49 9C 00 00 00 01 00 1C 72 65 67 69 64 2E  .#I.......regid.
988 30 Andreas Steffen
10[IMV]   80: 32 30 30 34 2D 30 33 2E 6F 72 67 2E 73 74 72 6F  2004-03.org.stro
989 30 Andreas Steffen
10[IMV]   96: 6E 67 73 77 61 6E 00 2B 64 65 62 69 61 6E 5F 37  ngswan.+debian_7
990 30 Andreas Steffen
10[IMV]  112: 2E 35 2D 78 38 36 5F 36 34 2D 61 63 70 69 2D 73  .5-x86_64-acpi-s
991 30 Andreas Steffen
10[IMV]  128: 75 70 70 6F 72 74 2D 62 61 73 65 2D 30 2E 31 34  upport-base-0.14
992 30 Andreas Steffen
10[IMV]  144: 30 2D 35 00 00 00 1C 72 65 67 69 64 2E 32 30 30  0-5....regid.200
993 30 Andreas Steffen
10[IMV]  160: 34 2D 30 33 2E 6F 72 67 2E 73 74 72 6F 6E 67 73  4-03.org.strongs
994 30 Andreas Steffen
10[IMV]  176: 77 61 6E 00 29 64 65 62 69 61 6E 5F 37 2E 35 2D  wan.)debian_7.5-
995 30 Andreas Steffen
10[IMV]  192: 78 38 36 5F 36 34 2D 61 63 70 69 64 2D 31 3A 32  x86_64-acpid-1:2
996 30 Andreas Steffen
10[IMV]  208: 2E 30 2E 31 36 2D 31 2B 64 65 62 37 75 31 00 00  .0.16-1+deb7u1..
997 30 Andreas Steffen
         ...
998 30 Andreas Steffen
10[IMV] 16144: 00 1C 72 65 67 69 64 2E 32 30 30 34 2D 30 33 2E  ..regid.2004-03.
999 30 Andreas Steffen
10[IMV] 16160: 6F 72 67 2E 73 74 72 6F 6E 67 73 77 61 6E 00 3A  org.strongswan.:
1000 30 Andreas Steffen
10[IMV] 16176: 64 65 62 69 61 6E 5F 37 2E 35 2D 78 38 36 5F 36  debian_7.5-x86_6
1001 30 Andreas Steffen
10[IMV] 16192: 34 2D 6C 69 62 6C 77 72 65 73 38 30 2D 31 3A 39  4-liblwres80-1:9
1002 30 Andreas Steffen
10[IMV] 16208: 2E 38 2E 34 2E 64 66 73 67 2E 50 31 2D 36 2B 6E  .8.4.dfsg.P1-6+n
1003 30 Andreas Steffen
10[IMV] 16224: 6D 75 32 2B 64 65 62 37 75 31 00 00 00 1C 72 65  mu2+deb7u1....re
1004 30 Andreas Steffen
10[IMV] 16240: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
1005 30 Andreas Steffen
10[IMV] 16256: 73 74 72 6F 6E 67 73 77 61 6E 00 30 64 65 62 69  strongswan.0debi
1006 30 Andreas Steffen
10[IMV] 16272: 61 6E 5F 37 2E 35 2D 78 38 36 5F 36 34 2D 6C 69  an_7.5-x86_64-li
1007 30 Andreas Steffen
10[IMV] 16288: 62 6C 7A 6D 61 35 2D 35 2E 31 2E 31 61 6C 70 68  blzma5-5.1.1alph
1008 30 Andreas Steffen
10[IMV] 16304: 61 2B 32 30 31 32 30 36 31 34 2D 32 00 00 00 1C  a+20120614-2....
1009 30 Andreas Steffen
10[IMV] 16320: 72 65 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72  regid.2004-03.or
1010 30 Andreas Steffen
10[IMV] 16336: 67 2E                                            g.
1011 30 Andreas Steffen
10[TNC] processing PA-TNC message with ID 0xbb068f24
1012 30 Andreas Steffen
10[TNC] processing PA-TNC attribute type 'TCG/Max Attribute Size Response' 0x005597/0x00000022
1013 30 Andreas Steffen
10[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
1014 30 Andreas Steffen
</pre>
1015 29 Andreas Steffen
1016 30 Andreas Steffen
h3. Received Max Attribute Size Response for IF-M Message Type 'TCG/SWID ' 
1017 30 Andreas Steffen
1018 30 Andreas Steffen
<pre>
1019 30 Andreas Steffen
10[IMV] received a segmentation contract response for PA message type 'TCG/SWID' 0x005597/0x00000003
1020 33 Andreas Steffen
10[IMV]   maximum attribute size of 100'000'000 bytes with maximum segment size of 16294 bytes
1021 30 Andreas Steffen
</pre>
1022 30 Andreas Steffen
1023 32 Andreas Steffen
h3. Received First Segment of Base Attribute 'TCG/SWID Tag ID Inventory' with ID 1
1024 30 Andreas Steffen
1025 30 Andreas Steffen
<pre>
1026 30 Andreas Steffen
10[TNC] received first segment for base attribute ID 1 (16294 bytes)
1027 30 Andreas Steffen
10[TNC] processing PA-TNC attribute type 'TCG/SWID Tag Identifier Inventory' 0x005597/0x00000012
1028 30 Andreas Steffen
10[LIB] 18 bytes insufficient to parse 28 bytes of data
1029 30 Andreas Steffen
10[IMV] received SWID tag ID inventory with 214 items for request 9 at eid 1 of epoch 0xa323499c, 159 items to follow
1030 31 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_debian_7.5-x86_64-acpi-support-base-0.140-5
1031 31 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_debian_7.5-x86_64-acpid-1:2.0.16-1+deb7u1
1032 33 Andreas Steffen
          ... 211 more SWID Tag IDs
1033 31 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_debian_7.5-x86_64-liblzma5-5.1.1alpha+20120614-2
1034 31 Andreas Steffen
</pre>
1035 31 Andreas Steffen
1036 31 Andreas Steffen
h3. Sending Next Segment Request for Base Attribute with ID 1
1037 31 Andreas Steffen
1038 31 Andreas Steffen
<pre>
1039 31 Andreas Steffen
10[TNC] creating PA-TNC message with ID 0x36c4fdc6
1040 31 Andreas Steffen
10[TNC] creating PA-TNC attribute type 'TCG/Next Segment Request' 0x005597/0x00000024
1041 31 Andreas Steffen
10[IMV] created PA-TNC message: => 24 bytes @ 0x7a3fa0
1042 31 Andreas Steffen
10[IMV]    0: 01 00 00 00 36 C4 FD C6 00 00 55 97 00 00 00 24  ....6.....U....$
1043 31 Andreas Steffen
10[IMV]   16: 00 00 00 10 00 00 00 01                          ........
1044 31 Andreas Steffen
10[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
1045 31 Andreas Steffen
10[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
1046 31 Andreas Steffen
10[TNC] creating PB-TNC SDATA batch
1047 31 Andreas Steffen
10[TNC] adding IETF/PB-PA message
1048 31 Andreas Steffen
10[TNC] sending PB-TNC SDATA batch (56 bytes) for Connection ID 2
1049 31 Andreas Steffen
10[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
1050 31 Andreas Steffen
</pre>
1051 31 Andreas Steffen
1052 1 Andreas Steffen
<pre>
1053 32 Andreas Steffen
10[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
1054 32 Andreas Steffen
09[CFG] received RADIUS Access-Request from client '10.1.0.1'
1055 32 Andreas Steffen
09[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
1056 32 Andreas Steffen
09[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
1057 32 Andreas Steffen
        ... 10 more RADIUS exchanges
1058 32 Andreas Steffen
10[CFG] received RADIUS Access-Request from client '10.1.0.1'
1059 32 Andreas Steffen
10[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
1060 32 Andreas Steffen
</pre>
1061 1 Andreas Steffen
1062 32 Andreas Steffen
<pre>
1063 32 Andreas Steffen
10[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
1064 32 Andreas Steffen
10[TNC] received TNCCS batch (11907 bytes) for Connection ID 2
1065 32 Andreas Steffen
10[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
1066 32 Andreas Steffen
10[TNC] processing PB-TNC CDATA batch
1067 32 Andreas Steffen
10[TNC] processing IETF/PB-PA message (11899 bytes)
1068 32 Andreas Steffen
</pre>
1069 1 Andreas Steffen
1070 32 Andreas Steffen
<pre>
1071 32 Andreas Steffen
10[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
1072 32 Andreas Steffen
10[IMV] IMV 2 "SWID" received message for Connection ID 2 from IMC 2 to IMV 2
1073 32 Andreas Steffen
10[IMV] => 11875 bytes @ 0x804130
1074 32 Andreas Steffen
10[IMV]    0: 01 00 00 00 7C B1 1D 71 00 00 55 97 00 00 00 23  ....|..q..U....#
1075 32 Andreas Steffen
10[IMV]   16: 00 00 2E 5B 00 00 00 01 73 74 72 6F 6E 67 73 77  ...[....strongsw
1076 32 Andreas Steffen
10[IMV]   32: 61 6E 00 26 64 65 62 69 61 6E 5F 37 2E 35 2D 78  an.&debian_7.5-x
1077 32 Andreas Steffen
10[IMV]   48: 38 36 5F 36 34 2D 6C 69 62 6D 6F 75 6E 74 31 2D  86_64-libmount1-
1078 32 Andreas Steffen
10[IMV]   64: 32 2E 32 30 2E 31 2D 35 2E 33 00 00 00 1C 72 65  2.20.1-5.3....re
1079 32 Andreas Steffen
10[IMV]   80: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
1080 32 Andreas Steffen
10[IMV]   96: 73 74 72 6F 6E 67 73 77 61 6E 00 1F 64 65 62 69  strongswan..debi
1081 32 Andreas Steffen
10[IMV]  112: 61 6E 5F 37 2E 35 2D 78 38 36 5F 36 34 2D 6C 69  an_7.5-x86_64-li
1082 32 Andreas Steffen
10[IMV]  128: 62 6D 70 63 32 2D 30 2E 39 2D 34 00 00 00 1C 72  bmpc2-0.9-4....r
1083 32 Andreas Steffen
         ...
1084 32 Andreas Steffen
10[IMV] 11744: 6E 67 73 77 61 6E 00 13 73 74 72 6F 6E 67 53 77  ngswan..strongSw
1085 32 Andreas Steffen
10[IMV] 11760: 61 6E 2D 35 2D 32 2D 31 64 72 31 00 66 2F 75 73  an-5-2-1dr1.f/us
1086 32 Andreas Steffen
10[IMV] 11776: 72 2F 6C 6F 63 61 6C 2F 73 68 61 72 65 2F 72 65  r/local/share/re
1087 32 Andreas Steffen
10[IMV] 11792: 67 69 64 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E  gid.2004-03.org.
1088 32 Andreas Steffen
10[IMV] 11808: 73 74 72 6F 6E 67 73 77 61 6E 2F 72 65 67 69 64  strongswan/regid
1089 32 Andreas Steffen
10[IMV] 11824: 2E 32 30 30 34 2D 30 33 2E 6F 72 67 2E 73 74 72  .2004-03.org.str
1090 32 Andreas Steffen
10[IMV] 11840: 6F 6E 67 73 77 61 6E 5F 73 74 72 6F 6E 67 53 77  ongswan_strongSw
1091 32 Andreas Steffen
10[IMV] 11856: 61 6E 2D 35 2D 32 2D 31 64 72 31 2E 73 77 69 64  an-5-2-1dr1.swid
1092 32 Andreas Steffen
10[IMV] 11872: 74 61 67                                         tag
1093 32 Andreas Steffen
10[TNC] processing PA-TNC message with ID 0x7cb11d71
1094 32 Andreas Steffen
10[TNC] processing PA-TNC attribute type 'TCG/Attribute Segment Envelope' 0x005597/0x00000023
1095 32 Andreas Steffen
</pre>
1096 1 Andreas Steffen
1097 32 Andreas Steffen
h3. Received Last Segment of Base Attribute 'TCG/SWID Tag ID Inventory' with ID 1
1098 32 Andreas Steffen
1099 32 Andreas Steffen
<pre>
1100 32 Andreas Steffen
10[TNC] received last segment for base attribute ID 1 (11851 bytes)
1101 32 Andreas Steffen
10[IMV] received SWID tag ID inventory with 159 items for request 9 at eid 1 of epoch 0xa323499c, 0 items to follow
1102 32 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_debian_7.5-x86_64-libmount1-2.20.1-5.3
1103 32 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_debian_7.5-x86_64-libmpc2-0.9-4
1104 32 Andreas Steffen
          ... 155 more SWID Tag IDs
1105 32 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_debian_7.5-x86_64-zlib1g-dev-1:1.2.7.dfsg-13
1106 32 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_strongSwan-5-2-1dr1
1107 32 Andreas Steffen
</pre>
1108 34 Andreas Steffen
1109 34 Andreas Steffen
h3. Sending Targeted SWID Request for a Single Tag
1110 32 Andreas Steffen
1111 32 Andreas Steffen
<pre>
1112 32 Andreas Steffen
10[IMV] 1 SWID tag target
1113 32 Andreas Steffen
10[IMV]   regid.2004-03.org.strongswan_strongSwan-5-2-1dr1
1114 32 Andreas Steffen
</pre>
1115 32 Andreas Steffen
1116 32 Andreas Steffen
<pre>
1117 32 Andreas Steffen
10[TNC] creating PA-TNC message with ID 0x9d4d952c
1118 32 Andreas Steffen
10[TNC] creating PA-TNC attribute type 'TCG/SWID Request' 0x005597/0x00000011
1119 32 Andreas Steffen
10[IMV] created PA-TNC message: => 83 bytes @ 0x80fd60
1120 32 Andreas Steffen
10[IMV]    0: 01 00 00 00 9D 4D 95 2C 00 00 55 97 00 00 00 11  .....M.,..U.....
1121 32 Andreas Steffen
10[IMV]   16: 00 00 00 4B 00 00 00 01 00 00 00 09 00 00 00 00  ...K............
1122 32 Andreas Steffen
10[IMV]   32: 00 1C 72 65 67 69 64 2E 32 30 30 34 2D 30 33 2E  ..regid.2004-03.
1123 32 Andreas Steffen
10[IMV]   48: 6F 72 67 2E 73 74 72 6F 6E 67 73 77 61 6E 00 13  org.strongswan..
1124 32 Andreas Steffen
10[IMV]   64: 73 74 72 6F 6E 67 53 77 61 6E 2D 35 2D 32 2D 31  strongSwan-5-2-1
1125 32 Andreas Steffen
10[IMV]   80: 64 72 31                                         dr1
1126 32 Andreas Steffen
10[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
1127 32 Andreas Steffen
</pre>
1128 32 Andreas Steffen
1129 32 Andreas Steffen
<pre>
1130 32 Andreas Steffen
10[TNC] PB-TNC state transition from 'Server Working' to 'Client Working'
1131 32 Andreas Steffen
10[TNC] creating PB-TNC SDATA batch
1132 1 Andreas Steffen
10[TNC] adding IETF/PB-PA message
1133 1 Andreas Steffen
10[TNC] sending PB-TNC SDATA batch (115 bytes) for Connection ID 2
1134 1 Andreas Steffen
10[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
1135 1 Andreas Steffen
</pre>
1136 1 Andreas Steffen
1137 1 Andreas Steffen
<pre>
1138 33 Andreas Steffen
10[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
1139 33 Andreas Steffen
09[CFG] received RADIUS Access-Request from client '10.1.0.1'
1140 33 Andreas Steffen
09[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
1141 33 Andreas Steffen
</pre>
1142 33 Andreas Steffen
1143 33 Andreas Steffen
<pre>
1144 33 Andreas Steffen
09[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
1145 33 Andreas Steffen
09[TNC] received TNCCS batch (546 bytes) for Connection ID 2
1146 33 Andreas Steffen
09[TNC] PB-TNC state transition from 'Client Working' to 'Server Working'
1147 33 Andreas Steffen
09[TNC] processing PB-TNC CDATA batch
1148 33 Andreas Steffen
09[TNC] processing IETF/PB-PA message (538 bytes)
1149 33 Andreas Steffen
</pre>
1150 33 Andreas Steffen
1151 33 Andreas Steffen
<pre>
1152 33 Andreas Steffen
09[TNC] handling PB-PA message type 'TCG/SWID' 0x005597/0x00000003
1153 33 Andreas Steffen
09[IMV] IMV 2 "SWID" received message for Connection ID 2 from IMC 2 to IMV 2
1154 33 Andreas Steffen
09[IMV] => 514 bytes @ 0x85ae40
1155 33 Andreas Steffen
09[IMV]    0: 01 00 00 00 32 BB AB 25 00 00 55 97 00 00 00 14  ....2..%..U.....
1156 33 Andreas Steffen
09[IMV]   16: 00 00 01 FA 00 00 00 01 00 00 00 09 A3 23 49 9C  .............#I.
1157 33 Andreas Steffen
09[IMV]   32: 00 00 00 01 00 66 2F 75 73 72 2F 6C 6F 63 61 6C  .....f/usr/local
1158 33 Andreas Steffen
09[IMV]   48: 2F 73 68 61 72 65 2F 72 65 67 69 64 2E 32 30 30  /share/regid.200
1159 33 Andreas Steffen
09[IMV]   64: 34 2D 30 33 2E 6F 72 67 2E 73 74 72 6F 6E 67 73  4-03.org.strongs
1160 33 Andreas Steffen
09[IMV]   80: 77 61 6E 2F 72 65 67 69 64 2E 32 30 30 34 2D 30  wan/regid.2004-0
1161 33 Andreas Steffen
09[IMV]   96: 33 2E 6F 72 67 2E 73 74 72 6F 6E 67 73 77 61 6E  3.org.strongswan
1162 33 Andreas Steffen
09[IMV]  112: 5F 73 74 72 6F 6E 67 53 77 61 6E 2D 35 2D 32 2D  _strongSwan-5-2-
1163 33 Andreas Steffen
09[IMV]  128: 31 64 72 31 2E 73 77 69 64 74 61 67 00 00 01 72  1dr1.swidtag...r
1164 33 Andreas Steffen
09[IMV]  144: 3C 3F 78 6D 6C 20 76 65 72 73 69 6F 6E 3D 22 31  <?xml version="1
1165 33 Andreas Steffen
09[IMV]  160: 2E 30 22 20 65 6E 63 6F 64 69 6E 67 3D 22 75 74  .0" encoding="ut
1166 33 Andreas Steffen
09[IMV]  176: 66 2D 38 22 3F 3E 0A 0A 3C 53 6F 66 74 77 61 72  f-8"?>..<Softwar
1167 33 Andreas Steffen
09[IMV]  192: 65 49 64 65 6E 74 69 74 79 0A 20 20 6E 61 6D 65  eIdentity.  name
1168 33 Andreas Steffen
09[IMV]  208: 3D 22 73 74 72 6F 6E 67 53 77 61 6E 22 0A 20 20  ="strongSwan".  
1169 33 Andreas Steffen
09[IMV]  224: 75 6E 69 71 75 65 49 64 3D 22 73 74 72 6F 6E 67  uniqueId="strong
1170 33 Andreas Steffen
09[IMV]  240: 53 77 61 6E 2D 35 2D 32 2D 31 64 72 31 22 0A 20  Swan-5-2-1dr1". 
1171 33 Andreas Steffen
09[IMV]  256: 20 76 65 72 73 69 6F 6E 3D 22 35 2E 32 2E 31 64   version="5.2.1d
1172 33 Andreas Steffen
09[IMV]  272: 72 31 22 20 76 65 72 73 69 6F 6E 53 63 68 65 6D  r1" versionSchem
1173 33 Andreas Steffen
09[IMV]  288: 65 3D 22 61 6C 70 68 61 6E 75 6D 65 72 69 63 22  e="alphanumeric"
1174 33 Andreas Steffen
09[IMV]  304: 0A 20 20 78 6D 6C 6E 73 3D 22 68 74 74 70 3A 2F  .  xmlns="http:/
1175 33 Andreas Steffen
09[IMV]  320: 2F 73 74 61 6E 64 61 72 64 73 2E 69 73 6F 2E 6F  /standards.iso.o
1176 33 Andreas Steffen
09[IMV]  336: 72 67 2F 69 73 6F 2F 31 39 37 37 30 2F 2D 32 2F  rg/iso/19770/-2/
1177 33 Andreas Steffen
09[IMV]  352: 32 30 31 34 2F 73 63 68 65 6D 61 2E 78 73 64 22  2014/schema.xsd"
1178 33 Andreas Steffen
09[IMV]  368: 3E 0A 20 20 3C 45 6E 74 69 74 79 0A 20 20 20 20  >.  <Entity.    
1179 33 Andreas Steffen
09[IMV]  384: 6E 61 6D 65 3D 22 73 74 72 6F 6E 67 53 77 61 6E  name="strongSwan
1180 33 Andreas Steffen
09[IMV]  400: 20 50 72 6F 6A 65 63 74 22 0A 20 20 20 20 72 65   Project".    re
1181 33 Andreas Steffen
09[IMV]  416: 67 69 64 3D 22 72 65 67 69 64 2E 32 30 30 34 2D  gid="regid.2004-
1182 33 Andreas Steffen
09[IMV]  432: 30 33 2E 6F 72 67 2E 73 74 72 6F 6E 67 73 77 61  03.org.strongswa
1183 33 Andreas Steffen
09[IMV]  448: 6E 22 0A 20 20 20 20 72 6F 6C 65 3D 22 70 75 62  n".    role="pub
1184 33 Andreas Steffen
09[IMV]  464: 6C 69 73 68 65 72 20 6C 69 63 65 6E 73 6F 72 20  lisher licensor 
1185 33 Andreas Steffen
09[IMV]  480: 74 61 67 63 72 65 61 74 6F 72 22 2F 3E 0A 3C 2F  tagcreator"/>.</
1186 33 Andreas Steffen
09[IMV]  496: 53 6F 66 74 77 61 72 65 49 64 65 6E 74 69 74 79  SoftwareIdentity
1187 33 Andreas Steffen
09[IMV]  512: 3E 0A                                            >.
1188 33 Andreas Steffen
09[TNC] processing PA-TNC message with ID 0x32bbab25
1189 33 Andreas Steffen
09[TNC] processing PA-TNC attribute type 'TCG/SWID Tag Inventory' 0x005597/0x00000014
1190 33 Andreas Steffen
</pre>
1191 33 Andreas Steffen
1192 35 Andreas Steffen
h3. Received SWID/Tag Inventory Containing a Single Tag
1193 35 Andreas Steffen
1194 33 Andreas Steffen
<pre>
1195 33 Andreas Steffen
09[IMV] received SWID tag inventory with 1 item for request 9 at eid 1 of epoch 0xa323499c, 0 items to follow
1196 33 Andreas Steffen
09[IMV] <?xml version="1.0" encoding="utf-8"?>
1197 33 Andreas Steffen
09[IMV]
1198 33 Andreas Steffen
09[IMV] <SoftwareIdentity
1199 33 Andreas Steffen
09[IMV]   name="strongSwan"
1200 33 Andreas Steffen
09[IMV]   uniqueId="strongSwan-5-2-1dr1"
1201 33 Andreas Steffen
09[IMV]   version="5.2.1dr1" versionScheme="alphanumeric"
1202 33 Andreas Steffen
09[IMV]   xmlns="http://standards.iso.org/iso/19770/-2/2014/schema.xsd">
1203 33 Andreas Steffen
09[IMV]   <Entity
1204 33 Andreas Steffen
09[IMV]     name="strongSwan Project"
1205 33 Andreas Steffen
09[IMV]     regid="regid.2004-03.org.strongswan"
1206 33 Andreas Steffen
09[IMV]     role="publisher licensor tagcreator"/>
1207 1 Andreas Steffen
09[IMV] </SoftwareIdentity>
1208 36 Andreas Steffen
</pre>
1209 1 Andreas Steffen
1210 1 Andreas Steffen
<pre>
1211 37 Andreas Steffen
09[IMV] IMV 2 handled SWIDT workitem 9: allow - received inventory of 373 SWID tag IDs and 1 SWID tag
1212 37 Andreas Steffen
09[TNC] creating PA-TNC message with ID 0x7ceaeaf5
1213 37 Andreas Steffen
09[TNC] creating PA-TNC attribute type 'IETF/Assessment Result' 0x000000/0x00000009
1214 37 Andreas Steffen
09[IMV] created PA-TNC message: => 24 bytes @ 0x78c860
1215 37 Andreas Steffen
09[IMV]    0: 01 00 00 00 7C EA EA F5 00 00 00 00 00 00 00 09  ....|...........
1216 37 Andreas Steffen
09[IMV]   16: 00 00 00 10 00 00 00 00                          ........
1217 37 Andreas Steffen
09[TNC] creating PB-PA message type 'TCG/SWID' 0x005597/0x00000003
1218 37 Andreas Steffen
09[TNC] IMV 2 provides recommendation 'allow' and evaluation 'compliant'
1219 37 Andreas Steffen
09[IMV] running policy script: 2>&1 ipsec imv_policy_manager stop 3
1220 37 Andreas Steffen
09[IMV] policy: imv_policy_manager stop successful
1221 37 Andreas Steffen
09[IMV] policy: No leaks detected, 11 suppressed by whitelist
1222 37 Andreas Steffen
09[IMV] IMV 1 "OS" changed state of Connection ID 2 to 'Allowed'
1223 37 Andreas Steffen
09[IMV] IMV 2 "SWID" changed state of Connection ID 2 to 'Allowed'
1224 37 Andreas Steffen
</pre>
1225 37 Andreas Steffen
1226 37 Andreas Steffen
<pre>
1227 37 Andreas Steffen
09[TNC] PB-TNC state transition from 'Server Working' to 'Decided'
1228 37 Andreas Steffen
09[TNC] creating PB-TNC RESULT batch
1229 37 Andreas Steffen
09[TNC] adding IETF/PB-PA message
1230 37 Andreas Steffen
09[TNC] adding IETF/PB-Assessment-Result message
1231 37 Andreas Steffen
09[TNC] adding IETF/PB-Access-Recommendation message
1232 37 Andreas Steffen
09[TNC] sending PB-TNC RESULT batch (88 bytes) for Connection ID 2
1233 37 Andreas Steffen
09[IKE] sending tunneled EAP-TTLS AVP [EAP/REQ/PT]
1234 37 Andreas Steffen
</pre>
1235 37 Andreas Steffen
1236 37 Andreas Steffen
<pre>
1237 37 Andreas Steffen
09[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
1238 37 Andreas Steffen
11[CFG] received RADIUS Access-Request from client '10.1.0.1'
1239 37 Andreas Steffen
11[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
1240 37 Andreas Steffen
</pre>
1241 37 Andreas Steffen
1242 37 Andreas Steffen
<pre>
1243 37 Andreas Steffen
11[IKE] received tunneled EAP-TTLS AVP [EAP/RES/PT]
1244 37 Andreas Steffen
11[TNC] received TNCCS batch (8 bytes) for Connection ID 2
1245 37 Andreas Steffen
11[TNC] PB-TNC state transition from 'Decided' to 'End'
1246 37 Andreas Steffen
11[TNC] processing PB-TNC CLOSE batch
1247 37 Andreas Steffen
11[TNC] final recommendation is 'allow' and evaluation is 'compliant'
1248 37 Andreas Steffen
11[TNC] policy enforced on peer 'carol' is 'allow'
1249 37 Andreas Steffen
11[TNC] policy enforcement point added group membership 'allow'
1250 37 Andreas Steffen
11[IKE] EAP_TTLS phase2 authentication of 'carol' with EAP_PT_EAP successful
1251 37 Andreas Steffen
11[IMV] IMV 1 "OS" deleted the state of Connection ID 2
1252 37 Andreas Steffen
11[IMV] IMV 2 "SWID" deleted the state of Connection ID 2
1253 37 Andreas Steffen
11[TLS] sending TLS close notify
1254 36 Andreas Steffen
</pre>
1255 36 Andreas Steffen
1256 36 Andreas Steffen
<pre>
1257 36 Andreas Steffen
11[CFG] sending RADIUS Access-Challenge to client '10.1.0.1'
1258 36 Andreas Steffen
04[CFG] received RADIUS Access-Request from client '10.1.0.1'
1259 36 Andreas Steffen
04[CFG] found RADIUS connection for user 'carol' NAS 'strongSwan'
1260 36 Andreas Steffen
04[CFG] sending RADIUS Access-Accept to client '10.1.0.1'
1261 36 Andreas Steffen
04[CFG] removed RADIUS connection for user 'carol' NAS 'strongSwan'
1262 36 Andreas Steffen
</pre>
1263 36 Andreas Steffen
1264 36 Andreas Steffen
h2. Shutting down the strongSwan PDP
1265 36 Andreas Steffen
1266 36 Andreas Steffen
<pre>
1267 36 Andreas Steffen
00[DMN] signal of type SIGINT received. Shutting down
1268 36 Andreas Steffen
00[IMV] IMV 2 "SWID" terminated
1269 36 Andreas Steffen
00[IMV] IMV 1 "OS" terminated
1270 36 Andreas Steffen
00[TNC] removed IETF attributes
1271 36 Andreas Steffen
00[TNC] removed ITA-HSR attributes
1272 36 Andreas Steffen
00[TNC] removed TCG attributes
1273 36 Andreas Steffen
libimcv terminated
1274 28 Andreas Steffen
</pre>