Files
strongswan-ext/testing/tests/ikev2/reauth-late/description.txt
T
Tobias Brunner 23e46ea5ab ikev2: Only request reauth during IKE_AUTH if active reauth is not possible
If we can initiate the reauthentication ourselves, there is no reason to
explicitly request the peer to do so (at basically the same time).
2021-08-24 14:31:55 +02:00

10 lines
618 B
Plaintext

This scenario tests <b>repeated authentication</b> according to RFC 4478.
The initiator <b>carol</b> sets a short <b>reauth_time=20s</b> but the responder
<b>moon</b> defining a much larger <b>reauth_time=60m</b> proposes this
value via an AUTH_LIFETIME notification to the initiator as it can't initiate
the reauthentication itself due to the virtual IP address. The initiator
ignores this notification and schedules the IKE reauthentication at its
configured time. A ping from <b>carol</b> to client <b>alice</b>
hiding in the subnet behind <b>moon</b> tests if the CHILD_SA has been
recreated under the new IKE_SA.