Quindi:
opkg list | grep strongswan | awk '{print $1}' | xargs opkg remove --force-removal-of-dependent-packages
opkg list | grep strongswan | awk '{print $1}' | xargs opkg remove --force-removal-of-dependent-packages
rimuove tutto, ripetuto due volte atrimenti rimane il pacchetto strongswan,poi manualmente rimuoviamo la cartella ipsec.d e i due files ipsec.*
Ho riprovato a reinstallare lo script, ho messo a posto il ddns "only.for.testing",lo script funziona,crea le chiavi avvia il demone :
:clap:
Mon Apr 27 16:20:35 2020 authpriv.info ipsec_starter[1306]: Starting strongSwan 5.6.3 IPsec [starter]...
Mon Apr 27 16:20:35 2020 daemon.err modprobe: ah4 is already loaded
Mon Apr 27 16:20:36 2020 daemon.err modprobe: esp4 is already loaded
Mon Apr 27 16:20:36 2020 daemon.err modprobe: ipcomp is already loaded
Mon Apr 27 16:20:36 2020 daemon.err modprobe: xfrm4_tunnel is already loaded
Mon Apr 27 16:20:36 2020 daemon.err modprobe: xfrm_user is already loaded
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[DMN] Starting IKE charon daemon (strongSwan 5.6.3, Linux 4.1.38, armv7l)
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[CFG] loading crls from '/etc/ipsec.d/crls'
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[CFG] loading secrets from '/etc/ipsec.secrets'
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[LIB] loaded plugins: charon aes des rc2 sha2 sha1 md5 random nonce x509 revocation constraints pubkey pkcs1 pgp dnskey sshkey pem fips-prf gmp xcbc hmac attr kernel-netlink resolve socket-default connmark stroke updown xauth-generic dhcp
Mon Apr 27 16:20:36 2020 daemon.info charon: 00[JOB] spawning 16 worker threads
Mon Apr 27 16:20:36 2020 authpriv.info ipsec_starter[1306]: charon (1376) started after 60 ms
Mon Apr 27 16:23:44 2020 daemon.info odhcpd[2831]: Using a RA lifetime of 0 seconds on wl0_2
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[DMN] signal of type SIGINT received. Shutting down
Mon Apr 27 16:23:52 2020 authpriv.info ipsec_starter[1306]: charon stopped after 200 ms
Mon Apr 27 16:23:52 2020 authpriv.info ipsec_starter[1306]: ipsec starter stopped
Mon Apr 27 16:23:52 2020 authpriv.info ipsec_starter[2396]: Starting strongSwan 5.6.3 IPsec [starter]...
Mon Apr 27 16:23:52 2020 daemon.err modprobe: ah4 is already loaded
Mon Apr 27 16:23:52 2020 daemon.err modprobe: esp4 is already loaded
Mon Apr 27 16:23:52 2020 daemon.err modprobe: ipcomp is already loaded
Mon Apr 27 16:23:52 2020 daemon.err modprobe: xfrm4_tunnel is already loaded
Mon Apr 27 16:23:52 2020 daemon.err modprobe: xfrm_user is already loaded
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[DMN] Starting IKE charon daemon (strongSwan 5.6.3, Linux 4.1.38, armv7l)
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loaded ca certificate "C=US, O=Technicolor, CN=CATechnicolor" from '/etc/ipsec.d/cacerts/caCert.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loading crls from '/etc/ipsec.d/crls'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loading secrets from '/etc/ipsec.secrets'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loaded RSA private key from '/etc/ipsec.d/private/serverKey_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loaded EAP secret for remoteusername
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[CFG] loaded 0 RADIUS server configurations
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[LIB] loaded plugins: charon aes des rc2 sha2 sha1 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pgp dnskey sshkey pem fips-prf gmp xcbc hmac attr kernel-netlink resolve socket-default connmark stroke updown eap-identity eap-md5 eap-mschapv2 eap-radius eap-tls xauth-generic dhcp
Mon Apr 27 16:23:52 2020 daemon.info charon: 00[JOB] spawning 16 worker threads
Mon Apr 27 16:23:52 2020 authpriv.info ipsec_starter[2396]: charon (2415) started after 60 ms
Mon Apr 27 16:23:52 2020 daemon.info charon: 05[CFG] received stroke: add connection 'rwEAPMSCHAPV2'
Mon Apr 27 16:23:52 2020 daemon.info charon: 05[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 05[CFG] added configuration 'rwEAPMSCHAPV2'
Mon Apr 27 16:23:52 2020 daemon.info charon: 07[CFG] received stroke: add connection 'rwPUBKEYIOS'
Mon Apr 27 16:23:52 2020 daemon.info charon: 07[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 07[CFG] CA certificate "caCert.pem" not found, discarding CA constraint
Mon Apr 27 16:23:52 2020 daemon.info charon: 07[CFG] added configuration 'rwPUBKEYIOS'
Mon Apr 27 16:23:52 2020 daemon.info charon: 09[CFG] received stroke: add connection 'rwEAPTLSIOS'
Mon Apr 27 16:23:52 2020 daemon.info charon: 09[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 09[LIB] opening '/etc/ipsec.d/certs/caCert.pem' failed: No such file or directory
Mon Apr 27 16:23:52 2020 daemon.info charon: 09[LIB] building CRED_CERTIFICATE - ANY failed, tried 1 builders
Mon Apr 27 16:23:52 2020 daemon.info charon: 09[CFG] loading certificate from 'caCert.pem' failed
Mon Apr 27 16:23:52 2020 daemon.info charon: 09[CFG] added configuration 'rwEAPTLSIOS'
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] received stroke: add connection 'rwPUBKEY'
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[LIB] opening '/etc/ipsec.d/certs/caCert.pem' failed: No such file or directory
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[LIB] building CRED_CERTIFICATE - ANY failed, tried 1 builders
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] loading certificate from 'caCert.pem' failed
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] added configuration 'rwPUBKEY'
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] received stroke: add connection 'rwEAPTLS'
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[LIB] opening '/etc/ipsec.d/certs/caCert.pem' failed: No such file or directory
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[LIB] building CRED_CERTIFICATE - ANY failed, tried 1 builders
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] loading certificate from 'caCert.pem' failed
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] added configuration 'rwEAPTLS'
Ci sono degli errori, forse sulla configurazione ipsec.conf,troppe istanze?:
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] received stroke: add connection 'rwPUBKEY'
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[LIB] opening '/etc/ipsec.d/certs/caCert.pem' failed: No such file or directory
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[LIB] building CRED_CERTIFICATE - ANY failed, tried 1 builders
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] loading certificate from 'caCert.pem' failed
Mon Apr 27 16:23:52 2020 daemon.info charon: 11[CFG] added configuration 'rwPUBKEY'
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] received stroke: add connection 'rwEAPTLS'
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] loaded certificate "C=US, O=Technicolor, CN=only.for.testing" from 'serverCert_only.for.testing.pem'
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[LIB] opening '/etc/ipsec.d/certs/caCert.pem' failed: No such file or directory
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[LIB] building CRED_CERTIFICATE - ANY failed, tried 1 builders
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] loading certificate from 'caCert.pem' failed
Mon Apr 27 16:23:52 2020 daemon.info charon: 13[CFG] added configuration 'rwEAPTLS'
Su dhcp.conf si puo' aggiungere?:
# Derive user-defined MAC address from hash of IKE identity.
# identity_lease = no
identity_lease = yes
Dovrebbe assegnare e rilasciare il fake mac sempre uguale allo stesso utente/certificato,cosi' da poterlo inserire sul dhcp della lan ed assegnare sempre lo stesso indirizzo, funziona l'ho gia' provato.
Poi come faccio a generare dopo lo script ulteriori certificati, o ad inserirli nello script?
