Ciao
@FrancYescO,
Ho voluto provare ad installare il tuo script, solo per "test installazione" in quanto ora e' settato come ap, e non posso spostare o modificare.
Il router e' il modello dgn4131 agg. alla versione 18,(sulla versione 17, il pacchetto strongswan-pki non e' sui feed e quindi non puo' generare i certificati).
Questi sono i pacchetti che mi ha installato:
strongswan
5.6.3-3
strongswan-charon
5.6.3-3
strongswan-default
5.6.3-3
strongswan-ipsec
5.6.3-3
strongswan-mod-aes
5.6.3-3
strongswan-mod-attr
5.6.3-3
strongswan-mod-connmark
5.6.3-3
strongswan-mod-constraints
5.6.3-3
strongswan-mod-des
5.6.3-3
strongswan-mod-dhcp
5.6.3-3
strongswan-mod-dnskey
5.6.3-3
strongswan-mod-fips-prf
5.6.3-3
strongswan-mod-gmp
5.6.3-3
strongswan-mod-hmac
5.6.3-3
strongswan-mod-kernel-netlink
5.6.3-3
strongswan-mod-md5
5.6.3-3
strongswan-mod-nonce
5.6.3-3
strongswan-mod-pem
5.6.3-3
strongswan-mod-pgp
5.6.3-3
strongswan-mod-pkcs1
5.6.3-3
strongswan-mod-pubkey
5.6.3-3
strongswan-mod-random
5.6.3-3
strongswan-mod-rc2
5.6.3-3
strongswan-mod-resolve
5.6.3-3
strongswan-mod-revocation
5.6.3-3
strongswan-mod-sha1
5.6.3-3
strongswan-mod-sha2
5.6.3-3
strongswan-mod-socket-default
5.6.3-3
strongswan-mod-sshkey
5.6.3-3
strongswan-mod-stroke
5.6.3-3
strongswan-mod-updown
5.6.3-3
strongswan-mod-x509
5.6.3-3
strongswan-mod-xauth-generic
5.6.3-3
strongswan-mod-xcbc
5.6.3-3
strongswan-pki
5.6.3-3
Sul repository vi sono tutti questi (dovrebbero servire anche strongswan-mod-eap-**?)
strongswan
strongswan-charon
strongswan-charon-cmd
strongswan-default
strongswan-ipsec
strongswan-isakmp
strongswan-libtls
strongswan-minimal
strongswan-mod-addrblock
strongswan-mod-aes
strongswan-mod-af-alg
strongswan-mod-agent
strongswan-mod-attr
strongswan-mod-attr-sql
strongswan-mod-ccm
strongswan-mod-cmac
strongswan-mod-connmark
strongswan-mod-constraints
strongswan-mod-coupling
strongswan-mod-curl
strongswan-mod-curve25519
strongswan-mod-des
strongswan-mod-dhcp
strongswan-mod-dnskey
strongswan-mod-duplicheck
strongswan-mod-eap-identity
strongswan-mod-eap-md5
strongswan-mod-eap-mschapv2
strongswan-mod-eap-radius
strongswan-mod-eap-tls
strongswan-mod-farp
strongswan-mod-fips-prf
strongswan-mod-forecast
strongswan-mod-gcm
strongswan-mod-gcrypt
StrongSwan libgcrypt plugin
strongswan-mod-gmpdh
strongswan-mod-ha
strongswan-mod-hmac
strongswan-mod-kernel-libipsec
strongswan-mod-kernel-netlink
strongswan-mod-ldap
strongswan-mod-led
strongswan-mod-load-tester
strongswan-mod-md4
strongswan-mod-md5
strongswan-mod-mysql
strongswan-mod-nonce
strongswan-mod-openssl
strongswan-mod-pem
strongswan-mod-pgp
strongswan-mod-pkcs1
strongswan-mod-pkcs11
strongswan-mod-pkcs12
strongswan-mod-pkcs7
strongswan-mod-pkcs8
strongswan-mod-pubkey
strongswan-mod-random
strongswan-mod-rc2
strongswan-mod-resolve
strongswan-mod-revocation
strongswan-mod-sha1
strongswan-mod-sha2
strongswan-mod-smp
strongswan-mod-socket-default
strongswan-mod-socket-dynamic
strongswan-mod-sql
strongswan-mod-sqlite
strongswan-mod-sshkey
strongswan-mod-stroke
strongswan-mod-test-vectors
strongswan-mod-uci
strongswan-mod-unity
strongswan-mod-updown
strongswan-mod-vici
strongswan-mod-whitelist
strongswan-mod-x509
strongswan-mod-xauth-eap
strongswan-mod-xauth-generic
strongswan-mod-xcbc
strongswan-pki
strongswan-scepclient
strongswan-swanctl
I certificati sono stati creati e spostati nelle varie cartelle, anche se nella cartella /tmp/ rimangono:
caCert.crt caKey.pem ,al riavvio dovremmo perderli (non potrei generare ulteriori certificati?Non importa e' giusto per farti un report).
Questo e' un log del servizio:
Sun Apr 26 13:08:16 2020 authpriv.info ipsec_starter[2047]: Starting strongSwan 5.6.3 IPsec [starter]...
Sun Apr 26 13:08:16 2020 daemon.err modprobe: ah4 is already loaded
Sun Apr 26 13:08:16 2020 daemon.err modprobe: esp4 is already loaded
Sun Apr 26 13:08:16 2020 daemon.err modprobe: ipcomp is already loaded
Sun Apr 26 13:08:16 2020 daemon.err modprobe: xfrm4_tunnel is already loaded
Sun Apr 26 13:08:16 2020 daemon.err modprobe: xfrm_user is already loaded
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[DMN] Starting IKE charon daemon (strongSwan 5.6.3, Linux 4.1.38, armv7l)
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loaded ca certificate "C=US, O=Technicolor, CN=CATechnicolor" from '/etc/ipsec.d/cacerts/caCert.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loading crls from '/etc/ipsec.d/crls'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loading secrets from '/etc/ipsec.secrets'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loaded RSA private key from '/etc/ipsec.d/private/serverKey_.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[CFG] loaded EAP secret for remoteusername
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[LIB] loaded plugins: charon aes des rc2 sha2 sha1 md5 random nonce x509 revocation constraints pubkey pkcs1 pgp dnskey sshkey pem fips-prf gmp xcbc hmac attr kernel-netlink resolve socket-default connmark stroke updown xauth-generic dhcp
Sun Apr 26 13:08:16 2020 daemon.info charon: 00[JOB] spawning 16 worker threads
Sun Apr 26 13:08:16 2020 authpriv.info ipsec_starter[2047]: charon (2066) started after 60 ms
Sun Apr 26 13:08:16 2020 daemon.info charon: 05[CFG] received stroke: add connection 'rwEAPMSCHAPV2'
Sun Apr 26 13:08:16 2020 daemon.info charon: 05[CFG] adding virtual IP address pool 10.0.1.0/24
Sun Apr 26 13:08:16 2020 daemon.info charon: 05[CFG] loaded certificate "C=US, O=Technicolor, CN=" from 'serverCert_.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 05[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN='
Sun Apr 26 13:08:16 2020 daemon.info charon: 05[CFG] added configuration 'rwEAPMSCHAPV2'
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] received stroke: add connection 'rwPUBKEYIOS'
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] reusing virtual IP address pool 10.0.1.0/24
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] loaded certificate "C=US, O=Technicolor, CN=" from 'serverCert_.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN='
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] loaded certificate "C=US, O=Technicolor, CN=myvpnclient1" from 'clientCert_myvpnclient1.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] id 'SHAREDSAN' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN=myvpnclient1'
Sun Apr 26 13:08:16 2020 daemon.info charon: 07[CFG] added configuration 'rwPUBKEYIOS'
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] received stroke: add connection 'rwEAPTLSIOS'
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] reusing virtual IP address pool 10.0.1.0/24
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] loaded certificate "C=US, O=Technicolor, CN=" from 'serverCert_.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN='
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] loaded certificate "C=US, O=Technicolor, CN=myvpnclient1" from 'clientCert_myvpnclient1.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] id 'SHAREDSAN' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN=myvpnclient1'
Sun Apr 26 13:08:16 2020 daemon.info charon: 09[CFG] added configuration 'rwEAPTLSIOS'
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] received stroke: add connection 'rwPUBKEY'
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] reusing virtual IP address pool 10.0.1.0/24
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] loaded certificate "C=US, O=Technicolor, CN=" from 'serverCert_.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN='
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] loaded certificate "C=US, O=Technicolor, CN=myvpnclient1" from 'clientCert_myvpnclient1.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN=myvpnclient1'
Sun Apr 26 13:08:16 2020 daemon.info charon: 11[CFG] added configuration 'rwPUBKEY'
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] received stroke: add connection 'rwEAPTLS'
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] reusing virtual IP address pool 10.0.1.0/24
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] loaded certificate "C=US, O=Technicolor, CN=" from 'serverCert_.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN='
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] loaded certificate "C=US, O=Technicolor, CN=myvpnclient1" from 'clientCert_myvpnclient1.pem'
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN=myvpnclient1'
Sun Apr 26 13:08:16 2020 daemon.info charon: 13[CFG] added configuration 'rwEAPTLS'
id '%any' not confirmed by certificate, defaulting to 'C=US, O=Technicolor, CN='
CN=e' cosi' come lo vedi vuoto,non ha preso il mio ddns?o qualcosaltro?(N.B. il sevizio ddns l'ho settato,non e' attivo poiche' l'interfaccia su cui e' settato non e' attiva)
Poi ho notato 10.0.1.0/24,e che non lo hai messo sulla subnet del dhcp, ma poi dopo ci si riesce a comunicare con gli utenti e servizi della lan?
NB. non sono critiche , solo per capire.