[strongSwan] EAP-AKA: EAP method not supported, sending EAP_NAK

Holger Birkmeyer (ng4T) holger.birkmeyer at ng4t.com
Thu May 21 17:49:07 CEST 2015

Dear Martin,

your hint solved the problem, thanks a lot.

I might drop the Ubuntu eap-package maintainer a note, that there is a
missing dependency to package strongswan-plugin-fips-prf.

merci beaucoup


On 21.05.2015 17:40, Martin Willi wrote:
> Hi Holger,
>> server requested EAP_AKA authentication (id 0x00)
>> EAP method not supported, sending EAP_NAK
>> loaded plugins: charon test-vectors aes rc2 sha1 sha2 md4 md5 random
>>  nonce x509 revocation constraints pkcs1 pkcs7 pkcs8 pkcs12 pem open
>>  ssl xcbc cmac hmac ctr ccm gcm attr kernel-netlink resolve
>>  socket-default stroke updown eap-identity eap-aka eap-aka-3gpp2
>>  addrblock
> EAP-AKA not only needs a backend (such as eap-aka-3gpp2, which you have
> loaded), but also a special PRF implemented in the fips-prf plugin.
> That plugin should get enabled implicitly if you ./configure with
> --enable-eap-aka, but you might need to update any manual
> strongswan.conf load statements.
> Regards
> Martin

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20150521/0558296f/attachment.pgp>

More information about the Users mailing list