[strongSwan] [strongSw an] AES_CCM_16 not supported error
prasobh.s25 at wipro.com
prasobh.s25 at wipro.com
Tue May 26 12:48:56 CEST 2015
Hi Noel,
Thanks for the pointer! How to find out whether crypto plug in enabled (using ipsec listalgs? ) ?
I have enabled both ccm and gcm plugins while compiling strongswan but both of them are not loaded while running strongswan. Its missing in the “loaded plugins:” section seen we enter the command “ipsec statusall”.
I put “charondebug=lib 4” to increase the log level and found that both the ccm and gcm plugins are not loaded . Iam using strongswan 5.0.0 . Also, when I enter “ipsec listalgs” command after running ipsec the “aead:” section is empty. What am I doing wrong ?? Is there some extra configuration to be done in strongswan.conf ?? Attaching the strongswan.conf file.
Best Regards,
Prasobh
-----Original Message-----
From: Noel Kuntze [mailto:noel at familie-kuntze.de]
Sent: 16 May 2015 11:50
To: Prasobh S (WT01 - Global Media & Telecom); users at lists.strongswan.org
Subject: Re: [strongSwan] AES_CCM_16 not supported error
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hello Prasobh,
Make sure you have a crypto plugin loaded that provides that algorithm.
Check the available algorithms for IKE with "ipsec listalgs".
Mit freundlichen Grüßen/Kind Regards,
Noel Kuntze
GPG Key ID: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658
Am 15.05.2015 um 13:26 schrieb prasobh.s25 at wipro.com:
>
> Dear All,
>
>
>
> I am getting following error while trying aes128ccm128 encryption algorithm on strongswan version 5.0.0
>
>
>
> /Received proposals: IKE: AES_CCM_16_128/PRF_HMAC_SHA1/MODP_768/
>
> /Configured proposals: IKE:AES_CCM_16_128/3DES_CBC/HMAC_SHA1_96/HMAC_SHA2_512_256/ PRF_HMAC_SHA1/MODP_768/
>
> /Selected proposals: IKE:AES_CCM_16_128/ PRF_HMAC_SHA1/MODP_768/
>
> /Shared Diffie Hellman secret => 96 bytes @ 0xae401448/
>
> /SKEYSEED => 20 bytes @ 0xae400cf0/
>
> /Sk_d Secret => 20 bytes @ 0xae400cf0/
>
> /ENCRYPTION_ALGORITHM AES_CCM_16 (key size 16) not supported!/
>
> /Key derivation failed/
>
>
>
>
>
> Can anyone help to find out what could be the issue ?
>
>
>
> Thanks and Regards,
>
> Prasobh
>
> The information contained in this electronic message and any attachments to this message are intended for the exclusive use of the addressee(s) and may contain proprietary, confidential or privileged information. If you are not the intended recipient, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately and destroy all copies of this message and any attachments. WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email. www.wipro.com
>
>
> _______________________________________________
> Users mailing list
> Users at lists.strongswan.org
> https://lists.strongswan.org/mailman/listinfo/users
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCAAGBQJVVuGRAAoJEDg5KY9j7GZYC3AP/j9V8JIwRl4I+U1RFXGOXKCk
/p8TZDVqSIpW0eXbUiwIqyWT7YB+fno1+chTdYTS+dbgC3OgubONp3/zneaMq766
uRme+ZqlhlAoCZ40mKlbJiePE7h2RQadv044aAeWwHmPpBlSIwF6TVp/TJFJhX0g
BR3qlHR0qPtQ8wI/jnAqMIkqQEZoVfIf/KQBwoIu/XBx0aP4+Bdocg7hASDeF+pq
8OluzwoXOZWB/TJKHslL3k/HLOdw9R+411tQFjdlhrmo8kPODuykI/dB5648lpZ0
0TpVgsnzAo8fMWfZr5gQgQ8KxRguaQ+BuREXRN0wffFskb0B+eh+Ouzqu+iM+aD2
PyFJYg1LP6csOj2DnhfMqsc5tcn3vrXvyxdBEbqKBdG4sXHAybNZQFF8Iqz3jWCf
vLjWBgMn3C5kHzRHzHWsq0pSShVqF+Oi7p//bjeSGBXlQY4gp4DJ7e/uhd14tBSY
9ogn1gAYJOTWZfrEDqvouebPIsGyjL6rtdllgLzJ/iliPk4mdkk7bHP8oPOxtFnI
FvUgjLSihLSFsO0EKYd6085AhIzaWnDSsUFOCHE5ODs076Ir4oECSmqL9sME+ppf
+TWFfaxI2XcI/nnseCl4AfemnzYZE6av3drwceHxI5XI1g/Wr33jQe47hCxkx8LR
plGvXdcX8wzDr92iedFh
=BT88
-----END PGP SIGNATURE-----
The information contained in this electronic message and any attachments to this message are intended for the exclusive use of the addressee(s) and may contain proprietary, confidential or privileged information. If you are not the intended recipient, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately and destroy all copies of this message and any attachments. WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email. www.wipro.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: strongswan.conf
Type: application/octet-stream
Size: 653 bytes
Desc: strongswan.conf
URL: <http://lists.strongswan.org/pipermail/users/attachments/20150526/0cd3c118/attachment-0001.obj>
More information about the Users
mailing list