#773791 network-manager-strongswan: does not seem to support EAP_IDENTITY

Package:
network-manager-strongswan
Source:
network-manager-strongswan
Description:
network management framework (strongSwan plugin)
Submitter:
Julian Gilbey
Date:
2017-10-02 11:39:04 UTC
Severity:
normal
#773791#5
Date:
2014-12-23 10:53:50 UTC
From:
To:
I have tried to connect to my university's VPN, instructions at
http://www.ucs.cam.ac.uk/vpn/generic

I have used the network-manager interface, as described at
https://wiki.strongswan.org/projects/strongswan/wiki/NetworkManager

The VPN connection fails, and this is what syslog reports:

Dec 23 10:44:05 polya dbus[2938]: [system] Activating service name='org.freedesktop.hostname1' (using servicehelper)
Dec 23 10:44:05 polya dbus[2938]: [system] Successfully activated service 'org.freedesktop.hostname1'
Dec 23 10:44:55 polya NetworkManager[12487]: <info> VPN connection 'VPN connection 1' (ConnectInteractive) reply received.
Dec 23 10:44:55 polya charon-nm: 10[CFG] received initiate for NetworkManager connection VPN connection 1
Dec 23 10:44:55 polya charon-nm: 10[CFG] using gateway certificate, identity 'OU=Domain Control Validated, CN=vpn.uis.cam.ac.uk'
Dec 23 10:44:55 polya NetworkManager[12487]: <info> VPN plugin state changed: starting (3)
Dec 23 10:44:55 polya charon-nm: 10[IKE] initiating IKE_SA VPN connection 1[13] to 192.153.213.116
Dec 23 10:44:55 polya charon-nm: 10[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
Dec 23 10:44:55 polya charon-nm: 10[NET] sending packet: from 192.168.0.6[59438] to 192.153.213.116[500] (1024 bytes)
Dec 23 10:44:55 polya NetworkManager[12487]: <info> VPN connection 'VPN connection 1' (Connect) reply received.
Dec 23 10:44:55 polya charon-nm: 03[NET] received packet: from 192.153.213.116[500] to 192.168.0.6[59438] (38 bytes)
Dec 23 10:44:55 polya charon-nm: 03[ENC] parsed IKE_SA_INIT response 0 [ N(INVAL_KE) ]
Dec 23 10:44:55 polya charon-nm: 03[IKE] peer didn't accept DH group MODP_2048, it requested MODP_1024
Dec 23 10:44:55 polya charon-nm: 03[IKE] initiating IKE_SA VPN connection 1[13] to 192.153.213.116
Dec 23 10:44:55 polya charon-nm: 03[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
Dec 23 10:44:55 polya charon-nm: 03[NET] sending packet: from 192.168.0.6[59438] to 192.153.213.116[500] (896 bytes)
Dec 23 10:44:55 polya charon-nm: 06[NET] received packet: from 192.153.213.116[500] to 192.168.0.6[59438] (312 bytes)
Dec 23 10:44:55 polya charon-nm: 06[ENC] parsed IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(MULT_AUTH) ]
Dec 23 10:44:55 polya charon-nm: 06[IKE] local host is behind NAT, sending keep alives
Dec 23 10:44:55 polya charon-nm: 06[IKE] establishing CHILD_SA VPN connection 1
Dec 23 10:44:55 polya charon-nm: 06[ENC] generating IKE_AUTH request 1 [ IDi N(INIT_CONTACT) IDr SA TSi TSr N(MOBIKE_SUP) N(NO_ADD_ADDR) N(MULT_AUTH) N(EAP_ONLY) ]
Dec 23 10:44:55 polya charon-nm: 06[NET] sending packet: from 192.168.0.6[4500] to 192.153.213.116[4500] (364 bytes)
Dec 23 10:44:55 polya charon-nm: 04[NET] received packet: from 192.153.213.116[4500] to 192.168.0.6[4500] (412 bytes)
Dec 23 10:44:55 polya charon-nm: 04[ENC] parsed IKE_AUTH response 1 [ IDr AUTH EAP/REQ/ID ]
Dec 23 10:44:55 polya charon-nm: 04[CFG] no issuer certificate found for "OU=Domain Control Validated, CN=vpn.uis.cam.ac.uk"
Dec 23 10:44:55 polya charon-nm: 04[CFG]   using trusted certificate "OU=Domain Control Validated, CN=vpn.uis.cam.ac.uk"
Dec 23 10:44:55 polya charon-nm: 04[IKE] authentication of 'OU=Domain Control Validated, CN=vpn.uis.cam.ac.uk' with RSA signature successful
Dec 23 10:44:55 polya charon-nm: 04[IKE] server requested EAP_IDENTITY (id 0x00), sending 'jdg18@cam.ac.uk'
Dec 23 10:44:55 polya charon-nm: 04[IKE] EAP_IDENTITY not supported, sending EAP_NAK
Dec 23 10:44:55 polya charon-nm: 04[ENC] generating IKE_AUTH request 2 [ EAP/RES/NAK ]
Dec 23 10:44:55 polya charon-nm: 04[NET] sending packet: from 192.168.0.6[4500] to 192.153.213.116[4500] (76 bytes)
Dec 23 10:44:55 polya charon-nm: 05[NET] received packet: from 192.153.213.116[4500] to 192.168.0.6[4500] (76 bytes)
Dec 23 10:44:55 polya charon-nm: 05[ENC] parsed IKE_AUTH response 2 [ EAP/FAIL ]
Dec 23 10:44:55 polya charon-nm: 05[IKE] received EAP_FAILURE, EAP authentication failed
Dec 23 10:44:55 polya charon-nm: 05[ENC] generating INFORMATIONAL request 3 [ N(AUTH_FAILED) ]
Dec 23 10:44:55 polya charon-nm: 05[NET] sending packet: from 192.168.0.6[4500] to 192.153.213.116[4500] (76 bytes)
Dec 23 10:44:55 polya NetworkManager[12487]: <warn> VPN plugin failed: connect-failed (1)
Dec 23 10:44:55 polya NetworkManager[12487]: <info> VPN plugin state changed: stopped (6)
Dec 23 10:44:55 polya NetworkManager[12487]: <info> VPN plugin state change reason: unknown (0)
Dec 23 10:44:55 polya NetworkManager[12487]: <warn> error disconnecting VPN: Could not process the request because no VPN connection was active.

What might I be doing wrong?

I have libcharon-extra-plugins installed and have not modified any
configuration files beyond the one listed below.

Thanks!

   Julian

#773791#10
Date:
2016-08-02 04:21:42 UTC
From:
To:
Hello Julian,

Please check if libstrongswan-extra-plugins and
libcharon-extra-plugins are installed.

This fixed the problem for me.

Cheers,

sebastian

#773791#15
Date:
2016-10-02 09:01:02 UTC
From:
To:
This seems an upstream bug that should be fixed in text version (which from
the PTS seems to have been just uploaded to unstable):
https://wiki.strongswan.org/issues/1429

The new version has still to propagate to my mirror so I couldn't verify it
yet.

Cheers,

Luca

#773791#20
Date:
2017-09-20 10:16:30 UTC
From:
To:
Hi Julien,

Can you confirm that this problem went away with Stretch?


Regards
Harri

#773791#25
Date:
2017-09-29 13:07:57 UTC
From:
To:
Hi Harald,

I just tried it using strongswan-nm 5.6.0-2 (current Debian testing),
with all other related packages.  It still didn't work; syslog
attached: at 13:59:40 I tried to start the VPN connection, at 14:00:00
I put my password in (I waited 20 seconds so the syslog would be clear).

It doesn't appear that the password is wrong, but who knows?

I don't know whether I'll be able to try again after this weekend, as
our project funding is coming to an end, so I may not have access to
the VPN any longer.  But I may - who knows?

Best wishes,

   Julian

#773791#30
Date:
2017-10-02 10:34:17 UTC
From:
To:
Did you use network-manager-strongswan 1.4.2-1 from Testing as well?

I'm putting Martin and Tobias on CC.

Regards
Harri

#773791#35
Date:
2017-10-02 11:37:34 UTC
From:
To:
It's a fully up-to-date testing machine, so I guess so.  (The machine
is off right now, so I'll be able to check next time I'm on it.)

Best wishes,

   Julian