1Mon Aug 13 2001 - Fri Aug 17 2001
2$KAME: helsinki-result.jp,v 1.49 2001/08/17 14:33:48 sakane Exp $
3
4
5generic
6	sec* interface($B<u$1B&$@$1$@$1$I$M(B)$B$O$&$^$/F0$/!#$I$N(BSPD entry$B$H(B
7	$B$I$N%$%s%?%U%'!<%9$,4XO"$E$$$F$$$k$N$+CN$k<jCJ$,I,MW(B(PF_KEY
8	API$B$^$?JQ99(B?)$B!#$H$3$m$G!"(Btunnel/transport$B$O(BSPD entry$B$N(Bproperty$B$G$"$k$H(B
9	$B==J,9g0U$5$l$F$$$k$+(B?
10
11	tunnel mode$B$N(Bproposal$BHf3S!#(Bsee F-Secure
12
13	phase 1$B$G$N(BAES/SHA2 support$BMW!#(B(AES$B$OF0:n3NG':Q(B)
14	Q. $B0E9f2=$7$?7k2L$,(BIV$BD9$h$jC;$$>l9g$O!)$=$s$J$N$"$j$($J$$!)(B
15
16	phase 1$B$G80D9$N%M%4$,$G$-$J$$!#(B($B$G$-$k!#4*0c$$$@$C$?(B)
17
18	IPsec$B$G$N(BSHA2 support$B3NG'(B($BE:IU$9$k(Bbit$B?t(B)$B!#(B
19
20	SSH$B<R$+$i(Btoolkit$B$rGc$C$F;H$C$F$$$k$H$3$m$,BgJQB?$$!#$J$s$+(BSSH$B<R$N(B
21	$B$?$a$K(Bbakeoff$B$7$F$$$k$h$&$J5$$,$7$F$-$?!#$H$$$&$+!"(Bipsec$B<+BN(BSSH$B<R$N(B
22	$BMx1W$N$?$a$N%W%m%H%3%k$8$c$J$$$+$H$$$&5$$9$i$7$F$/$k!#J#;($K$9$l$P(B
23	$B$9$k$[$I(BSSH$B<R$OLY$+$k(B... (conspiracy theory)
24
25	id payload$B$KBP$9$k(Bpolicy database$B8!:w$N8+D>$7!#(Bany$B$N>l9g(Bwildcard$B$@$H(B
26	$B;W$C$F8!:w$9$Y$-!#(Bexactly right!!
27
28	phase 2$B$G!"(Bipsec enc mode$B$,$D$$$F$$$J$+$C$?$H$-$N<h$j07$$(B
29	(transport mode$B$H;W$C$F$h$$$N$G$O$J$$$+(B)$B!#(B($B=$@5:Q(B)
30
31	$BD9$$(BKEYMAT$B$N7W;;$N$H$-!"I,MW80D9$N7W;;$K(Bbug$B$"$j(B ($B=$@5:Q(B)
32
33	DH$B8x3+>pJs$O;vA0$K7W;;$7$H$/J}$,$$$$$+$b(B
34
35	subjectAltName$B$H(BID payload$BHf3S$K$D$$$F$h$/9M$($J$$$H>ZL@=q$O;H$($J$$!#(B
36	$B>ZL@=q$rAw$kA0$K!"$I$N(BID$B$r(BsubjectAltName$B$K;H$&$+7h$a$J$$$H$$$1$J$$$+$i!#(B
37
38	ndp$B$r(Bbypass$B$5$;$k%U%i%0$+%]%j%7$,$"$C$?J}$,$$$$$+$b!#(B
39	$B0l1~(Bipsec_setsocket(NULL)$B$O$7$F$$$k!#(Bip6_output()$B$K%U%i%0EO$9(B?
40	$BH~$7$/$J$$(B... (itojun)
41
42
43latest isakmpd on KAME
44	Tue Aug 14 01:42:55 JST 2001
45	isakmpd$B$N(Binterface selection$BIt$rD>$7$?$i(Bphase 1$B$O@.8y$7$?!#(B
46	phase 2$B$,$&$^$/$$$+$J$$LOMM!#B?J,@_DjLdBj!#(B
47
4835:36.982316 130.233.9.166:500 -> 130.233.9.165:500: isakmp 1.0 msgid 00000000: 
49phase 1 ? ident[E]: [encrypted id]
502001-08-13 23:35:36: DEBUG: isakmp.c:402:isakmp_main(): malformed cookie receive
51d or the spi expired.
52
53
54USAGI linux
55	Tue Aug 14 01:42:55 JST 2001
56	$B$J$s$+:#$O$^$C$F$$$k$i$7$$!#(B
57
58	Wed Aug 15 JST
59	ESP 3des, des$B$N(Bmanual key$B$O@.8y(B
60
61	Thu Aug 16 JST
62	$B$H$j$"$($:(Bpluto$B$@$1F0$+$7$?!#(Bphase 2$B$O40N;$9$k$,7k2L$N80$,0c$&!#(B
63
64
65Compaq Tru54 UNIX X5.1B-BL4
66	Tue Aug 14 17:09:18 JST 2001
67	IPv4, ESP, tunnel mode
68	phase 1/2$B$H$b(B3DES + SHA1, group 2
69	phase 1 lifetime = 10min, phase 2 lifetime = 5min
70
71	IPv6, ESP + AH, transport tunnel mode
72	phase 1/2$B$H$b(B3DES + SHA1, group 2
73	phase 1 lifetime = 10min, phase 2 lifetime = 5min
74
75	IPv6, IPComp + ESP + AH, transport mode
76	phase 1/2$B$H$b(B3DES + SHA1 + defalte, group 2
77	phase 1 lifetime = 10min, phase 2 lifetime = 5min
78
79	initiator/responder$B$I$A$i$b$d$C$?!#(B
80
81	Compaq$B$,(Binitiator$B$N>l9g$KLdBj$"$j!#(B
82	Compaq$BB&$O(Bphase 2 lifetime$B$N(Bproposal$B:n$jItJ,$K(Bbug$B$,5o$k$h$&$G!"(B
83	GUI$B$G(B5min$B$H8@$C$F$b(B10min$B$H8@$C$F$/$k(B(phase 1 lifetime$B$NCM$r(B
84	$B%3%T!<$7$F$$$k(B?)$B!#(B
85
86	chargen$BCf$N(Brekey$BEy$b;n$7$?!#LdBj$J$7!#(B
87
88	IPv4 over IPv6/IPv6 over IPv4$B$d$m$&$H8@$o$l$?$,$G$-$:!#(Bsec* transition
89	$B=*$o$C$?$i$d$l$k$+$J!#(B
90
91	$BL@F|(B12:00 RSA signature mode$B$G:F@o(B
92	$B$`$`!"(Bauthentication-failed$B$G<:GT!#$3$C$A$NLdBj$+!)(B
93
94	Fitec$B$H8=>]$O0l=o!#(Bopenssl 0.9.6 $B$r;H$&$HLdBj$J$7!#(B
95	openssl$B$N%P!<%8%g%s2<$2$A$c$C$?$N$G(B
96	ipv6 address as subjectAltName $B$O=PMh$:!#(B
97
98
99Sun
100	Thu Aug 16 16:30 EEST 2001
101	phase1: RSA signature, 3des, sha1, dh5
102	phase2: ESP transport, aes 128, sha1, dh5
103
104	$BLdBj$J$7(B
105
106	Sun$B$O(B phase2$B$N(BAES$B$N80D9$r$D$1$F$J$+$C$?!#(Bdraft$B$K$h$k$H(Bmust$B!#(B
107	racoon$BB&$,(Bdefault$B80D9$r%;%C%H$9$k$h$&$K$7$FBP1~!#(B
108
109
110IBM AIX 5.1
111	Tue Aug 14 17:33:43 JST 2001
112	IPv6 test$B$7$h$&$H8@$o$l$k$b!"@hJ}$N%^%7%s(B($B1s3VCO(B)$B$K(Bglobal address$B$J$7!#(B
113
114	Thu Aug 16 21:00 ESST 2001
115	IPv6$B$@$1(B
116	phase1 pre-shared-key, 3des, sha1, dh2
117	phase2 esp transport, 3des, sha1, pfs2
118	$B:G=i$N(B1$B2s$OLdBj$J$7!#(B
119	phase2 SA$B$r>C$7$F:F%M%4$9$k$H(Bisakmpd$B$,$@$s$^$j$K$J$k!#(B
120	ibm isakmpd $B$KLdBj$"$k$C$]$$!#(B
121
122	san diego$B$G$d$C$?;~$O(B manual $B$@$C$?$+$J!)(B
123		$B$=$&$G$9(B(itojun)
124
125	prasad$B7/$O%$%s%I$K5"$C$F$k$N$GMh$J$$!#(B
126
127F-Secure VPN+ 5.40
128	Tue Aug 14 19:44:15 JST 2001
129	IPv4, ESP, tunnel mode
130	phase 1 3DES + SHA1, group 5, lifetime = 10min
131	phase 2 AES + SHA1, group 5, lifetime = 2min
132
133	IPv4, IPComp + ESP, transport mode
134	phase 1 3DES + SHA1, group 5, lifetime = 10min
135	phase 2 AES + SHA1 + deflate, group 5, lifetime = 2min
136
137	$B$I$A$i$bLdBj$J$7!"(Brekey$B$b(BOK$B!#(B
138
139	IPComp + ESP tunnel mode (IP ESP IPComp IP payload)$B$r$d$m$&$H$7$F(B
140	ipcomp/tunnel//use esp/transport//use$B$H%]%j%7$r=q$$$?$i!"(B
141	IKE phase 2$BE*$K(B
142		$B8~$3$&(B: IPComp tunnel, ESP tunnel
143		$B$3$C$A(B: IPComp tunnel, ESP transport
144	$B$N(Bproposal$B$rHf3S$7$F!"(Bno proposal chosen$B$K$J$k!#$3$C$A$NLdBj(B
145	(bundle$B$N<h$j07$$(B)
146
147	$B$G$C$+$$(BDH group$B!"(Bphase 1 SHA2-256/AES$B$b$G$-$k$i$7$$!#8e$G$d$j$?$$!#(B
148		(modp4096, phase 1 aes $B$O(Bok)
149
150	Fri Aug 17 11:00 EEST 2001
151	phase1: aggressive mode modp4096, aes, sha1, rsa signature
152	phase2: pfs 5, esp tunnel, aes, hmac sha1
153
154	aes for phase1 $B$b(BOK.
155	f-secure$B$O(BsubjectAltName$B$K%"%I%l%9=q$+$J$$$H%Q%1%C%H$@$;$J$$!#(B
156	invalid signature$B$G(Bf-secure$B$KE\$i$l$F<:GT!#860xITL@!#(B
157		-> f-secure$B$O(BsubjectAltName$B$r(B1$B$D$7$+<u$1$D$1$J$$!#(B
158		$B>ZL@=q$r:n$jD>$7$F@.8y!#(B
159
160	DH$B8x3+>pJs$O;vA0$K7W;;$7$H$/J}$,$$$$$+$b(B
161
162SecGo CryptoIP v3
163	Tue Aug 14 21:41:36 JST 2001
164	IPv4, ESP, transport mode
165	phase 1 3DES + SHA1, group 5, lifetime = 10min
166	phase 2 blowfish, group 5, lifetime = 2min
167
168	phase 2 AES$B$b;n$=$&$H$7$?$,<:GT(B(SecGo$BB&$,(B12$B0J30$N(Balgorithm #$B$r(B
169	$B;H$C$F$$$?(B or $B%3%s%Q%$%k$7$F$J$+$C$?(B)$B!#(Brekey$B$b$d$C$F$_$?!#(B
170
171	phase 1 AES$B$b$G$-$k$i$7$$(B(SSH toolkit$B;HMQ(B)$B!#(B
172
173	Wed Aug 15 00:16:35 JST 2001
174	IPv4, ESP, transport mode
175	phase 1 3DES + SHA1, lifetime = 10min
176	phase 2 AES, lifetime = 2min
177
178	tested rekey as well.
179
180Oullim information technologies SECUREWORKS VPN gateway 3.0
181	Tue Aug 14 21:48:36 JST 2001
182	phase 2 AES/blowfish$B$O$I$&$@$M$H%J%s%Q$7$F$_$k$b!"(Bnot ready$B!#(B
183	$BL@F|$+L@8eF|$M$H$N$3$H!#(B
184
185	Wed Aug 15 17:15:09 JST 2001
186	IPv4, ESP, tunnel mode
187	phase 1 3DES + SHA1, group 2, lifetime = 10min
188	phase 2 AES + SHA1, group 2, lifetime = 2min
189
190	$B<:GT!#@hJ}$,(BAES$B$N$H$-$K(BESP ICV check$B$K<:GT$9$k!#(B
191
192	IPv4, ESP, tunnel mode
193	phase 1 3DES + SHA1, group 2, lifetime = 10min
194	phase 2 AES + MD5, group 2, lifetime = 2min
195
196	$B$*$J$8$/<:GT(B
197
198	IPv4, ESP, tunnel mode
199	phase 1 3DES + SHA1, group 2, lifetime = 10min
200	phase 2 3DES + MD5, group 2, lifetime = 2min
201
202	$B@.8y!#(B
203
204	$B@hJ}$,$3$&$$$&$NEj$2$F$/$k$N$G!"$3$C$A$OE\$k(B(id payload$B$N=g=x$,(B
205	$BIaDL$G$O$J$$(B)$B!#(B
206
207>11:59.824877 130.233.10.30:500 -> 130.233.9.166:500: isakmp 1.0 msgid 75973360: phase 2/others ? oakley-quick:
208>    (hash: len=20)
209>    (sa: doi=ipsec situation=identity
210>        (p: #1 protoid=ipsec-esp transform=1 spi=6fd60ca5
211>            (t: #1 id=3des (type=lifetype value=sec)(type=life value=0078)(type=enc mode value=tunnel)(type=auth value=hmac-md5)(type=group desc value=modp1024))))
212>    (nonce: n len=16)
213>    (ke: key len=128)
214>    (id: idtype=IPv4 protoid=0 port=0 len=4 130.233.9.166)
215>    (id: idtype=IPv4net protoid=0 port=0 len=8 192.168.10.0/255.255.255.0)
216
217	Wed Aug 15 18:39:11 JST 2001
218	IPv4, ESP, tunnel mode
219	phase 1 3DES + SHA1, group 2, lifetime = 10min
220	phase 2 AES, group 2, lifetime = 2min
221
222	IKE$BE*$K$OBg>fIW!#(BIPsec$BE*$K$^$@BLL\!#(B
223
224	Wed Aug 15 19:09:05 JST 2001
225	IPv4, ESP, tunnel mode
226	phase 1 3DES + SHA1, group 2, lifetime = 10min
227	phase 2 AES, group 2, lifetime = 2min
228
229	IPv4, ESP, tunnel mode
230	phase 1 3DES + SHA1, group 2, lifetime = 10min
231	phase 2 AES + SHA1, group 2, lifetime = 2min
232
233	$B8~$3$&$,(BAES code$B$r=$@5$7$?!#(BIKE$BE*$K$b(BIPsec$BE*$K$bBg>fIW!#(B
234	rekey$B$b0l1~@.8y(B($B8~$3$&$O(Breal lifetime == soft, real * 1.2 == hard$B$H$+$K(B
235	$B@_Dj$7$F$$$k$N$G$A$g$C$H%X%s$@$C$?$1$I(B)$B!#(B
236
237	Thu Aug 16 22:01:57 JST 2001
238	$B$b$&$$$A$I!#$"$H$O(BID payload$B$N=g=x$@$1!#(B
239
240	Fri Aug 17 02:00 JST$B:"(B
241	$B:FD)@o!#@.8y!#(B
242
243
244Trilogy AdmitOne 2.6
245	Tue Aug 14 21:58:01 JST 2001
246	30$BJ,8e$H8@$o$l$?!#(B
247
248	Wed Aug 15 01:53:42 JST 2001
249	$BL@F|!#(B
250
251	Wed Aug 15 16:09:50 JST 2001
252	IPv4, ESP, transport mode
253	phase 1 3DES + SHA1, group 1, lifetime = 10min
254	phase 2 AES + SHA1, group 1, lifetime = 2min
255
256	Trilogy$BB&$O(BIKE phase 2$B$N(Bkey length$B$,(Bbyte$BC10L$@$H;W$C$F$$$k$i$7$/(B
257	negotiation$B<:GT!#=$@58e:FD)@o!#(B
258
259	Wed Aug 15 17:40:05 JST 2001
260	IPv4, ESP, transport mode
261	phase 1 3DES + SHA1, group 1, lifetime = 10min
262	phase 2 AES + SHA1, group 1, lifetime = 2min
263
264	$B:FD)@o!#$3$A$i$,(Binitiator$B$N$H$-$O$&$^$/$$$/!#$"$A$i$,(Binitiator$B$N(B
265	$B>l9g!"(Bid payload$B$K(Bproto=icmp$B$,Kd$^$C$F$*$j!"$3$A$i$N(Bkernel policy
266	proto=any$B$K(Bmatch$B$;$:(Bno policy found$B$K$J$k!#MW=$@5!#(B
267
268>spdadd 130.233.9.166 130.233.10.167 any -P out ipsec esp/transport//use;
269>spdadd 130.233.10.167 130.233.9.166 any -P in ipsec esp/transport//use;
270
271>35:45.215745 130.233.10.167:500 -> 130.233.9.166:500: isakmp 1.0 msgid dba05304: phase 2/others ? oakley-quick:
272>    (hash: len=20)
273>    (sa: doi=ipsec situation=identity
274>        (p: #1 protoid=ipsec-esp transform=1 spi=dba05304
275>            (t: #1 id=aes (type=lifetype value=sec)(type=life value=7080)(type=lifetype value=kb)(type=life value=2000)(type=
276>group desc value=modp768)(type=enc mode value=transport)(type=auth value=hmac-sha1)(type=keylen value=0080))))
277>    (nonce: n len=64)
278>    (ke: key len=96)
279>    (id: idtype=IPv4 protoid=icmp port=0 len=4 130.233.10.167)
280>    (id: idtype=IPv4 protoid=icmp port=0 len=4 130.233.9.166)
281
282>2001-08-15 17:35:45: DEBUG: isakmp_quick.c:1951:get_proposal_r(): get a src address from ID payload 130.233.10.167[0] prefixlen=32 ul_proto=1
283>2001-08-15 17:35:45: DEBUG: isakmp_quick.c:1956:get_proposal_r(): get dst address from ID payload 130.233.9.166[0] prefixlen=32 ul_proto=1
284>2001-08-15 17:35:45: DEBUG: policy.c:245:cmpspidxwild(): sub:0xbfbfd350: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=icmp dir=in
285>2001-08-15 17:35:45: DEBUG: policy.c:246:cmpspidxwild(): db: 0x80ca408: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=any dir=in
286>2001-08-15 17:35:45: DEBUG: policy.c:245:cmpspidxwild(): sub:0xbfbfd350: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=icmp dir=in
287>2001-08-15 17:35:45: DEBUG: policy.c:246:cmpspidxwild(): db: 0x80ca808: 130.233.9.166/32[0] 130.233.10.167/32[0] proto=any dir=out
288>2001-08-15 17:35:45: ERROR: isakmp_quick.c:1979:get_proposal_r(): no policy found: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=icmp dir=in
289
290
291ZyXEL
292	Tue Aug 14 12:00 ESST 2001
293	phase1 main mode, pre-shared key, des, sha1, dh1
294	phase2 esp, des, sha1, tunnel
295
296	$BLdBj$J$7!#(Bproposal$B$O(B1$B$D$@$1<u$1$D$1$k!#(Brekey$B$O$G$-$J$$!#(B
297
298
299III
300	Tue Aug 14 14:00 ESST 2001
301	phase1 main mode, pre-shared key, 3des, md5, dh2
302	phase2 esp, des, md5, tunnel
303
304	$BLdBj$J$7!#(Bproposal$B$O(B1$BHVL\$r;H$&!#(Brekey$B$O$G$-$J$$!#(B
305	$BBfOQ$N>e;J$K(BKAME$B$H%F%9%H$7$F$3$$$H8@$o$l$?$i$7$$!#(B
306
307
308WindowsXP
309	Tue Aug 14 20:00
310	phase1 main mode, pre-shared key, 3des, sha1, modp3072
311	phase2 esp, 3des, sha1, transport
312
313	modp3072$B$d$m$&$h$H%J%s%Q$5$l$k!#(B
314	dh$B$N7W;;(B: fbsd43 P100MHz$B$GLs(B7(s)
315	          XP P2 200MHz$B$GLs(B9(s)
316
317	$BL@F|M<J}(B RSA signature mode$B$G:F@o!#(B
318
319	$B5"$C$A$c$C$?$N$G$G$-$J$$!#(B
320
321Ashley
322	Tue Aug 14 18:00
323	invalid-signature$B$HJ86g$r8@$o$l$k!#(B
324	$B8_$$$K(B ssh-ca1$B$+$i=pL>$7$F$b$i$C$?$H8@$C$F$k$,!"(B
325	$B<B$O(Btest-ca1.ssh.com$B$H(Bbakeoff-ca1.ssh.com$B$N(B2$B$D$"$k;v$,H=L@!D(B
326
327	test-ca1.ssh.com$B$KE}0l$7$F:F@oM=Ls(B
328
329	Fri Aug 17 10:30
330	Ashley$B<BAu$K(Bpkcs#1 padding$B$NLdBj$"$j!#%M%4$G$-$:!#(B
331
332Netoctave
333	Wed Aug 15 11:00
334	$B$3$C$A$,(B initiate$B$9$k$H(B no-proposal-chosen$B$,5"$C$F$/$k!#(B
335	$BE($+$i(Bping$B$7$F$b$i$&$H(BIKE$B$N%Q%1%C%H$,=P$J$$!#(B
336
337	$B>u673NG'$7$F$b$i$C$F8e$+$i:F@o$9$kM=Dj!#(B
338
339isakmpd (jakob@openbsd)
340	Tue Aug 14
341	IPv4, ESP, transport mode
342	phase 1 3DES + SHA1, group 2, lifetime = 10min
343	phase 2 AES + SHA1, group 2, lifetime = 2min
344
345	$BLdBj$J$7!#(B
346
347	Wed Aug 15 21:25:49 JST 2001
348	IPv6, ESP, tunnel mode
349	phase 1 3DES + SHA1, group 2, lifetime = 10min
350	phase 2 AES + SHA1, group 2, lifetime = 2min
351
352	$B8~$3$&$O(Bmain mode$B$G(BFQDN$B$r(BID$B$K;H$$$?$,$C$?$,!"$3$&$$$&%(%i!<$GE\$i$l$k!#(B
353	sakane$B$O$3$l$O(Bwg$B$G$N9g0U$H;W$C$F$$$k$,!"MW3NG'!#(B
3542001-08-15 21:14:41: ERROR: ipsec_doi.c:3063:ipsecdoi_checkid1(): Expecting IP address type in main mode, but FQDN.
355
356	Fri Aug 17 10:00
357	rsa signature.
358	$BLdBj$J$7!#(B
359
360	isakmpd$B$O(B subjectAltName$B$r(B1$B$D$7$+<u$1$D$1$J$$!#(B
361
362
363Fitec
364	Wed Aug 15 13:00
365	RSA signature
366	invalid-authentication $B$GD7$M$i$l$k!#$$$h$$$h$3$C$A$NLdBj$+(B...
367
368	KeyUsage $B$r(BIKE$B$K$7$H$+$J$$$HE\$i$l$k!#(B
369	$BB>$N<BAu$H$&$^$/$$$+$J$$$N$O!"$3$l$,860x$+!)(B
370	$B$=$&$G$b$J$5$=$&!"(Bopenssl$B$NLdBj$+$b!#(B
371
372	openssl 0.9.6 $B$K$7$?$i@.8y!#0c$$$,J,$+$i$:!#(B
373
374SSH
375	IPv6$B$@$1$d$C$?(B
376
377	ssh solaris version:
378	ssh$BB&(B: IKE$B$N%Q%1%C%H$,=P$J$$!#(B
379	nd cache$B$NLdBj$+!)(B
380		tcp$B$@$1$N%]%j%7$G$b(BIKE$B$N%Q%1%C%H$,=P$;$J$$!#(B
381		solaris$B$O(Bstatic cache entry$BF~$l$k%3%^%s%I$,$J$$$i$7$$!#(B
382		$B0lC6(Bping6$B$7$F(Bcache$B$r:n$C$?5$$K$J$C$F$b(BNS$B$r=P$=$&$H$9$k!#(B
383	$B860xD4::$9$k$+$i:F@o$7$F$M$H8@$o$l$k!#(B
384	$B:F@o(B. $BLdBj$J$7(B
385
386	$BBt;3$N(Bphase2 proposal(43440B$B$N(BUDP$B%Q%1%C%H(B)$B$r<u$1$k$H(B
387	racoon $B$^$G%Q%1%C%H$,>e$,$C$FMh$J$$!#(B
388
389	500 proposal$B$rEj$2$F$/$k!#(Bproposal#$B$O(B1byte$B$J$N$GCF$/$Y$-!#(B
390	racoon$B$O:G=i$KA4It%Q!<%9$7$F$k$_$?$$!#(B
391
392	RSA signature mode
393	ssh$BB&$K(Bpublic key$B7W;;$KLdBj$"$C$?!#D>$7$F(BOK
394	ssh$B$O(Bssh-test-ca1$B$,%5%$%s$7$?>ZL@=q$r;H$$!"(B
395	racoon$B$O(Bfujixerox$B$,%5%$%s$7$?>ZL@=q$G$b(BOK
396
397	AES phase1 $B$,$&$^$/$$$+$J$$!#4V0c$$$J$/(Bracoon$B$NLdBj!#(B($BD>$7$FF0:n3NG':Q(B)
398
399	phase1 proposal$B$N%Q!<%9$KCn$,$$$k$+$b!#MW3NG'(B
400
401freeswan
402	IPv4, IPComp + ESP, transport mode
403	phase 1 3DES + SHA1, group 5, lifetime = 10min
404	phase 2 3DES + SHA1 + deflate, group 5, lifetime = 2min
405
406	IPComp$B$K$OLdBj$J$7!#(B
407
408	$B@hJ}$,(Binitiate$B$7$F$-$?$H$-$KLdBj$"$j!#(Bphase 2$B$G!"(Bipcomp enc mode$B$,(B
409	$BL5;XDj$N>l9g!"(Bipcomp$B$N>l9g$@$1$O(Btransport$B$H;W$o$J$1$l$P$J$i$J$$!#(B
410	$B$,!"(Bracoon$B$O8=>u$3$l$r(BRFC2407$BE*$K(B(Any$B$H$7$F(B)$B<h$j07$&!#$N$G!"(Bno
411	proposal chosen$B$K$J$k!#(B
412	RFC2407$B$+$i$9$k$H!"(Benc mode unspecified == transport$B$G$b$h$$$h$&$J(B
413	$B5$$,$9$k$,(B...  ("host-dependent"$B$C$F=q$$$F$"$k$+$i(B)
414
415RFC2407
416>         Encapsulation Mode
417>           RESERVED                0
418>           Tunnel                  1
419>           Transport               2
420>
421>           Values 3-61439 are reserved to IANA.  Values 61440-65535 are
422>           for private use.
423>
424>           If unspecified, the default value shall be assumed to be
425>           unspecified (host-dependent).
426
427draft-shacham-ippcp-rfc2393bis-08.txt
428>      Encapsulation Mode
429>
430>         To propose a non-default Encapsulation Mode (such as Tunnel
431>         Mode), an IPComp proposal MUST include an Encapsulation Mode
432>         attribute.  If the Encapsulation Mode is unspecified, the
433>         default value of Transport Mode is assumed.
434
435>42:28.211568 130.233.9.175:500 -> 130.233.9.166:500: isakmp 1.0 msgid 6935cbd8: phase 2/others ? oakley-quick:
436>    (hash: len=20)
437>    (sa: doi=ipsec situation=identity
438>        (p: #0 protoid=ipsec-esp transform=2 spi=3a47a3e7
439>            (t: #0 id=3des (type=group desc value=0005)(type=enc mode value=transport)(type=lifetype value=sec)(type=life value=7080)(type=auth value=hmac-md5))
440>            (t: #1 id=3des (type=group desc value=0005)(type=enc mode value=transport)(type=lifetype value=sec)(type=life value=7080)(type=auth value=hmac-sha1)))
441>        (p: #0 protoid=ipcomp transform=1 spi=ac23
442>            (t: #0 id=deflate (type=lifetype value=sec)(type=life value=7080))))
443>    (nonce: n len=16)
444>    (ke: key len=192)
445
446>2001-08-15 16:42:28: DEBUG: ipsec_doi.c:1024:get_ph2approvalx(): peer's single bundle:
447>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto():  (proto_id=ESP spisize=4 spi=3a47a3e7 spi_p=00000000 encmode=Transport reqid=0:0)
448>2001-08-15 16:42:28: DEBUG: proposal.c:848:printsatrns():   (trns_id=3DES encklen=0 authtype=1)
449>2001-08-15 16:42:28: DEBUG: proposal.c:848:printsatrns():   (trns_id=3DES encklen=0 authtype=2)
450>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto():  (proto_id=IPCOMP spisize=2 spi=0000ac23 spi_p=00000000 encmode=Any reqid=0:0)
451>2001-08-15 16:42:28: DEBUG: proposal.c:855:printsatrns():   (trns_id=DEFLATE)
452>2001-08-15 16:42:28: DEBUG: ipsec_doi.c:1027:get_ph2approvalx(): my single bundle:
453>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto():  (proto_id=ESP spisize=4 spi=00000000 spi_p=00000000 encmode=Transport reqid=0:0)
454>2001-08-15 16:42:28: DEBUG: proposal.c:848:printsatrns():   (trns_id=3DES encklen=0 authtype=2)
455>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto():  (proto_id=IPCOMP spisize=4 spi=00000000 spi_p=00000000 encmode=Transport reqid=0:0)
456>2001-08-15 16:42:28: DEBUG: proposal.c:855:printsatrns():   (trns_id=DEFLATE)
457>2001-08-15 16:42:28: ERROR: proposal.c:497:cmpsatrns(): authtype mismatched: my:1 peer:2
458>2001-08-15 16:42:28: ERROR: proposal.c:365:cmpsaprop_alloc(): IPComp SPI size promoted from 16bit to 32bit
459>2001-08-15 16:42:28: ERROR: proposal.c:378:cmpsaprop_alloc(): encmode mismatched: my:2 peer:0			<-----
460
461	Thu Aug 16 16:49:08 JST 2001
462	IPv4, IPComp + ESP, transport mode
463	phase 1 3DES + SHA1, group 5, lifetime = 10min
464	phase 2 3DES + SHA1 + deflate, group 5, lifetime = 2min
465	$B:FD)@o!#=$@5$G$-$?$3$H$r3NG'!#(B
466
467
468netopia
469	Wed Aug 15 19:00 JST$B:"(B
470	IPv6, ESP, transport mode
471	phase 1 3DES + SHA1, group 2, lifetime = 24h
472	phase 2 3DES + SHA1, group 2, lifetime = 1h
473
474	KAME$B%Y!<%9<BAu!#(BCPU$B$,$7$g$\$$$i$7$/(BD-H$B$K(B5$BIC$/$i$$$+$+$C$F$I$-$I$-$9$k!#(B
475	bug report$B$J$I$"$C$?$iAw$C$F$b$i$&$h$&$*4j$$$9$k!#(B
476
477
478Ericsson
479	Wed Aug 15 20:30 JST$B:"(B
480	IPv6, ESP, transport mode
481	phase 1 3DES + SHA1, group 2, lifetime = 24h
482	phase 2 AES + SHA1, group 2, lifetime = 1h
483
484	$B@.8y(B
485
486	IPv6, ESP, transport mode
487	phase 1 3DES + SHA1, group 2, lifetime = 24h
488	phase 2 blowfish + SHA1, group 2, lifetime = 1h
489
490	$B<:GT!#(Bblowfish$B!"$3$C$A$,$o$N80$N@8@.$,$*$+$7$$(B(= $BD9$$80$N>l9g(B)$B!#(B
491
492	IPv6, ESP, transport mode
493	phase 1 3DES + SHA1, group 2, lifetime = 24h
494	phase 2 3DES + SHA1, group 2, lifetime = 1h
495
496	$B<:GT!#(Bericsson$BB&!"(BND$B$,$*$+$7$$!#(B
497
498
499Nokia EPOC
500	Wed Aug 15 20:51:25 JST 2001
501	IPv6, ESP, tunnel mode
502	phase 1 3DES + SHA1, group 2, lifetime = 3600min
503	phase 2 3DES + SHA1 + deflate, group 2, lifetime = 2min
504
505	IPsec key$B$bF~$k$,!"@hJ}$N%]%j%7LdBj$G(Bping$B$OJV$i$J$$!#(B
506
507Trustworks TrustedClient v3.2
508	Thu Aug 16 20:17:51 JST 2001
509	IPv6, AH + ESP, transport mode
510	phase 1 3DES + SHA1, group 5, lifetime = 3min
511	phase 2 3DES + SHA1, group 5, lifetime = 2min
512
513	$B@hJ}$,(Bresponder$B$N$H$-!"808r49$,=*N;$7$?=V4V@hJ}$N(BIKE daemon$B$,(Bpanic$B!#(B
514	$B$^$"808r49<+BN$O$G$-$F$$$k$h$&$@!#(B
515
516
517Nortel GatewayController/CallServer 2000 (not released yet)
518	Fri Aug 17 00:16:23 JST 2001
519	IPv4, ESP, transport mode
520	phase 1 3DES + SHA1, group 5, lifetime = 3min
521	phase 2 AES + SHA1, group 5, lifetime = 2min
522
523	Nortel$BB&(Binitiator: round=10$B$H$$$&(Battribute$B$r$D$1$F$/$k$N$G(Bno proposal
524	chosen
525	KAME$BB&(Binitiator: id payload$BH4$-(B(ip address$B;H$((B)$B$@$H(BNortel$BB&$O(B
526	$B$X$/$k$N$GBLL\(B
527
528	IPv4, ESP, transport mode
529	phase 1 3DES + SHA1, group 5, lifetime = 3min
530	phase 2 3DES + SHA1, group 5, lifetime = 2min
531
532	Nortel$BB&(Binitiator: ok
533	KAME$BB&(Binitiator: id payload$BH4$-$@$H(BNortel$BB&$O$X$/$k$N$GBLL\(B
534