Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec Segfaults with RSA+Xauth (works fine with PSK+Xauth) on i386 :-/

    Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
    9 Posts 4 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      seattle-it
      last edited by

      This one is beyond me.. racoon segfaults every time the client sends back the XAUTH_USER_NAME and XAUTH_USER_PASSWORD when using RSA+Xauth. It does a core dump and game over. Everything is fine with PSK+Xauth.

      Nov 20 19:52:20 pf racoon: 2012-11-19 20:52:20: DEBUG: Attribute XAUTH_USER_NAME, len 9
      Nov 20 19:52:20 pf racoon: 2012-11-19 20:52:20: DEBUG: Attribute XAUTH_USER_PASSWORD, len 14
      Nov 20 19:52:20 pf racoon: 2012-11-19 20:52:20: INFO: Using port 0

      There's nothing useful when running it verbose with -D from the cli either. Anyone else experiencing this?

      Running 2.1-BETA0 (i386) from yesterday (same behavior from a September beta fwiw).

      My tech blog - seattleit.net/blog

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        We've had at least one other report of that, but so far haven't been able to reproduce it here. The other person is actually seeing it crash with PSK+Xauth and not RSA.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • MellowlynxM
          Mellowlynx
          last edited by

          @jimp:

          The other person is actually seeing it crash with PSK+Xauth and not RSA.

          +1 for me, just noticed that I have that problem too :(

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            The very latest snapshot should have a fixed racoon binary (hopefully). Worth another try.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • S
              seattle-it
              last edited by

              @jimp:

              The very latest snapshot should have a fixed racoon binary (hopefully). Worth another try.

              Updated to the latest:

              • PSK+Xauth now segfaults
              • RSA+Xauth now gets me this far before it segfaults…
              
              2012-11-21 17:35:34: DEBUG: Configuration exchange type mode config REPLY
              2012-11-21 17:35:34: DEBUG: Attribute XAUTH_USER_NAME, len 7
              2012-11-21 17:35:34: DEBUG: Attribute XAUTH_USER_PASSWORD, len 15
              2012-11-21 17:35:34: INFO: Using port 0
              2012-11-21 17:35:34: DEBUG: External authentication script starting for user "testing"
              Segmentation fault: 11 (core dumped)
              
              

              My tech blog - seattleit.net/blog

              1 Reply Last reply Reply Quote 0
              • E
                eri--
                last edited by

                Can you retrieve the core file and upload somewhere?
                Also can you make sure the /var/etc/ipsec/ipsec.php is there?

                1 Reply Last reply Reply Quote 0
                • MellowlynxM
                  Mellowlynx
                  last edited by

                  @ermal:

                  Can you retrieve the core file and upload somewhere?
                  Also can you make sure the /var/etc/ipsec/ipsec.php is there?

                  Yep, ipsec.php is there, and other configs there look fine to.
                  Here's my core file: http://files.ivimbu.com/u/?a=d&i=0iu2eGXXFu

                  1 Reply Last reply Reply Quote 0
                  • E
                    eri--
                    last edited by

                    I actually pushed a new fix.
                    Please try with next snapshot.

                    1 Reply Last reply Reply Quote 0
                    • S
                      seattle-it
                      last edited by

                      @ermal:

                      I actually pushed a new fix.
                      Please try with next snapshot.

                      That fixed it!!! Great job ;-)

                      My tech blog - seattleit.net/blog

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.