From 8b3d522620e5bbef473b3516cd1f9d0548db2978 Mon Sep 17 00:00:00 2001 From: Andreas Steffen Date: Fri, 3 Jun 2011 08:36:57 +0200 Subject: [PATCH] link to the TNC@FHH project --- testing/tests/tnc/tnccs-11-fhh/description.txt | 4 +++- testing/tests/tnc/tnccs-11-radius-block/description.txt | 5 +++-- testing/tests/tnc/tnccs-11-radius/description.txt | 5 +++-- testing/tests/tnc/tnccs-20-fhh/description.txt | 5 +++-- 4 files changed, 12 insertions(+), 7 deletions(-) diff --git a/testing/tests/tnc/tnccs-11-fhh/description.txt b/testing/tests/tnc/tnccs-11-fhh/description.txt index 2b7545f59..406b163e1 100644 --- a/testing/tests/tnc/tnccs-11-fhh/description.txt +++ b/testing/tests/tnc/tnccs-11-fhh/description.txt @@ -3,7 +3,9 @@ using EAP-TTLS authentication only with the gateway presenting a server certific the clients doing EAP-MD5 password-based authentication. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 1.1 client-server interface. -The Dummy IMC and IMV from the TNC@FHH project are used which communicate over a proprietary protocol. +The Dummy IMC and IMV from the + +TNC@FHH project are used which communicate over a proprietary protocol.

carol passes the health test and dave fails. Based on these measurements the clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets, diff --git a/testing/tests/tnc/tnccs-11-radius-block/description.txt b/testing/tests/tnc/tnccs-11-radius-block/description.txt index 10640649c..d665b1364 100644 --- a/testing/tests/tnc/tnccs-11-radius-block/description.txt +++ b/testing/tests/tnc/tnccs-11-radius-block/description.txt @@ -1,8 +1,9 @@ The roadwarriors carol and dave set up a connection each to gateway moon. At the outset the gateway authenticates itself to the clients by sending an IKEv2 RSA signature accompanied by a certificate. -carol and dave then set up an EAP-TTLS tunnel each via moon to -the FreeRADIUS server alice authenticated by an X.509 AAA certificate. +carol and dave then set up an EAP-TTLS tunnel each via moon to the + +TNC@FHH-enhanced FreeRADIUS server alice authenticated by an X.509 AAA certificate. The strong EAP-TTLS tunnel protects the ensuing weak client authentication based on EAP-MD5. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 1.1 client-server interface. diff --git a/testing/tests/tnc/tnccs-11-radius/description.txt b/testing/tests/tnc/tnccs-11-radius/description.txt index 2d66d3e3e..42651cc8a 100644 --- a/testing/tests/tnc/tnccs-11-radius/description.txt +++ b/testing/tests/tnc/tnccs-11-radius/description.txt @@ -1,8 +1,9 @@ The roadwarriors carol and dave set up a connection each to gateway moon. At the outset the gateway authenticates itself to the clients by sending an IKEv2 RSA signature accompanied by a certificate. -carol and dave then set up an EAP-TTLS tunnel each via moon to -the FreeRADIUS server alice authenticated by an X.509 AAA certificate. +carol and dave then set up an EAP-TTLS tunnel each via moon to the + +TNC@FHH-enhanced FreeRADIUS server alice authenticated by an X.509 AAA certificate. The strong EAP-TTLS tunnel protects the ensuing weak client authentication based on EAP-MD5. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the IF-TNCCS 1.1 client-server interface. diff --git a/testing/tests/tnc/tnccs-20-fhh/description.txt b/testing/tests/tnc/tnccs-20-fhh/description.txt index 798ba0034..e68f363bb 100644 --- a/testing/tests/tnc/tnccs-20-fhh/description.txt +++ b/testing/tests/tnc/tnccs-20-fhh/description.txt @@ -3,8 +3,9 @@ using EAP-TTLS authentication only with the gateway presenting a server certific the clients doing EAP-MD5 password-based authentication. In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the health of carol and dave via the TNCCS 2.0 client-server interface -compliant with RFC 5793 PB-TNC. The Dummy IMC and IMV from the TNC@FHH project are -used which communicate over a proprietary protocol. +compliant with RFC 5793 PB-TNC. The Dummy IMC and IMV from the + +TNC@FHH project are used which communicate over a proprietary protocol.

carol passes the health test and dave fails. Based on these measurements the clients are connected by gateway moon to the "rw-allow" and "rw-isolate" subnets,