Re: ikev2_resp_create_child_sa: no proposal chosen

2023-02-24 Thread Thomas Bohl
Thanks for your responses. Try adding some non-modp2048 options. Maybe look at the SA installed from the initial negotiation (ipsecctl -vvsa) for ideas. I think this is the right answer. The log tells you what the other side sent: spi=0x0a131729beeb819a: ikev2_log_proposal: ESP #1 ENCR=AES_CB

Re: Learning pure OpenBSD

2023-02-24 Thread latincom
> I agree with Anderson, I don’t see the need for this, especially in > Canada. If we need OpenBSD VMs that we don’t just fire up our own machine, > there are lots of options for OpenBSD VMs for free in Canada, and there > are paid options where the funds come back to the OpenBSD Foundation (ex. >

Re: Learning pure OpenBSD

2023-02-24 Thread latincom
> On Thu, Feb 23, 2023 at 11:38 PM wrote: > >> Hello Misc >> >> I have used OpenBSD, Slackware and Debian for almost 23 years, just as a >> User! But i think that Linux is a Linus Kernel with many app; and >> OpenBSD >> is a complete OS, then the Administration in Linux could be Test and >> Error,

Re: Learning pure OpenBSD

2023-02-24 Thread Duncan Patton a Campbell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Iff you don't have the hardware to spare and want to play with various OBSD (&linuxen) Incarnations, try a cheap cloud service like https://www.vultr.com/ Dhu On Fri, 24 Feb 2023 16:10:28 + Katherine Mcmillan wrote: > I agree with Anderson

Re: Learning pure OpenBSD

2023-02-24 Thread Katherine Mcmillan
I agree with Anderson, I don’t see the need for this, especially in Canada. If we need OpenBSD VMs that we don’t just fire up our own machine, there are lots of options for OpenBSD VMs for free in Canada, and there are paid options where the funds come back to the OpenBSD Foundation (ex. OpenBSD

Re: ikev2_resp_create_child_sa: no proposal chosen

2023-02-24 Thread Stuart Henderson
On 2023/02/24 12:49, Tobias Heider wrote: > On Fri, Feb 24, 2023 at 09:24:29AM -, Stuart Henderson wrote: > > On 2023-02-23, Thomas Bohl wrote: > > > I have several OpenBSD 7.2 connected to a commercial VPN-Router (LANCOM > > > 1781EW+) using iked. It works, except every time the Child SA >

Re: ikev2_resp_create_child_sa: no proposal chosen

2023-02-24 Thread Tobias Heider
On Fri, Feb 24, 2023 at 09:24:29AM -, Stuart Henderson wrote: > On 2023-02-23, Thomas Bohl wrote: > > I have several OpenBSD 7.2 connected to a commercial VPN-Router (LANCOM > > 1781EW+) using iked. It works, except every time the Child SA > > negotiation starts, iked answers NO_PROPOSAL_CHO

Re: Learning pure OpenBSD

2023-02-24 Thread Anders Andersson
On Thu, Feb 23, 2023 at 11:38 PM wrote: > Hello Misc > > I have used OpenBSD, Slackware and Debian for almost 23 years, just as a > User! But i think that Linux is a Linus Kernel with many app; and OpenBSD > is a complete OS, then the Administration in Linux could be Test and > Error, but in Open

Re: ikev2_resp_create_child_sa: no proposal chosen

2023-02-24 Thread Stuart Henderson
On 2023-02-23, Thomas Bohl wrote: > I have several OpenBSD 7.2 connected to a commercial VPN-Router (LANCOM > 1781EW+) using iked. It works, except every time the Child SA > negotiation starts, iked answers NO_PROPOSAL_CHOSEN to the router. Which > leads to closed connections and a new IKE SA n

Re: Disabling .core file generation

2023-02-24 Thread Stuart Henderson
On 2023-02-24, Daniele Bonini wrote: > And I set login.conf adding the following: > > default:\ > .. > :coredumpsize-max=1M:\ > :coredumpsize-cur=1M: That is in blocks not bytes. -- Please keep replies on the mailing list.

Re: Disabling .core file generation

2023-02-24 Thread Crystal Kolipe
On Fri, Feb 24, 2023 at 08:49:59AM +0100, David Demelier wrote: > On Fri, 2023-02-24 at 05:38 +0100, Daniele Bonini wrote: > > Crystal Kolipe wrote: > > > > > > On Mon, Feb 20, 2023 at 05:15:30PM +0100, Daniele Bonini wrote:  > > > > > Is it still possible to disable file .core generation at all