Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ipsec: T7225: fix IKE DiffieHellmanGroup and ExtendedAuthEnabled in iOS profile #4382

Merged
merged 2 commits into from
Mar 7, 2025

Conversation

c-po
Copy link
Member

@c-po c-po commented Mar 7, 2025

Change summary

Fix dynamic generation of IKE DiffieHellmanGroup in iOS profile

Commit e97d86e (T6617: T6618: vpn ipsec remote-access: fix profile generators) added a bug when working with
DiffieHellmanGroup, it started becoming a boolean and no longer referencing the DH groups itself. This has been fixed.

iOS18+ always requires ExtendedAuthEnabled to be set, if this is unset, loading the iOS VPN profile will error out on the device
giving:

Profile Installation Failed
configuration is invalid:
Missing identity

My first assumption was an empty string in LocalIdentifier for IKE, but turned out only adding this flag solved it.

This was made optional in commit e97d86e (T6617: T6618: vpn ipsec remote-access: fix profile generators) but got reverted now.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Code style update (formatting, renaming)
  • Refactoring (no functional changes)
  • Migration from an old Vyatta component to vyos-1x, please link to related PR inside obsoleted component
  • Other (please describe):

Related Task(s)

Related PR(s)

How to test / Smoketest result

Checklist:

  • I have read the CONTRIBUTING document
  • I have linked this PR to one or more Phabricator Task(s)
  • I have run the components SMOKETESTS if applicable
  • My commit headlines contain a valid Task id
  • My change requires a change to the documentation
  • I have updated the documentation accordingly

c-po added 2 commits March 6, 2025 22:52
If this is unset, loading the iOS VPN profile will error out on the device
giving:

Profile Installation Failed
configuration is invalid:
Missing identity

My first assumption was an empty string in LocalIdentifier for IKE, but turned
out only adding this flag solved it.

This was made optional in commit e97d86e ("T6617: T6618: vpn ipsec
remote-access: fix profile generators") but got reverted now.
… profile

Commit e97d86e ("T6617: T6618: vpn ipsec remote-access: fix profile generators")
added a bug when working with DiffieHellmanGroup, it started becoming a boolead
and no longer referencing the DH groups itself.

This has been fixed.
@c-po c-po requested a review from a team as a code owner March 7, 2025 06:48
Copy link

github-actions bot commented Mar 7, 2025

👍
No issues in PR Title / Commit Title

@c-po c-po changed the title Ipsec ios profile fixes ipsec: T7225: fix IKE DiffieHellmanGroup and ExtendedAuthEnabled in iOS profile Mar 7, 2025
@c-po c-po added bp/sagitta Create automatic backport for sagitta LTS version bp/circinus Create automatic backport for circinus labels Mar 7, 2025
Copy link

github-actions bot commented Mar 7, 2025

CI integration 👍 passed!

Details

CI logs

  • CLI Smoketests (no interfaces) 👍 passed
  • CLI Smoketests (interfaces only) 👍 passed
  • Config tests 👍 passed
  • RAID1 tests 👍 passed
  • TPM tests 👍 passed

@c-po c-po merged commit c65d443 into vyos:current Mar 7, 2025
18 of 19 checks passed
@vyosbot vyosbot added mirror-initiated This PR initiated for mirror sync workflow mirror-completed and removed mirror-initiated This PR initiated for mirror sync workflow labels Mar 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bp/circinus Create automatic backport for circinus bp/sagitta Create automatic backport for sagitta LTS version current mirror-completed
Development

Successfully merging this pull request may close these issues.

4 participants