0s autopkgtest [06:17:24]: starting date and time: 2026-02-03 06:17:24+0000 0s autopkgtest [06:17:24]: git checkout: 4b346b80 nova: make wait_reboot return success even when a no-op 0s autopkgtest [06:17:24]: host juju-7f2275-prod-proposed-migration-environment-2; command line: /home/ubuntu/autopkgtest/runner/autopkgtest --output-dir /tmp/autopkgtest-work.ybrbycxy/out --timeout-copy=6000 --needs-internet=try --setup-commands /home/ubuntu/autopkgtest-cloud/worker-config-production/setup-canonical.sh --apt-pocket=proposed=src:ca-certificates --apt-upgrade libreswan --timeout-short=300 --timeout-copy=20000 --timeout-build=20000 --env=ADT_TEST_TRIGGERS=ca-certificates/20250419build1 -- ssh -s /home/ubuntu/autopkgtest/ssh-setup/nova -- --flavor autopkgtest-cpu2-ram4-disk20-s390x --security-groups autopkgtest-juju-7f2275-prod-proposed-migration-environment-2@sto01-s390x-13.secgroup --name adt-resolute-s390x-libreswan-20260203-061724-juju-7f2275-prod-proposed-migration-environment-2-f74c4111-d049-4c60-87aa-23f7d03f22aa --image adt/ubuntu-resolute-s390x-server --keyname testbed-juju-7f2275-prod-proposed-migration-environment-2 --net-id=net_prod-autopkgtest-workers-s390x -e TERM=linux --mirror=http://ftpmaster.internal/ubuntu/ 3s Creating nova instance adt-resolute-s390x-libreswan-20260203-061724-juju-7f2275-prod-proposed-migration-environment-2-f74c4111-d049-4c60-87aa-23f7d03f22aa from image adt/ubuntu-resolute-s390x-server-20260203.img (UUID 733879ca-10c9-4d0b-9d4a-492c78d47079)... 90s autopkgtest [06:18:54]: testbed dpkg architecture: s390x 90s autopkgtest [06:18:54]: testbed apt version: 3.1.14 90s autopkgtest [06:18:54]: @@@@@@@@@@@@@@@@@@@@ test bed setup 91s autopkgtest [06:18:55]: testbed release detected to be: None 92s autopkgtest [06:18:56]: updating testbed package index (apt update) 92s Get:1 http://ftpmaster.internal/ubuntu resolute-proposed InRelease [124 kB] 92s Hit:2 http://ftpmaster.internal/ubuntu resolute InRelease 93s Hit:3 http://ftpmaster.internal/ubuntu resolute-updates InRelease 93s Hit:4 http://ftpmaster.internal/ubuntu resolute-security InRelease 93s Get:5 http://ftpmaster.internal/ubuntu resolute-proposed/universe Sources [1270 kB] 93s Get:6 http://ftpmaster.internal/ubuntu resolute-proposed/main Sources [269 kB] 93s Get:7 http://ftpmaster.internal/ubuntu resolute-proposed/restricted Sources [5260 B] 93s Get:8 http://ftpmaster.internal/ubuntu resolute-proposed/multiverse Sources [27.8 kB] 93s Get:9 http://ftpmaster.internal/ubuntu resolute-proposed/main s390x Packages [295 kB] 93s Get:10 http://ftpmaster.internal/ubuntu resolute-proposed/universe s390x Packages [1037 kB] 93s Get:11 http://ftpmaster.internal/ubuntu resolute-proposed/multiverse s390x Packages [7580 B] 95s Fetched 3036 kB in 2s (1222 kB/s) 99s Reading package lists... 101s Hit:1 http://ftpmaster.internal/ubuntu resolute-proposed InRelease 101s Hit:2 http://ftpmaster.internal/ubuntu resolute InRelease 101s Hit:3 http://ftpmaster.internal/ubuntu resolute-updates InRelease 101s Hit:4 http://ftpmaster.internal/ubuntu resolute-security InRelease 106s Reading package lists... 107s Reading package lists... 108s Building dependency tree... 108s Reading state information... 110s Calculating upgrade... 110s The following packages will be upgraded: 110s ca-certificates systemd-hwe-hwdb 110s 2 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 110s Need to get 166 kB of archives. 110s After this operation, 1024 B of additional disk space will be used. 110s Get:1 http://ftpmaster.internal/ubuntu resolute-proposed/main s390x ca-certificates all 20250419build1 [163 kB] 110s Get:2 http://ftpmaster.internal/ubuntu resolute/main s390x systemd-hwe-hwdb all 259.0.1 [3152 B] 112s dpkg-preconfigure: unable to re-open stdin: No such file or directory 112s Fetched 166 kB in 0s (1093 kB/s) 113s (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 61953 files and directories currently installed.) 113s Preparing to unpack .../ca-certificates_20250419build1_all.deb ... 113s Unpacking ca-certificates (20250419build1) over (20250419) ... 114s Preparing to unpack .../systemd-hwe-hwdb_259.0.1_all.deb ... 114s Unpacking systemd-hwe-hwdb (259.0.1) over (257.7.1) ... 114s Setting up ca-certificates (20250419build1) ... 124s Updating certificates in /etc/ssl/certs... 129s 0 added, 0 removed; done. 130s Setting up systemd-hwe-hwdb (259.0.1) ... 132s Processing triggers for udev (259-1ubuntu3) ... 134s Processing triggers for man-db (2.13.1-1) ... 135s Processing triggers for ca-certificates (20250419build1) ... 135s Updating certificates in /etc/ssl/certs... 139s 0 added, 0 removed; done. 139s Running hooks in /etc/ca-certificates/update.d... 139s done. 140s autopkgtest [06:19:44]: upgrading testbed (apt dist-upgrade and autopurge) 141s Reading package lists... 142s Building dependency tree... 142s Reading state information... 143s Calculating upgrade... 144s 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 144s Reading package lists... 146s Building dependency tree... 146s Reading state information... 146s Solving dependencies... 147s 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 151s autopkgtest [06:19:55]: testbed running kernel: Linux 6.18.0-9-generic #9-Ubuntu SMP Mon Jan 12 15:39:23 UTC 2026 151s autopkgtest [06:19:55]: @@@@@@@@@@@@@@@@@@@@ apt-source libreswan 155s Get:1 http://ftpmaster.internal/ubuntu resolute/universe libreswan 5.2-2.2ubuntu1 (dsc) [2735 B] 155s Get:2 http://ftpmaster.internal/ubuntu resolute/universe libreswan 5.2-2.2ubuntu1 (tar) [4132 kB] 155s Get:3 http://ftpmaster.internal/ubuntu resolute/universe libreswan 5.2-2.2ubuntu1 (asc) [862 B] 155s Get:4 http://ftpmaster.internal/ubuntu resolute/universe libreswan 5.2-2.2ubuntu1 (diff) [16.7 kB] 155s gpgv: Signature made Thu Jul 31 14:30:12 2025 UTC 155s gpgv: using RSA key 25E3FF2D7F469DBE7D0D4E50AFCFEC8E669CE1C2 155s gpgv: Can't check signature: No public key 155s dpkg-source: warning: cannot verify inline signature for ./libreswan_5.2-2.2ubuntu1.dsc: no acceptable signature found 158s autopkgtest [06:20:02]: testing package libreswan version 5.2-2.2ubuntu1 159s autopkgtest [06:20:03]: build not needed 162s autopkgtest [06:20:06]: test opportunistic: preparing testbed 162s Reading package lists... 162s Building dependency tree... 163s Reading state information... 163s Solving dependencies... 164s The following NEW packages will be installed: 164s dns-root-data libevent-2.1-7t64 libevent-pthreads-2.1-7t64 libldns3t64 164s libnss3-tools libreswan libunbound8 164s 0 upgraded, 7 newly installed, 0 to remove and 0 not upgraded. 164s Need to get 2943 kB of archives. 164s After this operation, 11.8 MB of additional disk space will be used. 164s Get:1 http://ftpmaster.internal/ubuntu resolute/main s390x dns-root-data all 2025080400 [5908 B] 164s Get:2 http://ftpmaster.internal/ubuntu resolute/main s390x libnss3-tools s390x 2:3.120-1 [637 kB] 164s Get:3 http://ftpmaster.internal/ubuntu resolute/main s390x libevent-pthreads-2.1-7t64 s390x 2.1.12-stable-10build1 [8060 B] 164s Get:4 http://ftpmaster.internal/ubuntu resolute/universe s390x libldns3t64 s390x 1.8.4-2build1 [170 kB] 164s Get:5 http://ftpmaster.internal/ubuntu resolute/main s390x libevent-2.1-7t64 s390x 2.1.12-stable-10build1 [144 kB] 164s Get:6 http://ftpmaster.internal/ubuntu resolute/main s390x libunbound8 s390x 1.24.2-1ubuntu1 [464 kB] 164s Get:7 http://ftpmaster.internal/ubuntu resolute/universe s390x libreswan s390x 5.2-2.2ubuntu1 [1515 kB] 165s Fetched 2943 kB in 0s (9527 kB/s) 165s Selecting previously unselected package dns-root-data. 165s (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 61954 files and directories currently installed.) 165s Preparing to unpack .../0-dns-root-data_2025080400_all.deb ... 165s Unpacking dns-root-data (2025080400) ... 165s Selecting previously unselected package libnss3-tools. 165s Preparing to unpack .../1-libnss3-tools_2%3a3.120-1_s390x.deb ... 165s Unpacking libnss3-tools (2:3.120-1) ... 165s Selecting previously unselected package libevent-pthreads-2.1-7t64:s390x. 165s Preparing to unpack .../2-libevent-pthreads-2.1-7t64_2.1.12-stable-10build1_s390x.deb ... 165s Unpacking libevent-pthreads-2.1-7t64:s390x (2.1.12-stable-10build1) ... 165s Selecting previously unselected package libldns3t64:s390x. 165s Preparing to unpack .../3-libldns3t64_1.8.4-2build1_s390x.deb ... 165s Unpacking libldns3t64:s390x (1.8.4-2build1) ... 165s Selecting previously unselected package libevent-2.1-7t64:s390x. 165s Preparing to unpack .../4-libevent-2.1-7t64_2.1.12-stable-10build1_s390x.deb ... 165s Unpacking libevent-2.1-7t64:s390x (2.1.12-stable-10build1) ... 165s Selecting previously unselected package libunbound8:s390x. 165s Preparing to unpack .../5-libunbound8_1.24.2-1ubuntu1_s390x.deb ... 165s Unpacking libunbound8:s390x (1.24.2-1ubuntu1) ... 165s Selecting previously unselected package libreswan. 165s Preparing to unpack .../6-libreswan_5.2-2.2ubuntu1_s390x.deb ... 165s Unpacking libreswan (5.2-2.2ubuntu1) ... 165s Setting up libldns3t64:s390x (1.8.4-2build1) ... 165s Setting up libevent-pthreads-2.1-7t64:s390x (2.1.12-stable-10build1) ... 165s Setting up libevent-2.1-7t64:s390x (2.1.12-stable-10build1) ... 165s Setting up dns-root-data (2025080400) ... 165s Setting up libunbound8:s390x (1.24.2-1ubuntu1) ... 165s Setting up libnss3-tools (2:3.120-1) ... 165s Setting up libreswan (5.2-2.2ubuntu1) ... 166s ipsec.service is a disabled or a static unit, not starting it. 166s Processing triggers for man-db (2.13.1-1) ... 169s Processing triggers for libc-bin (2.42-2ubuntu4) ... 172s autopkgtest [06:20:16]: test opportunistic: [----------------------- 172s ping: oe.libreswan.org: No address associated with hostname 173s autopkgtest [06:20:17]: test opportunistic: -----------------------] 173s opportunistic SKIP exit status 77 and marked as skippable 173s autopkgtest [06:20:17]: test opportunistic: - - - - - - - - - - results - - - - - - - - - - 173s autopkgtest [06:20:17]: test cryptocheck: preparing testbed 192s Creating nova instance adt-resolute-s390x-libreswan-20260203-061724-juju-7f2275-prod-proposed-migration-environment-2-f74c4111-d049-4c60-87aa-23f7d03f22aa from image adt/ubuntu-resolute-s390x-server-20260203.img (UUID 733879ca-10c9-4d0b-9d4a-492c78d47079)... 252s autopkgtest [06:21:36]: testbed dpkg architecture: s390x 253s autopkgtest [06:21:37]: testbed apt version: 3.1.14 253s autopkgtest [06:21:37]: @@@@@@@@@@@@@@@@@@@@ test bed setup 253s autopkgtest [06:21:37]: testbed release detected to be: resolute 254s autopkgtest [06:21:38]: updating testbed package index (apt update) 254s Get:1 http://ftpmaster.internal/ubuntu resolute-proposed InRelease [124 kB] 254s Hit:2 http://ftpmaster.internal/ubuntu resolute InRelease 254s Hit:3 http://ftpmaster.internal/ubuntu resolute-updates InRelease 254s Hit:4 http://ftpmaster.internal/ubuntu resolute-security InRelease 254s Get:5 http://ftpmaster.internal/ubuntu resolute-proposed/multiverse Sources [27.8 kB] 254s Get:6 http://ftpmaster.internal/ubuntu resolute-proposed/universe Sources [1270 kB] 254s Get:7 http://ftpmaster.internal/ubuntu resolute-proposed/restricted Sources [5260 B] 254s Get:8 http://ftpmaster.internal/ubuntu resolute-proposed/main Sources [269 kB] 254s Get:9 http://ftpmaster.internal/ubuntu resolute-proposed/main s390x Packages [295 kB] 254s Get:10 http://ftpmaster.internal/ubuntu resolute-proposed/universe s390x Packages [1037 kB] 255s Get:11 http://ftpmaster.internal/ubuntu resolute-proposed/multiverse s390x Packages [7580 B] 255s Fetched 3036 kB in 1s (2410 kB/s) 259s Reading package lists... 259s Hit:1 http://ftpmaster.internal/ubuntu resolute-proposed InRelease 259s Hit:2 http://ftpmaster.internal/ubuntu resolute InRelease 259s Hit:3 http://ftpmaster.internal/ubuntu resolute-updates InRelease 259s Hit:4 http://ftpmaster.internal/ubuntu resolute-security InRelease 263s Reading package lists... 263s Reading package lists... 263s Building dependency tree... 263s Reading state information... 263s Calculating upgrade... 264s The following packages will be upgraded: 264s ca-certificates systemd-hwe-hwdb 264s 2 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 264s Need to get 166 kB of archives. 264s After this operation, 1024 B of additional disk space will be used. 264s Get:1 http://ftpmaster.internal/ubuntu resolute-proposed/main s390x ca-certificates all 20250419build1 [163 kB] 264s Get:2 http://ftpmaster.internal/ubuntu resolute/main s390x systemd-hwe-hwdb all 259.0.1 [3152 B] 264s dpkg-preconfigure: unable to re-open stdin: No such file or directory 264s Fetched 166 kB in 0s (10.8 MB/s) 264s (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 61953 files and directories currently installed.) 264s Preparing to unpack .../ca-certificates_20250419build1_all.deb ... 264s Unpacking ca-certificates (20250419build1) over (20250419) ... 264s Preparing to unpack .../systemd-hwe-hwdb_259.0.1_all.deb ... 265s Unpacking systemd-hwe-hwdb (259.0.1) over (257.7.1) ... 265s Setting up ca-certificates (20250419build1) ... 274s Updating certificates in /etc/ssl/certs... 277s 0 added, 0 removed; done. 277s Setting up systemd-hwe-hwdb (259.0.1) ... 280s Processing triggers for udev (259-1ubuntu3) ... 282s Processing triggers for man-db (2.13.1-1) ... 283s Processing triggers for ca-certificates (20250419build1) ... 283s Updating certificates in /etc/ssl/certs... 286s 0 added, 0 removed; done. 286s Running hooks in /etc/ca-certificates/update.d... 286s done. 287s autopkgtest [06:22:11]: upgrading testbed (apt dist-upgrade and autopurge) 287s Reading package lists... 287s Building dependency tree... 287s Reading state information... 287s Calculating upgrade... 288s 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 288s Reading package lists... 288s Building dependency tree... 288s Reading state information... 288s Solving dependencies... 290s 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 293s Reading package lists... 293s Building dependency tree... 293s Reading state information... 294s Solving dependencies... 295s The following NEW packages will be installed: 295s dns-root-data libevent-2.1-7t64 libevent-pthreads-2.1-7t64 libldns3t64 295s libnss3-tools libreswan libunbound8 295s 0 upgraded, 7 newly installed, 0 to remove and 0 not upgraded. 295s Need to get 2943 kB of archives. 295s After this operation, 11.8 MB of additional disk space will be used. 295s Get:1 http://ftpmaster.internal/ubuntu resolute/main s390x dns-root-data all 2025080400 [5908 B] 295s Get:2 http://ftpmaster.internal/ubuntu resolute/main s390x libnss3-tools s390x 2:3.120-1 [637 kB] 295s Get:3 http://ftpmaster.internal/ubuntu resolute/main s390x libevent-pthreads-2.1-7t64 s390x 2.1.12-stable-10build1 [8060 B] 295s Get:4 http://ftpmaster.internal/ubuntu resolute/universe s390x libldns3t64 s390x 1.8.4-2build1 [170 kB] 295s Get:5 http://ftpmaster.internal/ubuntu resolute/main s390x libevent-2.1-7t64 s390x 2.1.12-stable-10build1 [144 kB] 295s Get:6 http://ftpmaster.internal/ubuntu resolute/main s390x libunbound8 s390x 1.24.2-1ubuntu1 [464 kB] 295s Get:7 http://ftpmaster.internal/ubuntu resolute/universe s390x libreswan s390x 5.2-2.2ubuntu1 [1515 kB] 296s Fetched 2943 kB in 0s (8760 kB/s) 296s Selecting previously unselected package dns-root-data. 296s (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 61954 files and directories currently installed.) 296s Preparing to unpack .../0-dns-root-data_2025080400_all.deb ... 296s Unpacking dns-root-data (2025080400) ... 296s Selecting previously unselected package libnss3-tools. 296s Preparing to unpack .../1-libnss3-tools_2%3a3.120-1_s390x.deb ... 296s Unpacking libnss3-tools (2:3.120-1) ... 296s Selecting previously unselected package libevent-pthreads-2.1-7t64:s390x. 296s Preparing to unpack .../2-libevent-pthreads-2.1-7t64_2.1.12-stable-10build1_s390x.deb ... 296s Unpacking libevent-pthreads-2.1-7t64:s390x (2.1.12-stable-10build1) ... 296s Selecting previously unselected package libldns3t64:s390x. 296s Preparing to unpack .../3-libldns3t64_1.8.4-2build1_s390x.deb ... 296s Unpacking libldns3t64:s390x (1.8.4-2build1) ... 296s Selecting previously unselected package libevent-2.1-7t64:s390x. 296s Preparing to unpack .../4-libevent-2.1-7t64_2.1.12-stable-10build1_s390x.deb ... 296s Unpacking libevent-2.1-7t64:s390x (2.1.12-stable-10build1) ... 296s Selecting previously unselected package libunbound8:s390x. 296s Preparing to unpack .../5-libunbound8_1.24.2-1ubuntu1_s390x.deb ... 296s Unpacking libunbound8:s390x (1.24.2-1ubuntu1) ... 296s Selecting previously unselected package libreswan. 296s Preparing to unpack .../6-libreswan_5.2-2.2ubuntu1_s390x.deb ... 296s Unpacking libreswan (5.2-2.2ubuntu1) ... 296s Setting up libldns3t64:s390x (1.8.4-2build1) ... 296s Setting up libevent-pthreads-2.1-7t64:s390x (2.1.12-stable-10build1) ... 296s Setting up libevent-2.1-7t64:s390x (2.1.12-stable-10build1) ... 296s Setting up dns-root-data (2025080400) ... 296s Setting up libunbound8:s390x (1.24.2-1ubuntu1) ... 296s Setting up libnss3-tools (2:3.120-1) ... 296s Setting up libreswan (5.2-2.2ubuntu1) ... 297s ipsec.service is a disabled or a static unit, not starting it. 297s Processing triggers for man-db (2.13.1-1) ... 300s Processing triggers for libc-bin (2.42-2ubuntu4) ... 332s autopkgtest [06:22:56]: test cryptocheck: [----------------------- 332s Testing installed binary: /usr/libexec/ipsec/algparse 332s Testing installed binary: /usr/libexec/ipsec/pluto 332s testing -tp 332s ipsec algparse: Encryption algorithms: 332s ipsec algparse: AES_CCM_16 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm, aes_ccm_c 332s ipsec algparse: AES_CCM_12 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm_b 332s ipsec algparse: AES_CCM_8 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm_a 332s ipsec algparse: 3DES_CBC [*192] IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CBC) 3des 332s ipsec algparse: CAMELLIA_CTR {256,192,*128} IKEv1: ESP IKEv2: ESP 332s ipsec algparse: CAMELLIA_CBC {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP NSS(CBC) camellia 332s ipsec algparse: AES_GCM_16 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm, aes_gcm_c 332s ipsec algparse: AES_GCM_12 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm_b 332s ipsec algparse: AES_GCM_8 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm_a 332s ipsec algparse: AES_CTR {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CTR) aesctr 332s ipsec algparse: AES_CBC {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CBC) aes 332s ipsec algparse: NULL_AUTH_AES_GMAC {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_gmac 332s ipsec algparse: NULL [] IKEv1: ESP IKEv2: ESP NULL 332s ipsec algparse: CHACHA20_POLY1305 [*256] IKEv1: IKEv2: IKE ESP NSS(AEAD) chacha20poly1305 332s ipsec algparse: Hash algorithms: 332s ipsec algparse: MD5 IKEv1: IKE IKEv2: NSS 332s ipsec algparse: SHA1 IKEv1: IKE IKEv2: IKE FIPS NSS sha 332s ipsec algparse: SHA2_256 IKEv1: IKE IKEv2: IKE FIPS NSS sha2, sha256 332s ipsec algparse: SHA2_384 IKEv1: IKE IKEv2: IKE FIPS NSS sha384 332s ipsec algparse: SHA2_512 IKEv1: IKE IKEv2: IKE FIPS NSS sha512 332s ipsec algparse: IDENTITY IKEv1: IKEv2: FIPS 332s ipsec algparse: PRF algorithms: 332s ipsec algparse: HMAC_MD5 IKEv1: IKE IKEv2: IKE NSS md5 332s ipsec algparse: HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS NSS sha, sha1 332s ipsec algparse: HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS NSS sha2, sha256, sha2_256 332s ipsec algparse: HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS NSS sha384, sha2_384 332s ipsec algparse: HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS NSS sha512, sha2_512 332s ipsec algparse: AES_XCBC IKEv1: IKEv2: IKE native(XCBC) aes128_xcbc 332s ipsec algparse: Integrity algorithms: 332s ipsec algparse: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH NSS md5, hmac_md5 332s ipsec algparse: HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha, sha1, sha1_96, hmac_sha1 332s ipsec algparse: HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha512, sha2_512, sha2_512_256, hmac_sha2_512 332s ipsec algparse: HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha384, sha2_384, sha2_384_192, hmac_sha2_384 332s ipsec algparse: HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 332s ipsec algparse: HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH 332s ipsec algparse: AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH native(XCBC) aes_xcbc, aes128_xcbc, aes128_xcbc_96 332s ipsec algparse: AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac 332s ipsec algparse: NONE IKEv1: ESP IKEv2: IKE ESP FIPS null 332s ipsec algparse: DH algorithms: 332s ipsec algparse: NONE IKEv1: IKEv2: IKE ESP AH FIPS NSS(MODP) null, dh0 332s ipsec algparse: MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH NSS(MODP) dh5 332s ipsec algparse: MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh14 332s ipsec algparse: MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh15 332s ipsec algparse: MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh16 332s ipsec algparse: MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh17 332s ipsec algparse: MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh18 332s ipsec algparse: DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_256, ecp256 332s ipsec algparse: DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_384, ecp384 332s ipsec algparse: DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_521, ecp521 332s ipsec algparse: DH31 IKEv1: IKE IKEv2: IKE ESP AH NSS(ECP) curve25519 332s ipsec algparse: IPCOMP algorithms: 332s ipsec algparse: DEFLATE IKEv1: ESP AH IKEv2: ESP AH FIPS 332s ipsec algparse: LZS IKEv1: IKEv2: ESP AH FIPS 332s ipsec algparse: LZJH IKEv1: IKEv2: ESP AH FIPS 332s algparse -v2 'esp' (expect SUCCESS) 332s | parsing 'AES_GCM_16_256,AES_GCM_16_128,CHACHA20_POLY1305,AES_CBC_256,AES_CBC_128' for ESP 332s | proposal: 'AES_GCM_16_256' 332s | token: '' '' "AES_GCM_16_256" '' 332s | token: '' "AES_GCM_16_256" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'AES_GCM_16_256' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_256] 332s | appending ESP integrity algorithm NONE[_0] 332s | proposal: 'AES_GCM_16_128' 332s | token: '' '' "AES_GCM_16_128" '' 332s | token: '' "AES_GCM_16_128" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'AES_GCM_16_128' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_128] 332s | appending ESP integrity algorithm NONE[_0] 332s | proposal: 'CHACHA20_POLY1305' 332s | token: '' '' "CHACHA20_POLY1305" '' 332s | token: '' "CHACHA20_POLY1305" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm CHACHA20_POLY1305[_0] 332s | appending ESP integrity algorithm NONE[_0] 332s | proposal: 'AES_CBC_256' 332s | token: '' '' "AES_CBC_256" '' 332s | token: '' "AES_CBC_256" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'AES_CBC_256' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | proposal: 'AES_CBC_128' 332s | token: '' '' "AES_CBC_128" '' 332s | token: '' "AES_CBC_128" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'AES_CBC_128' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s AES_GCM_16_256-NONE 332s AES_GCM_16_128-NONE 332s CHACHA20_POLY1305-NONE 332s AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=' (expect ERROR) 332s ERROR: ESP proposal is empty 332s algparse -v2 'esp=aes' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes;modp2048' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes-sha1' (expect SUCCESS) 332s | parsing '' for ESP 332s | parsing 'aes' for ESP 332s | proposal: 'aes' 332s | token: '' '' "aes" '' 332s | token: '' "aes" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes;modp2048' for ESP 332s | proposal: 'aes;modp2048' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "modp2048" '' 332s | token: ';' "modp2048" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | appending ESP DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s ipsec algparse: ignoring ESP DH algorithm MODP2048 as PFS policy is disabled 332s | parsing 'aes-sha1' for ESP 332s | proposal: 'aes-sha1' 332s | token: '' '' "aes" '-' 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1-modp2048' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-128-sha1' (expect SUCCESS) 332s AES_CBC_128-HMAC_SHA1_96 332s algparse -v2 'esp=aes-128-sha1' (expect SUCCESS) 332s AES_CBC_128-HMAC_SHA1_96 332s algparse -v2 'esp=aes-128-sha1-modp2048' (expect SUCCESS) 332s AES_CBC_128-HMAC_SHA1_96 332s algparse -v2 'esp=aes-128' (expect SUCCESS) 332s AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes_gcm_a-128-null' (expect SUCCESS) 332s AES_GCM_8_128-NONE 332s algparse -v2 'esp=3des-sha1;modp1024' (expect ERROR) 332s ERROR: ESP DH algorithm 'modp1024' is not supported 332s algparse -v2 'esp=3des-sha1;modp1536' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=3des-sha1;modp2048' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=3des-sha1;dh21' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=3des-sha1;ecp_521' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=3des-sha1;dh23' (expect ERROR) 332s ERROR: ESP DH algorithm 'dh23' is not supported 332s algparse -v2 'esp=3des-sha1;dh24' (expect ERROR) 332s ERROR: ESP DH algorithm 'dh24' is not supported 332s algparse -v2 'esp=3des-sha1' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=null-sha1' (expect SUCCESS) 332s NULL-HMAC_SHA1_96 332s algparse -v2 'esp=aes_cbc' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes-sha' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes128-sha1' (expect SUCCESS) 332s AES_CBC_128-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha2' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=aes-sha256' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=aes-sha384' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_384_192 332s algparse -v2 'esp=aes-sha512' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256 332s algparse -v2 'esp=aes128-aes_xcbc' (expect SUCCESS) 332s AES_CBC_128-AES_XCBC_96 332s algparse -v2 'esp=aes192-sha1' (expect SUCCESS) 332s AES_CBC_192-HMAC_SHA1_96 332s algparse -v2 'esp=aes256-sha1' (expect SUCCESS) 332s AES_CBC_256-HMAC_SHA1_96 332s algparse -v2 'esp=aes256-sha' (expect SUCCESS) 332s AES_CBC_256-HMAC_SHA1_96 332s algparse -v2 'esp=aes256-sha2' (expect SUCCESS) 332s AES_CBC_256-HMAC_SHA2_256_128 332s algparse -v2 'esp=aes256-sha2_256' (expect SUCCESS) 332s AES_CBC_256-HMAC_SHA2_256_128 332s algparse -v2 'esp=aes256-sha2_384' (expect SUCCESS) 332s AES_CBC_256-HMAC_SHA2_384_192 332s algparse -v2 'esp=aes256-sha2_512' (expect SUCCESS) 332s AES_CBC_256-HMAC_SHA2_512_256 332s algparse -v2 'esp=camellia' (expect SUCCESS) 332s CAMELLIA_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=camellia128' (expect SUCCESS) 332s CAMELLIA_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=camellia192' (expect SUCCESS) 332s CAMELLIA_CBC_192-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=camellia256' (expect SUCCESS) 332s CAMELLIA_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes_ccm' (expect SUCCESS) 332s AES_CCM_16-NONE 332s algparse -v2 'esp=aes_ccm_a-128-null' (expect SUCCESS) 332s AES_CCM_8_128-NONE 332s algparse -v2 'esp=aes_ccm_a-192-null' (expect SUCCESS) 332s AES_CCM_8_192-NONE 332s algparse -v2 'esp=aes_ccm_a-256-null' (expect SUCCESS) 332s AES_CCM_8_256-NONE 332s algparse -v2 'esp=aes_ccm_b-128-null' (expect SUCCESS) 332s AES_CCM_12_128-NONE 332s algparse -v2 'esp=aes_ccm_b-192-null' (expect SUCCESS) 332s AES_CCM_12_192-NONE 332s algparse -v2 'esp=aes_ccm_b-256-null' (expect SUCCESS) 332s AES_CCM_12_256-NONE 332s algparse -v2 'esp=aes_ccm_c-128-null' (expect SUCCESS) 332s AES_CCM_16_128-NONE 332s algparse -v2 'esp=aes_ccm_c-192-null' (expect SUCCESS) 332s AES_CCM_16_192-NONE 332s algparse -v2 'esp=aes_ccm_c-256-null' (expect SUCCESS) 332s AES_CCM_16_256-NONE 332s algparse -v2 'esp=aes_gcm' (expect SUCCESS) 332s AES_GCM_16-NONE 332s algparse -v2 'esp=aes_gcm_a-128-null' (expect SUCCESS) 332s AES_GCM_8_128-NONE 332s algparse -v2 'esp=aes_gcm_a-192-null' (expect SUCCESS) 332s AES_GCM_8_192-NONE 332s algparse -v2 'esp=aes_gcm_a-256-null' (expect SUCCESS) 332s AES_GCM_8_256-NONE 332s algparse -v2 'esp=aes_gcm_b-128-null' (expect SUCCESS) 332s AES_GCM_12_128-NONE 332s algparse -v2 'esp=aes_gcm_b-192-null' (expect SUCCESS) 332s AES_GCM_12_192-NONE 332s algparse -v2 'esp=aes_gcm_b-256-null' (expect SUCCESS) 332s AES_GCM_12_256-NONE 332s algparse -v2 'esp=aes_gcm_c-128-null' (expect SUCCESS) 332s AES_GCM_16_128-NONE 332s algparse -v2 'esp=aes_gcm_c-192-null' (expect SUCCESS) 332s AES_GCM_16_192-NONE 332s algparse -v2 'esp=aes_gcm_c-256-null' (expect SUCCESS) 332s AES_GCM_16_256-NONE 332s algparse -v2 'esp=aes_ccm_a-null' (expect SUCCESS) 332s AES_CCM_8-NONE 332s algparse -v2 'esp=aes_ccm_b-null' (expect SUCCESS) 332s AES_CCM_12-NONE 332s algparse -v2 'esp=aes_ccm_c-null' (expect SUCCESS) 332s AES_CCM_16-NONE 332s algparse -v2 'esp=aes_gcm_a-null' (expect SUCCESS) 332s AES_GCM_8-NONE 332s algparse -v2 'esp=aes_gcm_b-null' (expect SUCCESS) 332s AES_GCM_12-NONE 332s algparse -v2 'esp=aes_gcm_c-null' (expect SUCCESS) 332s AES_GCM_16-NONE 332s algparse -v2 'esp=aes_ccm-null' (expect SUCCESS) 332s AES_CCM_16-NONE 332s algparse -v2 'esp=aes_gcm-null' (expect SUCCESS) 332s AES_GCM_16-NONE 332s algparse -v2 'esp=aes_ccm-256-null' (expect SUCCESS) 332s AES_CCM_16_256-NONE 332s algparse -v2 'esp=aes_gcm-192-null' (expect SUCCESS) 332s AES_GCM_16_192-NONE 332s algparse -v2 'esp=aes_ccm_256-null' (expect SUCCESS) 332s AES_CCM_16_256-NONE 332s algparse -v2 'esp=aes_gcm_192-null' (expect SUCCESS) 332s AES_GCM_16_192-NONE 332s algparse -v2 'esp=aes_ccm_8-null' (expect SUCCESS) 332s AES_CCM_8-NONE 332s algparse -v2 'esp=aes_ccm_12-null' (expect SUCCESS) 332s AES_CCM_12-NONE 332s algparse -v2 'esp=aes_ccm_16-null' (expect SUCCESS) 332s AES_CCM_16-NONE 332s algparse -v2 'esp=aes_gcm_8-null' (expect SUCCESS) 332s AES_GCM_8-NONE 332s algparse -v2 'esp=aes_gcm_12-null' (expect SUCCESS) 332s AES_GCM_12-NONE 332s algparse -v2 'esp=aes_gcm_16-null' (expect SUCCESS) 332s AES_GCM_16-NONE 332s algparse -v2 'esp=aes_ccm_8-128-null' (expect SUCCESS) 332s AES_CCM_8_128-NONE 332s algparse -v2 'esp=aes_ccm_12-192-null' (expect SUCCESS) 332s AES_CCM_12_192-NONE 332s algparse -v2 'esp=aes_ccm_16-256-null' (expect SUCCESS) 332s AES_CCM_16_256-NONE 332s algparse -v2 'esp=aes_gcm_8-128-null' (expect SUCCESS) 332s AES_GCM_8_128-NONE 332s algparse -v2 'esp=aes_gcm_12-192-null' (expect SUCCESS) 332s AES_GCM_12_192-NONE 332s algparse -v2 'esp=aes_gcm_16-256-null' (expect SUCCESS) 332s AES_GCM_16_256-NONE 332s algparse -v2 'esp=aes_ccm_8_128-null' (expect SUCCESS) 332s AES_CCM_8_128-NONE 332s algparse -v2 'esp=aes_ccm_12_192-null' (expect SUCCESS) 332s AES_CCM_12_192-NONE 332s algparse -v2 'esp=aes_ccm_16_256-null' (expect SUCCESS) 332s AES_CCM_16_256-NONE 332s algparse -v2 'esp=aes_gcm_8_128-null' (expect SUCCESS) 332s AES_GCM_8_128-NONE 332s algparse -v2 'esp=aes_gcm_12_192-null' (expect SUCCESS) 332s AES_GCM_12_192-NONE 332s algparse -v2 'esp=aes_gcm_16_256-null' (expect SUCCESS) 332s AES_GCM_16_256-NONE 332s algparse -v2 'esp=aes_ctr' (expect SUCCESS) 332s AES_CTR-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aesctr' (expect SUCCESS) 332s AES_CTR-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes_ctr128' (expect SUCCESS) 332s AES_CTR_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes_ctr192' (expect SUCCESS) 332s AES_CTR_192-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes_ctr256' (expect SUCCESS) 332s AES_CTR_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=camellia_cbc_256-hmac_sha2_512_256;modp8192' (expect SUCCESS) 332s CAMELLIA_CBC_256-HMAC_SHA2_512_256 332s algparse -v2 'esp=null_auth_aes_gmac_256-null;modp8192' (expect SUCCESS) 332s NULL_AUTH_AES_GMAC_256-NONE 332s algparse -v2 'esp=3des-sha1;modp8192' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=3des-sha1-modp8192' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1,3des-sha1;modp8192' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1-modp8192,3des-sha1-modp8192' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1-modp8192,aes-sha1-modp8192,aes-sha1-modp8192' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes;none' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes;none,aes' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes;none,aes;modp2048' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s AES_CBC-HMAC_SHA2_512_256+HMAC_SHA2_256_128 332s algparse -v2 'esp=aes-sha1-none' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=aes-sha1;none' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96 332s algparse -v2 'esp=3des168-sha1' (expect ERROR) 332s ERROR: ESP encryption algorithm 3DES_CBC does not allow a key lengths 332s algparse -v2 'esp=3des-null' (expect ERROR) 332s ERROR: non-AEAD ESP encryption algorithm 3DES_CBC cannot have 'NONE' as the integrity algorithm 332s algparse -v2 'esp=aes128-null' (expect ERROR) 332s ERROR: non-AEAD ESP encryption algorithm AES_CBC cannot have 'NONE' as the integrity algorithm 332s algparse -v2 'esp=aes224-sha1' (expect ERROR) 332s ERROR: ESP encryption algorithm AES_CBC with key length 224 invalid; valid key lengths: 128, 192, 256 332s algparse -v2 'esp=aes-224-sha1' (expect ERROR) 332s ERROR: ESP encryption algorithm AES_CBC with key length 224 invalid; valid key lengths: 128, 192, 256 332s algparse -v2 'esp=aes0-sha1' (expect ERROR) 332s ERROR: ESP encryption key length is zero 332s algparse -v2 'esp=aes-0-sha1' (expect ERROR) 332s ERROR: ESP encryption key length is zero 332s algparse -v2 'esp=aes512-sha1' (expect ERROR) 332s ERROR: ESP encryption algorithm AES_CBC with key length 512 invalid; valid key lengths: 128, 192, 256 332s algparse -v2 'esp=aes-sha1555' (expect ERROR) 332s ERROR: ESP integrity algorithm 'sha1555' is not recognized 332s algparse -v2 'esp=camellia666-sha1' (expect ERROR) 332s ERROR: ESP encryption algorithm CAMELLIA_CBC with key length 666 invalid; valid key lengths: 128, 192, 256 332s algparse -v2 'esp=blowfish' (expect ERROR) 332s ERROR: ESP encryption algorithm 'blowfish' is not supported 332s algparse -v2 'esp=des-sha1' (expect ERROR) 332s ERROR: ESP encryption algorithm 'des' is not supported 332s algparse -v2 'esp=aes_ctr666' (expect ERROR) 332s ERROR: ESP encryption algorithm AES_CTR with key length 666 invalid; valid key lengths: 128, 192, 256 332s algparse -v2 'esp=aes128-sha2_128' (expect ERROR) 332s ERROR: ESP integrity algorithm 'sha2_128' is not recognized 332s algparse -v2 'esp=aes256-sha2_256-4096' (expect ERROR) 332s ERROR: ESP DH algorithm '4096' is not recognized 332s algparse -v2 'esp=aes256-sha2_256-128' (expect ERROR) 332s ERROR: ESP DH algorithm '128' is not recognized 332s algparse -v2 'esp=vanitycipher' (expect ERROR) 332s ERROR: ESP encryption algorithm 'vanitycipher' is not recognized 332s algparse -v2 'esp=ase-sah' (expect ERROR) 332s ERROR: ESP encryption algorithm 'ase' is not recognized 332s algparse -v2 'esp=aes-sah1' (expect ERROR) 332s ERROR: ESP integrity algorithm 'sah1' is not recognized 332s algparse -v2 'esp=id3' (expect ERROR) 332s ERROR: ESP encryption algorithm 'id3' is not recognized 332s algparse -v2 'esp=aes-id3' (expect ERROR) 332s ERROR: ESP integrity algorithm 'id3' is not recognized 332s algparse -v2 'esp=aes_gcm-md5' (expect ERROR) 332s ERROR: AEAD ESP encryption algorithm AES_GCM_16 must have 'NONE' as the integrity algorithm 332s algparse -v2 'esp=mars' (expect ERROR) 332s ERROR: ESP encryption algorithm 'mars' is not supported 332s algparse -v2 'esp=aes_gcm-16' (expect ERROR) 332s ERROR: ESP encryption algorithm AES_GCM_16 with key length 16 invalid; valid key lengths: 128, 192, 256 332s algparse -v2 'esp=aes_gcm-0' (expect ERROR) 332s ERROR: ESP encryption key length is zero 332s algparse -v2 'esp=aes_gcm-123456789012345' (expect ERROR) 332s ERROR: ESP encryption algorithm 'aes_gcm-123456789012345' key length WAY too big 332s algparse -v2 'esp=3des-sha1;dh22' (expect ERROR) 332s ERROR: ESP DH algorithm 'dh22' is not supported 332s algparse -v2 'esp=3des-sha1;modp8192,3des-sha2' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=3des-sha1-modp8192,3des-sha2' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=3des-sha1-modp8192,3des-sha2-modp8192' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=3des-sha1-modp8192,3des-sha2;modp8192' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=3des-sha1;modp8192,3des-sha2-modp8192' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=3des-sha1;modp8192,3des-sha2;modp8192' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'esp=3des-sha1-modp8192,3des-sha2-modp2048' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1_96 332s 3DES_CBC-HMAC_SHA2_256_128 332s algparse -v2 'ah' (expect SUCCESS) 332s HMAC_SHA2_512_256 332s HMAC_SHA2_256_128 332s algparse -v2 'ah=' (expect ERROR) 332s ERROR: AH proposal is empty 332s algparse -v2 'ah=md5' (expect SUCCESS) 332s HMAC_MD5_96 332s algparse -v2 'ah=sha' (expect SUCCESS) 332s HMAC_SHA1_96 332s algparse -v2 'ah=sha;modp2048' (expect SUCCESS) 332s HMAC_SHA1_96 332s algparse -v2 'ah=sha1' (expect SUCCESS) 332s HMAC_SHA1_96 332s algparse -v2 'ah=sha2' (expect SUCCESS) 332s HMAC_SHA2_256_128 332s algparse -v2 'ah=sha256' (expect SUCCESS) 332s HMAC_SHA2_256_128 332s algparse -v2 'ah=sha384' (expect SUCCESS) 332s HMAC_SHA2_384_192 332s algparse -v2 'ah=sha512' (expect SUCCESS) 332s HMAC_SHA2_512_256 332s algparse -v2 'ah=sha2_256' (expect SUCCESS) 332s HMAC_SHA2_256_128 332s algparse -v2 'ah=sha2_384' (expect SUCCESS) 332s HMAC_SHA2_384_192 332s algparse -v2 'ah=sha2_512' (expect SUCCESS) 332s HMAC_SHA2_512_256 332s algparse -v2 'ah=aes_xcbc' (expect SUCCESS) 332s AES_XCBC_96 332s algparse -v2 'ah=sha2-none' (expect SUCCESS) 332s HMAC_SHA2_256_128 332s algparse -v2 'ah=sha2;none' (expect SUCCESS) 332s HMAC_SHA2_256_128 332s algparse -v2 'ah=sha1-modp8192,sha1-modp8192,sha1-modp8192' (expect SUCCESS) 332s HMAC_SHA1_96 332s algparse -v2 'ah=aes-sha1' (expect ERROR) 332s ERROR: AH integrity algorithm 'aes' is not recognized 332s algparse -v2 'ah=vanityhash1' (expect ERROR) 332s ERROR: AH integrity algorithm 'vanityhash1' is not recognized 332s algparse -v2 'ah=aes_gcm_c-256' (expect ERROR) 332s ERROR: AH integrity algorithm 'aes_gcm_c' is not recognized 332s algparse -v2 'ah=id3' (expect ERROR) 332s ERROR: AH integrity algorithm 'id3' is not recognized 332s algparse -v2 'ah=3des' (expect ERROR) 332s ERROR: AH integrity algorithm '3des' is not recognized 332s algparse -v2 'ah=null' (expect ERROR) 332s ERROR: AH cannot have 'none' as the integrity algorithm 332s algparse -v2 'ah=aes_gcm' (expect ERROR) 332s ERROR: AH integrity algorithm 'aes_gcm' is not recognized 332s algparse -v2 'ah=aes_ccm' (expect ERROR) 332s ERROR: AH integrity algorithm 'aes_ccm' is not recognized 332s algparse -v2 'ah=ripemd' (expect ERROR) 332s ERROR: AH integrity algorithm 'ripemd' is not recognized 332s algparse -v2 'ike' (expect SUCCESS) 332s AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s CHACHA20_POLY1305-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=' (expect ERROR) 332s ERROR: IKE proposal is empty 332s algparse -v2 'ike=3des-sha1' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=3des-sha1' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=3des-sha1;modp1536' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1-MODP1536 332s algparse -v2 'ike=3des;dh21' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA2_512+HMAC_SHA2_256-DH21 332s algparse -v2 'ike=3des-sha1;dh21' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1-DH21 332s algparse -v2 'ike=3des-sha1-ecp_521' (expect SUCCESS) 332s 3DES_CBC-HMAC_SHA1-DH21 332s algparse -v2 'ike=3des+aes' (expect SUCCESS) 332s 3DES_CBC+AES_CBC-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes;none' (expect ERROR) 332s ERROR: IKE DH algorithm 'none' not permitted 332s algparse -v2 'ike=id2' (expect ERROR) 332s ERROR: IKE encryption algorithm 'id2' is not recognized 332s algparse -v2 'ike=3des-id2' (expect ERROR) 332s ERROR: IKE PRF algorithm 'id2' is not recognized 332s algparse -v2 'ike=aes_ccm' (expect ERROR) 332s ERROR: IKE encryption algorithm 'aes_ccm' is not supported 332s algparse -v2 'ike=aes-sha1-sha2-ecp_521' (expect ERROR) 332s ERROR: IKE DH algorithm 'sha2' is not recognized 332s algparse -v2 'ike=aes-sha2-sha2;ecp_521' (expect ERROR) 332s ERROR: IKE DH algorithm 'sha2' is not recognized 332s algparse -v2 'ike=aes-sha1_96-sha2-ecp_521' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96-HMAC_SHA2_256-DH21 332s algparse -v2 'ike=aes-sha1_96-sha2;ecp_521' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1_96-HMAC_SHA2_256-DH21 332s algparse -v2 'ike=aes+aes-sha1+sha1-modp8192+modp8192' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1-MODP8192 332s algparse -v2 'ike=3des+aes+aes-sha2+sha1+sha1-modp4096+modp8192+modp8192' (expect SUCCESS) 332s 3DES_CBC+AES_CBC-HMAC_SHA2_256+HMAC_SHA1-MODP4096+MODP8192 332s algparse -v2 'ike=aes+3des+aes-sha1+sha2+sha1-modp8192+modp4096+modp8192' (expect SUCCESS) 332s AES_CBC+3DES_CBC-HMAC_SHA1+HMAC_SHA2_256-MODP8192+MODP4096 332s algparse -v2 'ike=aes+aes+3des-sha1+sha1+sha2-modp8192+modp8192+modp4096' (expect SUCCESS) 332s AES_CBC+3DES_CBC-HMAC_SHA1+HMAC_SHA2_256-MODP8192+MODP4096 332s algparse -v2 'ike=aes+aes128+aes256' (expect SUCCESS) 332s AES_CBC-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes128+aes+aes256' (expect SUCCESS) 332s AES_CBC_128+AES_CBC-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes128+aes256+aes' (expect SUCCESS) 332s AES_CBC_128+AES_CBC_256+AES_CBC-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes-sha1-modp8192,aes-sha1-modp8192,aes-sha1-modp8192' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1-MODP8192 332s algparse -v2 'ike=aes-sha1-modp8192,aes-sha2-modp8192,aes-sha1-modp8192' (expect SUCCESS) 332s AES_CBC-HMAC_SHA1-MODP8192 332s AES_CBC-HMAC_SHA2_256-MODP8192 332s algparse -v2 'ike=aes_gcm' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes_gcm-sha2' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes_gcm-sha2-modp2048' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_256-MODP2048 332s algparse -v2 'ike=aes_gcm-sha2;modp2048' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_256-MODP2048 332s algparse -v2 'ike=aes_gcm-modp2048' (expect ERROR) 332s ERROR: IKE PRF algorithm 'modp2048' is not recognized 332s algparse -v2 'ike=aes_gcm;modp2048' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048 332s algparse -v2 'ike=aes_gcm-none' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_512+HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes_gcm-none-sha2' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_256-DH19+DH20+DH21+DH31+MODP4096+MODP3072+MODP2048+MODP8192 332s algparse -v2 'ike=aes_gcm-none-sha2-modp2048' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_256-MODP2048 332s algparse -v2 'ike=aes_gcm-none-sha2;modp2048' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_256-MODP2048 332s algparse -v2 'ike=aes_gcm-none-modp2048' (expect ERROR) 332s ERROR: IKE PRF algorithm 'modp2048' is not recognized 332s algparse -v2 'ike=aes_gcm-none;modp2048' (expect SUCCESS) 332s AES_GCM_16-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048 332s algparse -v2 'ike=aes_gcm-sha1-none-modp2048' (expect ERROR) 332s ERROR: IKE proposal contains unexpected 'modp2048' 332s algparse -v2 'ike=aes_gcm-sha1-none;modp2048' (expect ERROR) 332s ERROR: IKE proposal contains unexpected 'modp2048' 332s algparse -v2 'ike=aes+aes_gcm' (expect ERROR) 332s ERROR: AEAD and non-AEAD IKE encryption algorithm cannot be combined 332s algparse -v2 'ike=,' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes,' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes,,aes' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=,aes' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=-' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=+' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=;' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes-' (expect ERROR) 332s ERROR: IKE PRF algorithm is empty 332s algparse -v2 'ike=aes+' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes;' (expect ERROR) 332s ERROR: IKE DH algorithm is empty 332s algparse -v2 'ike=-aes' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=+aes' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=;aes' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes+-' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes+;' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s algparse -v2 'ike=aes++' (expect ERROR) 332s ERROR: IKE encryption algorithm is empty 332s | token: '' "aes" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha1' for ESP 332s | proposal: 'aes-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha1-modp2048' for ESP 332s | proposal: 'aes-sha1-modp2048' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp2048" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp2048" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP2048 as PFS policy is disabled 332s | parsing 'aes-128-sha1' for ESP 332s | proposal: 'aes-128-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "128" '-' 332s | token: '-' "128" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes-128-sha1' for ESP 332s | proposal: 'aes-128-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "128" '-' 332s | token: '-' "128" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes-128-sha1-modp2048' for ESP 332s | proposal: 'aes-128-sha1-modp2048' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "128" '-' 332s | token: '-' "128" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp2048" '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp2048" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP2048 as PFS policy is disabled 332s | parsing 'aes-128' for ESP 332s | proposal: 'aes-128' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "128" '' 332s | token: '-' "128" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes_gcm_a-128-null' for ESP 332s | proposal: 'aes_gcm_a-128-null' 332s | token: '' '' "aes_gcm_a" '-' 332s | token: '' "aes_gcm_a" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing '3des-sha1;modp1024' for ESP 332s | proposal: '3des-sha1;modp1024' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp1024" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp1024" '' '' 332s | parsing dh: 332s | ike_alg_byname() failed: ESP DH algorithm 'modp1024' is not supported 332s | lookup for DH algorithm 'modp1024' failed 332s | ... failed 'ESP DH algorithm 'modp1024' is not supported' 332s | parsing '3des-sha1;modp1536' for ESP 332s | proposal: '3des-sha1;modp1536' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp1536" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp1536" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP1536[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP1536 as PFS policy is disabled 332s | parsing '3des-sha1;modp2048' for ESP 332s | proposal: '3des-sha1;modp2048' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp2048" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp2048" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP2048 as PFS policy is disabled 332s | parsing '3des-sha1;dh21' for ESP 332s | proposal: '3des-sha1;dh21' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "dh21" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "dh21" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm DH21[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm DH21 as PFS policy is disabled 332s | parsing '3des-sha1;ecp_521' for ESP 332s | proposal: '3des-sha1;ecp_521' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "ecp_521" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "ecp_521" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm DH21[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm DH21 as PFS policy is disabled 332s | parsing '3des-sha1;dh23' for ESP 332s | proposal: '3des-sha1;dh23' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "dh23" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "dh23" '' '' 332s | parsing dh: 332s | ike_alg_byname() failed: ESP DH algorithm 'dh23' is not supported 332s | lookup for DH algorithm 'dh23' failed 332s | ... failed 'ESP DH algorithm 'dh23' is not supported' 332s | parsing '3des-sha1;dh24' for ESP 332s | proposal: '3des-sha1;dh24' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "dh24" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "dh24" '' '' 332s | parsing dh: 332s | ike_alg_byname() failed: ESP DH algorithm 'dh24' is not supported 332s | lookup for DH algorithm 'dh24' failed 332s | ... failed 'ESP DH algorithm 'dh24' is not supported' 332s | parsing '3des-sha1' for ESP 332s | proposal: '3des-sha1' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'null-sha1' for ESP 332s | proposal: 'null-sha1' 332s | token: '' '' "null" '-' 332s | token: '' "null" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm NULL[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes_cbc' for ESP 332s | proposal: 'aes_cbc' 332s | token: '' '' "aes_cbc" '' 332s | token: '' "aes_cbc" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes-sha' for ESP 332s | proposal: 'aes-sha' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha" '' 332s | token: '-' "sha" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha1' for ESP 332s | proposal: 'aes-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes128-sha1' for ESP 332s | proposal: 'aes128-sha1' 332s | token: '' '' "aes128" '-' 332s | token: '' "aes128" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes128' is not recognized 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha2' for ESP 332s | proposal: 'aes-sha2' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha2" '' 332s | token: '-' "sha2" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha256' for ESP 332s | proposal: 'aes-sha256' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha256" '' 332s | token: '-' "sha256" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha384' for ESP 332s | proposal: 'aes-sha384' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha384" '' 332s | token: '-' "sha384" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_384_192[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha512' for ESP 332s | proposal: 'aes-sha512' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha512" '' 332s | token: '-' "sha512" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | token: '' '' '' 332s | parsing 'aes128-aes_xcbc' for ESP 332s | proposal: 'aes128-aes_xcbc' 332s | token: '' '' "aes128" '-' 332s | token: '' "aes128" '-' "aes_xcbc" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes128' is not recognized 332s | token: '-' "aes_xcbc" '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm AES_XCBC_96[_0] 332s | token: '' '' '' 332s | parsing 'aes192-sha1' for ESP 332s | proposal: 'aes192-sha1' 332s | token: '' '' "aes192" '-' 332s | token: '' "aes192" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes192' is not recognized 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes256-sha1' for ESP 332s | proposal: 'aes256-sha1' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes256-sha' for ESP 332s | proposal: 'aes256-sha' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha" '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'aes256-sha2' for ESP 332s | proposal: 'aes256-sha2' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha2" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha2" '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'aes256-sha2_256' for ESP 332s | proposal: 'aes256-sha2_256' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha2_256" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha2_256" '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'aes256-sha2_384' for ESP 332s | proposal: 'aes256-sha2_384' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha2_384" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha2_384" '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_384_192[_0] 332s | token: '' '' '' 332s | parsing 'aes256-sha2_512' for ESP 332s | proposal: 'aes256-sha2_512' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha2_512" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha2_512" '' '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | token: '' '' '' 332s | parsing 'camellia' for ESP 332s | proposal: 'camellia' 332s | token: '' '' "camellia" '' 332s | token: '' "camellia" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm CAMELLIA_CBC[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'camellia128' for ESP 332s | proposal: 'camellia128' 332s | token: '' '' "camellia128" '' 332s | token: '' "camellia128" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'camellia128' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm CAMELLIA_CBC[_128] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'camellia192' for ESP 332s | proposal: 'camellia192' 332s | token: '' '' "camellia192" '' 332s | token: '' "camellia192" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'camellia192' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm CAMELLIA_CBC[_192] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'camellia256' for ESP 332s | proposal: 'camellia256' 332s | token: '' '' "camellia256" '' 332s | token: '' "camellia256" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'camellia256' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm CAMELLIA_CBC[_256] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes_ccm' for ESP 332s | proposal: 'aes_ccm' 332s | token: '' '' "aes_ccm" '' 332s | token: '' "aes_ccm" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_0] 332s | appending ESP integrity algorithm NONE[_0] 332s | parsing 'aes_ccm_a-128-null' for ESP 332s | proposal: 'aes_ccm_a-128-null' 332s | token: '' '' "aes_ccm_a" '-' 332s | token: '' "aes_ccm_a" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_a-192-null' for ESP 332s | proposal: 'aes_ccm_a-192-null' 332s | token: '' '' "aes_ccm_a" '-' 332s | token: '' "aes_ccm_a" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_a-256-null' for ESP 332s | proposal: 'aes_ccm_a-256-null' 332s | token: '' '' "aes_ccm_a" '-' 332s | token: '' "aes_ccm_a" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_b-128-null' for ESP 332s | proposal: 'aes_ccm_b-128-null' 332s | token: '' '' "aes_ccm_b" '-' 332s | token: '' "aes_ccm_b" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_b-192-null' for ESP 332s | proposal: 'aes_ccm_b-192-null' 332s | token: '' '' "aes_ccm_b" '-' 332s | token: '' "aes_ccm_b" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_b-256-null' for ESP 332s | proposal: 'aes_ccm_b-256-null' 332s | token: '' '' "aes_ccm_b" '-' 332s | token: '' "aes_ccm_b" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_c-128-null' for ESP 332s | proposal: 'aes_ccm_c-128-null' 332s | token: '' '' "aes_ccm_c" '-' 332s | token: '' "aes_ccm_c" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_c-192-null' for ESP 332s | proposal: 'aes_ccm_c-192-null' 332s | token: '' '' "aes_ccm_c" '-' 332s | token: '' "aes_ccm_c" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_c-256-null' for ESP 332s | proposal: 'aes_ccm_c-256-null' 332s | token: '' '' "aes_ccm_c" '-' 332s | token: '' "aes_ccm_c" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm' for ESP 332s | proposal: 'aes_gcm' 332s | token: '' '' "aes_gcm" '' 332s | token: '' "aes_gcm" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_0] 332s | appending ESP integrity algorithm NONE[_0] 332s | parsing 'aes_gcm_a-128-null' for ESP 332s | proposal: 'aes_gcm_a-128-null' 332s | token: '' '' "aes_gcm_a" '-' 332s | token: '' "aes_gcm_a" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_a-192-null' for ESP 332s | proposal: 'aes_gcm_a-192-null' 332s | token: '' '' "aes_gcm_a" '-' 332s | token: '' "aes_gcm_a" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_a-256-null' for ESP 332s | proposal: 'aes_gcm_a-256-null' 332s | token: '' '' "aes_gcm_a" '-' 332s | token: '' "aes_gcm_a" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_b-128-null' for ESP 332s | proposal: 'aes_gcm_b-128-null' 332s | token: '' '' "aes_gcm_b" '-' 332s | token: '' "aes_gcm_b" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_b-192-null' for ESP 332s | proposal: 'aes_gcm_b-192-null' 332s | token: '' '' "aes_gcm_b" '-' 332s | token: '' "aes_gcm_b" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_b-256-null' for ESP 332s | proposal: 'aes_gcm_b-256-null' 332s | token: '' '' "aes_gcm_b" '-' 332s | token: '' "aes_gcm_b" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_c-128-null' for ESP 332s | proposal: 'aes_gcm_c-128-null' 332s | token: '' '' "aes_gcm_c" '-' 332s | token: '' "aes_gcm_c" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_c-192-null' for ESP 332s | proposal: 'aes_gcm_c-192-null' 332s | token: '' '' "aes_gcm_c" '-' 332s | token: '' "aes_gcm_c" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_c-256-null' for ESP 332s | proposal: 'aes_gcm_c-256-null' 332s | token: '' '' "aes_gcm_c" '-' 332s | token: '' "aes_gcm_c" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_a-null' for ESP 332s | proposal: 'aes_ccm_a-null' 332s | token: '' '' "aes_ccm_a" '-' 332s | token: '' "aes_ccm_a" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_b-null' for ESP 332s | proposal: 'aes_ccm_b-null' 332s | token: '' '' "aes_ccm_b" '-' 332s | token: '' "aes_ccm_b" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_c-null' for ESP 332s | proposal: 'aes_ccm_c-null' 332s | token: '' '' "aes_ccm_c" '-' 332s | token: '' "aes_ccm_c" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_a-null' for ESP 332s | proposal: 'aes_gcm_a-null' 332s | token: '' '' "aes_gcm_a" '-' 332s | token: '' "aes_gcm_a" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_b-null' for ESP 332s | proposal: 'aes_gcm_b-null' 332s | token: '' '' "aes_gcm_b" '-' 332s | token: '' "aes_gcm_b" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_c-null' for ESP 332s | proposal: 'aes_gcm_c-null' 332s | token: '' '' "aes_gcm_c" '-' 332s | token: '' "aes_gcm_c" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm-null' for ESP 332s | proposal: 'aes_ccm-null' 332s | token: '' '' "aes_ccm" '-' 332s | token: '' "aes_ccm" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm-null' for ESP 332s | proposal: 'aes_gcm-null' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm-256-null' for ESP 332s | proposal: 'aes_ccm-256-null' 332s | token: '' '' "aes_ccm" '-' 332s | token: '' "aes_ccm" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm-192-null' for ESP 332s | proposal: 'aes_gcm-192-null' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_256-null' for ESP 332s | proposal: 'aes_ccm_256-null' 332s | token: '' '' "aes_ccm_256" '-' 332s | token: '' "aes_ccm_256" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ccm_256' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_192-null' for ESP 332s | proposal: 'aes_gcm_192-null' 332s | token: '' '' "aes_gcm_192" '-' 332s | token: '' "aes_gcm_192" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_gcm_192' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_8-null' for ESP 332s | proposal: 'aes_ccm_8-null' 332s | token: '' '' "aes_ccm_8" '-' 332s | token: '' "aes_ccm_8" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_12-null' for ESP 332s | proposal: 'aes_ccm_12-null' 332s | token: '' '' "aes_ccm_12" '-' 332s | token: '' "aes_ccm_12" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_16-null' for ESP 332s | proposal: 'aes_ccm_16-null' 332s | token: '' '' "aes_ccm_16" '-' 332s | token: '' "aes_ccm_16" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_8-null' for ESP 332s | proposal: 'aes_gcm_8-null' 332s | token: '' '' "aes_gcm_8" '-' 332s | token: '' "aes_gcm_8" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_12-null' for ESP 332s | proposal: 'aes_gcm_12-null' 332s | token: '' '' "aes_gcm_12" '-' 332s | token: '' "aes_gcm_12" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_16-null' for ESP 332s | proposal: 'aes_gcm_16-null' 332s | token: '' '' "aes_gcm_16" '-' 332s | token: '' "aes_gcm_16" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_8-128-null' for ESP 332s | proposal: 'aes_ccm_8-128-null' 332s | token: '' '' "aes_ccm_8" '-' 332s | token: '' "aes_ccm_8" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_12-192-null' for ESP 332s | proposal: 'aes_ccm_12-192-null' 332s | token: '' '' "aes_ccm_12" '-' 332s | token: '' "aes_ccm_12" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_16-256-null' for ESP 332s | proposal: 'aes_ccm_16-256-null' 332s | token: '' '' "aes_ccm_16" '-' 332s | token: '' "aes_ccm_16" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_8-128-null' for ESP 332s | proposal: 'aes_gcm_8-128-null' 332s | token: '' '' "aes_gcm_8" '-' 332s | token: '' "aes_gcm_8" '-' "128" '-' 332s | token: '-' "128" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_12-192-null' for ESP 332s | proposal: 'aes_gcm_12-192-null' 332s | token: '' '' "aes_gcm_12" '-' 332s | token: '' "aes_gcm_12" '-' "192" '-' 332s | token: '-' "192" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_16-256-null' for ESP 332s | proposal: 'aes_gcm_16-256-null' 332s | token: '' '' "aes_gcm_16" '-' 332s | token: '' "aes_gcm_16" '-' "256" '-' 332s | token: '-' "256" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_8_128-null' for ESP 332s | proposal: 'aes_ccm_8_128-null' 332s | token: '' '' "aes_ccm_8_128" '-' 332s | token: '' "aes_ccm_8_128" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ccm_8_128' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_12_192-null' for ESP 332s | proposal: 'aes_ccm_12_192-null' 332s | token: '' '' "aes_ccm_12_192" '-' 332s | token: '' "aes_ccm_12_192" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ccm_12_192' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_12[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ccm_16_256-null' for ESP 332s | proposal: 'aes_ccm_16_256-null' 332s | token: '' '' "aes_ccm_16_256" '-' 332s | token: '' "aes_ccm_16_256" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ccm_16_256' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_8_128-null' for ESP 332s | proposal: 'aes_gcm_8_128-null' 332s | token: '' '' "aes_gcm_8_128" '-' 332s | token: '' "aes_gcm_8_128" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_gcm_8_128' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_8[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_12_192-null' for ESP 332s | proposal: 'aes_gcm_12_192-null' 332s | token: '' '' "aes_gcm_12_192" '-' 332s | token: '' "aes_gcm_12_192" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_gcm_12_192' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_12[_192] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm_16_256-null' for ESP 332s | proposal: 'aes_gcm_16_256-null' 332s | token: '' '' "aes_gcm_16_256" '-' 332s | token: '' "aes_gcm_16_256" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_gcm_16_256' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_ctr' for ESP 332s | proposal: 'aes_ctr' 332s | token: '' '' "aes_ctr" '' 332s | token: '' "aes_ctr" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CTR[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aesctr' for ESP 332s | proposal: 'aesctr' 332s | token: '' '' "aesctr" '' 332s | token: '' "aesctr" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CTR[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes_ctr128' for ESP 332s | proposal: 'aes_ctr128' 332s | token: '' '' "aes_ctr128" '' 332s | token: '' "aes_ctr128" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ctr128' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CTR[_128] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes_ctr192' for ESP 332s | proposal: 'aes_ctr192' 332s | token: '' '' "aes_ctr192" '' 332s | token: '' "aes_ctr192" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ctr192' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CTR[_192] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes_ctr256' for ESP 332s | proposal: 'aes_ctr256' 332s | token: '' '' "aes_ctr256" '' 332s | token: '' "aes_ctr256" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ctr256' is not recognized 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CTR[_256] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'camellia_cbc_256-hmac_sha2_512_256;modp8192' for ESP 332s | proposal: 'camellia_cbc_256-hmac_sha2_512_256;modp8192' 332s | token: '' '' "camellia_cbc_256" '-' 332s | token: '' "camellia_cbc_256" '-' "hmac_sha2_512_256" ';' 332s | ike_alg_byname() failed: ESP encryption algorithm 'camellia_cbc_256' is not recognized 332s | token: '-' "hmac_sha2_512_256" ';' "modp8192" '' 332s | appending ESP encryption algorithm CAMELLIA_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing 'null_auth_aes_gmac_256-null;modp8192' for ESP 332s | proposal: 'null_auth_aes_gmac_256-null;modp8192' 332s | token: '' '' "null_auth_aes_gmac_256" '-' 332s | token: '' "null_auth_aes_gmac_256" '-' "null" ';' 332s | ike_alg_byname() failed: ESP encryption algorithm 'null_auth_aes_gmac_256' is not recognized 332s | token: '-' "null" ';' "modp8192" '' 332s | appending ESP encryption algorithm NULL_AUTH_AES_GMAC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1;modp8192' for ESP 332s | proposal: '3des-sha1;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1-modp8192' for ESP 332s | proposal: '3des-sha1-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing 'aes-sha1,3des-sha1;modp8192' for ESP 332s | proposal: 'aes-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha1;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing 'aes-sha1-modp8192,3des-sha1-modp8192' for ESP 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha1-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing 'aes-sha1-modp8192,aes-sha1-modp8192,aes-sha1-modp8192' for ESP 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing 'aes;none' for ESP 332s | proposal: 'aes;none' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "none" '' 332s | token: ';' "none" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | appending ESP DH algorithm NONE[_0] 332s | token: '' '' '' 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s ipsec algparse: ignoring redundant ESP DH algorithm NONE as PFS policy is disabled 332s | parsing 'aes;none,aes' for ESP 332s | proposal: 'aes;none' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "none" '' 332s | token: ';' "none" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | appending ESP DH algorithm NONE[_0] 332s | token: '' '' '' 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | proposal: 'aes' 332s | token: '' '' "aes" '' 332s | token: '' "aes" '' '' 332s | token: '' '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s ipsec algparse: ignoring redundant ESP DH algorithm NONE as PFS policy is disabled 332s | parsing 'aes;none,aes;modp2048' for ESP 332s | proposal: 'aes;none' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "none" '' 332s | token: ';' "none" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | appending ESP DH algorithm NONE[_0] 332s | token: '' '' '' 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | proposal: 'aes;modp2048' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "modp2048" '' 332s | token: ';' "modp2048" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | appending ESP DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | appending ESP integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s ipsec algparse: ignoring redundant ESP DH algorithm NONE as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP2048 as PFS policy is disabled 332s | parsing 'aes-sha1-none' for ESP 332s | proposal: 'aes-sha1-none' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "none" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "none" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm NONE[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring redundant ESP DH algorithm NONE as PFS policy is disabled 332s | parsing 'aes-sha1;none' for ESP 332s | proposal: 'aes-sha1;none' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "none" '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "none" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm NONE[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring redundant ESP DH algorithm NONE as PFS policy is disabled 332s | parsing '3des168-sha1' for ESP 332s | proposal: '3des168-sha1' 332s | token: '' '' "3des168" '-' 332s | token: '' "3des168" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm '3des168' is not recognized 332s | parsing '3des-null' for ESP 332s | proposal: '3des-null' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "null" '' 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes128-null' for ESP 332s | proposal: 'aes128-null' 332s | token: '' '' "aes128" '-' 332s | token: '' "aes128" '-' "null" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes128' is not recognized 332s | token: '-' "null" '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | appending ESP integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes224-sha1' for ESP 332s | proposal: 'aes224-sha1' 332s | token: '' '' "aes224" '-' 332s | token: '' "aes224" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes224' is not recognized 332s | parsing 'aes-224-sha1' for ESP 332s | proposal: 'aes-224-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "224" '-' 332s | byname('aes') with ='224' failed: ESP encryption algorithm AES_CBC with key length 224 invalid; valid key lengths: 128, 192, 256 332s | parsing 'aes0-sha1' for ESP 332s | proposal: 'aes0-sha1' 332s | token: '' '' "aes0" '-' 332s | token: '' "aes0" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes0' is not recognized 332s | parsing 'aes-0-sha1' for ESP 332s | proposal: 'aes-0-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "0" '-' 332s | parsing 'aes512-sha1' for ESP 332s | proposal: 'aes512-sha1' 332s | token: '' '' "aes512" '-' 332s | token: '' "aes512" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes512' is not recognized 332s | parsing 'aes-sha1555' for ESP 332s | proposal: 'aes-sha1555' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1555" '' 332s | token: '-' "sha1555" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | ike_alg_byname() failed: ESP integrity algorithm 'sha1555' is not recognized 332s | lookup for integrity algorithm 'sha1555' failed 332s | or - failed 'ESP integrity algorithm 'sha1555' is not recognized') 332s | parsing 'camellia666-sha1' for ESP 332s | proposal: 'camellia666-sha1' 332s | token: '' '' "camellia666" '-' 332s | token: '' "camellia666" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'camellia666' is not recognized 332s | parsing 'blowfish' for ESP 332s | proposal: 'blowfish' 332s | token: '' '' "blowfish" '' 332s | token: '' "blowfish" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'blowfish' is not supported 332s | parsing 'des-sha1' for ESP 332s | proposal: 'des-sha1' 332s | token: '' '' "des" '-' 332s | token: '' "des" '-' "sha1" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'des' is not supported 332s | parsing 'aes_ctr666' for ESP 332s | proposal: 'aes_ctr666' 332s | token: '' '' "aes_ctr666" '' 332s | token: '' "aes_ctr666" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes_ctr666' is not recognized 332s | parsing 'aes128-sha2_128' for ESP 332s | proposal: 'aes128-sha2_128' 332s | token: '' '' "aes128" '-' 332s | token: '' "aes128" '-' "sha2_128" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes128' is not recognized 332s | token: '-' "sha2_128" '' '' 332s | appending ESP encryption algorithm AES_CBC[_128] 332s | parsing integ: 332s | ike_alg_byname() failed: ESP integrity algorithm 'sha2_128' is not recognized 332s | lookup for integrity algorithm 'sha2_128' failed 332s | or - failed 'ESP integrity algorithm 'sha2_128' is not recognized') 332s | parsing 'aes256-sha2_256-4096' for ESP 332s | proposal: 'aes256-sha2_256-4096' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha2_256" '-' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha2_256" '-' "4096" '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '-' "4096" '' '' 332s | parsing dh: 332s | ike_alg_byname() failed: ESP DH algorithm '4096' is not recognized 332s | lookup for DH algorithm '4096' failed 332s | ... failed 'ESP DH algorithm '4096' is not recognized' 332s | parsing 'aes256-sha2_256-128' for ESP 332s | proposal: 'aes256-sha2_256-128' 332s | token: '' '' "aes256" '-' 332s | token: '' "aes256" '-' "sha2_256" '-' 332s | ike_alg_byname() failed: ESP encryption algorithm 'aes256' is not recognized 332s | token: '-' "sha2_256" '-' "128" '' 332s | appending ESP encryption algorithm AES_CBC[_256] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '-' "128" '' '' 332s | parsing dh: 332s | ike_alg_byname() failed: ESP DH algorithm '128' is not recognized 332s | lookup for DH algorithm '128' failed 332s | ... failed 'ESP DH algorithm '128' is not recognized' 332s | parsing 'vanitycipher' for ESP 332s | proposal: 'vanitycipher' 332s | token: '' '' "vanitycipher" '' 332s | token: '' "vanitycipher" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'vanitycipher' is not recognized 332s | parsing 'ase-sah' for ESP 332s | proposal: 'ase-sah' 332s | token: '' '' "ase" '-' 332s | token: '' "ase" '-' "sah" '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'ase' is not recognized 332s | parsing 'aes-sah1' for ESP 332s | proposal: 'aes-sah1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sah1" '' 332s | token: '-' "sah1" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | ike_alg_byname() failed: ESP integrity algorithm 'sah1' is not recognized 332s | lookup for integrity algorithm 'sah1' failed 332s | or - failed 'ESP integrity algorithm 'sah1' is not recognized') 332s | parsing 'id3' for ESP 332s | proposal: 'id3' 332s | token: '' '' "id3" '' 332s | token: '' "id3" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'id3' is not recognized 332s | ike_alg_byname() failed: ESP encryption algorithm 'id3' is not recognized 332s | parsing 'aes-id3' for ESP 332s | proposal: 'aes-id3' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "id3" '' 332s | token: '-' "id3" '' '' 332s | appending ESP encryption algorithm AES_CBC[_0] 332s | parsing integ: 332s | ike_alg_byname() failed: ESP integrity algorithm 'id3' is not recognized 332s | lookup for integrity algorithm 'id3' failed 332s | or - failed 'ESP integrity algorithm 'id3' is not recognized') 332s | parsing 'aes_gcm-md5' for ESP 332s | proposal: 'aes_gcm-md5' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gtesting -ta 332s cm" '-' "md5" '' 332s | token: '-' "md5" '' '' 332s | appending ESP encryption algorithm AES_GCM_16[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_MD5_96[_0] 332s | token: '' '' '' 332s | parsing 'mars' for ESP 332s | proposal: 'mars' 332s | token: '' '' "mars" '' 332s | token: '' "mars" '' '' 332s | ike_alg_byname() failed: ESP encryption algorithm 'mars' is not supported 332s | parsing 'aes_gcm-16' for ESP 332s | proposal: 'aes_gcm-16' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "16" '' 332s | byname('aes_gcm') with ='16' failed: ESP encryption algorithm AES_GCM_16 with key length 16 invalid; valid key lengths: 128, 192, 256 332s | parsing 'aes_gcm-0' for ESP 332s | proposal: 'aes_gcm-0' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "0" '' 332s | parsing 'aes_gcm-123456789012345' for ESP 332s | proposal: 'aes_gcm-123456789012345' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "123456789012345" '' 332s | parsing '3des-sha1;dh22' for ESP 332s | proposal: '3des-sha1;dh22' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "dh22" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "dh22" '' '' 332s | parsing dh: 332s | ike_alg_byname() failed: ESP DH algorithm 'dh22' is not supported 332s | lookup for DH algorithm 'dh22' failed 332s | ... failed 'ESP DH algorithm 'dh22' is not supported' 332s | parsing '3des-sha1;modp8192,3des-sha2' for ESP 332s | proposal: '3des-sha1;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" '' 332s | token: '-' "sha2" '' '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1-modp8192,3des-sha2' for ESP 332s | proposal: '3des-sha1-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" '' 332s | token: '-' "sha2" '' '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1-modp8192,3des-sha2-modp8192' for ESP 332s | proposal: '3des-sha1-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" '-' 332s | token: '-' "sha2" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1-modp8192,3des-sha2;modp8192' for ESP 332s | proposal: '3des-sha1-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" ';' 332s | token: '-' "sha2" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1;modp8192,3des-sha2-modp8192' for ESP 332s | proposal: '3des-sha1;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" '-' 332s | token: '-' "sha2" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1;modp8192,3des-sha2;modp8192' for ESP 332s | proposal: '3des-sha1;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2;modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" ';' 332s | token: '-' "sha2" ';' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: ';' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s | parsing '3des-sha1-modp8192,3des-sha2-modp2048' for ESP 332s | proposal: '3des-sha1-modp8192' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: '3des-sha2-modp2048' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha2" '-' 332s | token: '-' "sha2" '-' "modp2048" '' 332s | appending ESP encryption algorithm 3DES_CBC[_0] 332s | parsing integ: 332s | appending ESP integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '-' "modp2048" '' '' 332s | parsing dh: 332s | appending ESP DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring ESP DH algorithm MODP8192 as PFS policy is disabled 332s ipsec algparse: ignoring ESP DH algorithm MODP2048 as PFS policy is disabled 332s | parsing 'SHA2_512_256,SHA2_256_128' for AH 332s | proposal: 'SHA2_512_256' 332s | token: '' '' "SHA2_512_256" '' 332s | token: '' "SHA2_512_256" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_512_256[_0] 332s | token: '' '' '' 332s | proposal: 'SHA2_256_128' 332s | token: '' '' "SHA2_256_128" '' 332s | token: '' "SHA2_256_128" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing '' for AH 332s | parsing 'md5' for AH 332s | proposal: 'md5' 332s | token: '' '' "md5" '' 332s | token: '' "md5" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_MD5_96[_0] 332s | token: '' '' '' 332s | parsing 'sha' for AH 332s | proposal: 'sha' 332s | token: '' '' "sha" '' 332s | token: '' "sha" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'sha;modp2048' for AH 332s | proposal: 'sha;modp2048' 332s | token: '' '' "sha" ';' 332s | token: '' "sha" ';' "modp2048" '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA1_96[_0] 332s | token: ';' "modp2048" '' '' 332s | parsing dh: 332s | appending AH DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring AH DH algorithm MODP2048 as PFS policy is disabled 332s | parsing 'sha1' for AH 332s | proposal: 'sha1' 332s | token: '' '' "sha1" '' 332s | token: '' "sha1" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA1_96[_0] 332s | token: '' '' '' 332s | parsing 'sha2' for AH 332s | proposal: 'sha2' 332s | token: '' '' "sha2" '' 332s | token: '' "sha2" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'sha256' for AH 332s | proposal: 'sha256' 332s | token: '' '' "sha256" '' 332s | token: '' "sha256" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'sha384' for AH 332s | proposal: 'sha384' 332s | token: '' '' "sha384" '' 332s | token: '' "sha384" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_384_192[_0] 332s | token: '' '' '' 332s | parsing 'sha512' for AH 332s | proposal: 'sha512' 332s | token: '' '' "sha512" '' 332s | token: '' "sha512" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_512_256[_0] 332s | token: '' '' '' 332s | parsing 'sha2_256' for AH 332s | proposal: 'sha2_256' 332s | token: '' '' "sha2_256" '' 332s | token: '' "sha2_256" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '' '' '' 332s | parsing 'sha2_384' for AH 332s | proposal: 'sha2_384' 332s | token: '' '' "sha2_384" '' 332s | token: '' "sha2_384" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_384_192[_0] 332s | token: '' '' '' 332s | parsing 'sha2_512' for AH 332s | proposal: 'sha2_512' 332s | token: '' '' "sha2_512" '' 332s | token: '' "sha2_512" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_512_256[_0] 332s | token: '' '' '' 332s | parsing 'aes_xcbc' for AH 332s | proposal: 'aes_xcbc' 332s | token: '' '' "aes_xcbc" '' 332s | token: '' "aes_xcbc" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm AES_XCBC_96[_0] 332s | token: '' '' '' 332s | parsing 'sha2-none' for AH 332s | proposal: 'sha2-none' 332s | token: '' '' "sha2" '-' 332s | token: '' "sha2" '-' "none" '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: '-' "none" '' '' 332s | parsing dh: 332s | appending AH DH algorithm NONE[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring redundant AH DH algorithm NONE as PFS policy is disabled 332s | parsing 'sha2;none' for AH 332s | proposal: 'sha2;none' 332s | token: '' '' "sha2" ';' 332s | token: '' "sha2" ';' "none" '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA2_256_128[_0] 332s | token: ';' "none" '' '' 332s | parsing dh: 332s | appending AH DH algorithm NONE[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring redundant AH DH algorithm NONE as PFS policy is disabled 332s | parsing 'sha1-modp8192,sha1-modp8192,sha1-modp8192' for AH 332s | proposal: 'sha1-modp8192' 332s | token: '' '' "sha1" '-' 332s | token: '' "sha1" '-' "modp8192" '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending AH DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: 'sha1-modp8192' 332s | token: '' '' "sha1" '-' 332s | token: '' "sha1" '-' "modp8192" '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending AH DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | proposal: 'sha1-modp8192' 332s | token: '' '' "sha1" '-' 332s | token: '' "sha1" '-' "modp8192" '' 332s | parsing integ: 332s | appending AH integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "modp8192" '' '' 332s | parsing dh: 332s | appending AH DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: ignoring AH DH algorithm MODP8192 as PFS policy is disabled 332s | parsing 'aes-sha1' for AH 332s | proposal: 'aes-sha1' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'aes' is not recognized 332s | lookup for integrity algorithm 'aes' failed 332s | or - failed 'AH integrity algorithm 'aes' is not recognized') 332s | parsing 'vanityhash1' for AH 332s | proposal: 'vanityhash1' 332s | token: '' '' "vanityhash1" '' 332s | token: '' "vanityhash1" '' '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'vanityhash1' is not recognized 332s | lookup for integrity algorithm 'vanityhash1' failed 332s | or - failed 'AH integrity algorithm 'vanityhash1' is not recognized') 332s | parsing 'aes_gcm_c-256' for AH 332s | proposal: 'aes_gcm_c-256' 332s | token: '' '' "aes_gcm_c" '-' 332s | token: '' "aes_gcm_c" '-' "256" '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'aes_gcm_c' is not recognized 332s | lookup for integrity algorithm 'aes_gcm_c' failed 332s | or - failed 'AH integrity algorithm 'aes_gcm_c' is not recognized') 332s | parsing 'id3' for AH 332s | proposal: 'id3' 332s | token: '' '' "id3" '' 332s | token: '' "id3" '' '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'id3' is not recognized 332s | lookup for integrity algorithm 'id3' failed 332s | or - failed 'AH integrity algorithm 'id3' is not recognized') 332s | parsing '3des' for AH 332s | proposal: '3des' 332s | token: '' '' "3des" '' 332s | token: '' "3des" '' '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm '3des' is not recognized 332s | lookup for integrity algorithm '3des' failed 332s | or - failed 'AH integrity algorithm '3des' is not recognized') 332s | parsing 'null' for AH 332s | proposal: 'null' 332s | token: '' '' "null" '' 332s | token: '' "null" '' '' 332s | parsing integ: 332s | appending AH integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm' for AH 332s | proposal: 'aes_gcm' 332s | token: '' '' "aes_gcm" '' 332s | token: '' "aes_gcm" '' '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'aes_gcm' is not recognized 332s | lookup for integrity algorithm 'aes_gcm' failed 332s | or - failed 'AH integrity algorithm 'aes_gcm' is not recognized') 332s | parsing 'aes_ccm' for AH 332s | proposal: 'aes_ccm' 332s | token: '' '' "aes_ccm" '' 332s | token: '' "aes_ccm" '' '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'aes_ccm' is not recognized 332s | lookup for integrity algorithm 'aes_ccm' failed 332s | or - failed 'AH integrity algorithm 'aes_ccm' is not recognized') 332s | parsing 'ripemd' for AH 332s | proposal: 'ripemd' 332s | token: '' '' "ripemd" '' 332s | token: '' "ripemd" '' '' 332s | parsing integ: 332s | ike_alg_byname() failed: AH integrity algorithm 'ripemd' is not recognized 332s | lookup for integrity algorithm 'ripemd' failed 332s | or - failed 'AH integrity algorithm 'ripemd' is not recognized') 332s | parsing 'AES_GCM_16_256,AES_GCM_16_128,CHACHA20_POLY1305,AES_CBC_256,AES_CBC_128' for IKE 332s | proposal: 'AES_GCM_16_256' 332s | token: '' '' "AES_GCM_16_256" '' 332s | token: '' "AES_GCM_16_256" '' '' 332s | ike_alg_byname() failed: IKE encryption algorithm 'AES_GCM_16_256' is not recognized 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_256] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm NONE[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | proposal: 'AES_GCM_16_128' 332s | token: '' '' "AES_GCM_16_128" '' 332s | token: '' "AES_GCM_16_128" '' '' 332s | ike_alg_byname() failed: IKE encryption algorithm 'AES_GCM_16_128' is not recognized 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_128] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm NONE[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | proposal: 'CHACHA20_POLY1305' 332s | token: '' '' "CHACHA20_POLY1305" '' 332s | token: '' "CHACHA20_POLY1305" '' '' 332s | token: '' '' '' 332s | appending IKE encryption algorithm CHACHA20_POLY1305[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm NONE[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | proposal: 'AES_CBC_256' 332s | token: '' '' "AES_CBC_256" '' 332s | token: '' "AES_CBC_256" '' '' 332s | ike_alg_byname() failed: IKE encryption algorithm 'AES_CBC_256' is not recognized 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_256] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | proposal: 'AES_CBC_128' 332s | token: '' '' "AES_CBC_128" '' 332s | token: '' "AES_CBC_128" '' '' 332s | ike_alg_byname() failed: IKE encryption algorithm 'AES_CBC_128' is not recognized 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_128] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing '' for IKE 332s | parsing '3des-sha1' for IKE 332s | proposal: '3des-sha1' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '' '' '' 332s | - succeeded, advancing tokens 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing '3des-sha1' for IKE 332s | proposal: '3des-sha1' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '' 332s | token: '-' "sha1" '' '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '' '' '' 332s | - succeeded, advancing tokens 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing '3des-sha1;modp1536' for IKE 332s | proposal: '3des-sha1;modp1536' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "modp1536" '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: ';' "modp1536" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP1536[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing '3des;dh21' for IKE 332s | proposal: '3des;dh21' 332s | token: '' '' "3des" ';' 332s | token: '' "3des" ';' "dh21" '' 332s | token: ';' "dh21" '' '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing dh: 332s | appending IKE DH algorithm DH21[_0] 332s | token: '' '' '' 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing '3des-sha1;dh21' for IKE 332s | proposal: '3des-sha1;dh21' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" ';' 332s | token: '-' "sha1" ';' "dh21" '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: ';' "dh21" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm DH21[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing '3des-sha1-ecp_521' for IKE 332s | proposal: '3des-sha1-ecp_521' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "ecp_521" '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "ecp_521" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm DH21[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing '3des+aes' for IKE 332s | proposal: '3des+aes' 332s | token: '' '' "3des" '+' 332s | token: '' "3des" '+' "aes" '' 332s | token: '+' "aes" '' '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes;none' for IKE 332s | proposal: 'aes;none' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "none" '' 332s | token: ';' "none" '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | appending IKE DH algorithm NONE[_0] 332s | token: '' '' '' 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'id2' for IKE 332s | proposal: 'id2' 332s | token: '' '' "id2" '' 332s | token: '' "id2" '' '' 332s | ike_alg_byname() failed: IKE encryption algorithm 'id2' is not recognized 332s | ike_alg_byname() failed: IKE encryption algorithm 'id2' is not recognized 332s | parsing '3des-id2' for IKE 332s | proposal: '3des-id2' 332s | token: '' '' "3des" '-' 332s | token: '' "3des" '-' "id2" '' 332s | token: '-' "id2" '' '' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'id2' is not recognized 332s | lookup for PRF algorithm 'id2' failed 332s | - failed, saving error 'IKE PRF algorithm 'id2' is not recognized' and tossing result 332s | parsing integ: 332s | ike_alg_byname() failed: IKE integrity algorithm 'id2' is not recognized 332s | lookup for integrity algorithm 'id2' failed 332s | - and - failed, returning earlier PRF error 'IKE PRF algorithm 'id2' is not recognized' and discarding INTEG error 'IKE integrity algorithm 'id2' is not recognized') 332s | parsing 'aes_ccm' for IKE 332s | proposal: 'aes_ccm' 332s | token: '' '' "aes_ccm" '' 332s | token: '' "aes_ccm" '' '' 332s | alg_byname_ok() failed: IKE encryption algorithm 'aes_ccm' is not supported 332s | parsing 'aes-sha1-sha2-ecp_521' for IKE 332s | proposal: 'aes-sha1-sha2-ecp_521' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "sha2" '-' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "sha2" '-' "ecp_521" '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | ike_alg_byname() failed: IKE DH algorithm 'sha2' is not recognized 332s | lookup for DH algorithm 'sha2' failed 332s | ... failed 'IKE DH algorithm 'sha2' is not recognized' 332s | parsing 'aes-sha2-sha2;ecp_521' for IKE 332s | proposal: 'aes-sha2-sha2;ecp_521' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha2" '-' 332s | token: '-' "sha2" '-' "sha2" ';' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '-' "sha2" ';' "ecp_521" '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | ike_alg_byname() failed: IKE DH algorithm 'sha2' is not recognized 332s | lookup for DH algorithm 'sha2' failed 332s | ... failed 'IKE DH algorithm 'sha2' is not recognized' 332s | parsing 'aes-sha1_96-sha2-ecp_521' for IKE 332s | proposal: 'aes-sha1_96-sha2-ecp_521' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1_96" '-' 332s | token: '-' "sha1_96" '-' "sha2" '-' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'sha1_96' is not recognized 332s | lookup for PRF algorithm 'sha1_96' failed 332s | - failed, saving error 'IKE PRF algorithm 'sha1_96' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "sha2" '-' "ecp_521" '' 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '-' "ecp_521" '' '' 332s | parsing dh: 332s | appending IKE DH algorithm DH21[_0] 332s | token: '' '' '' 332s | parsing 'aes-sha1_96-sha2;ecp_521' for IKE 332s | proposal: 'aes-sha1_96-sha2;ecp_521' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1_96" '-' 332s | token: '-' "sha1_96" '-' "sha2" ';' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'sha1_96' is not recognized 332s | lookup for PRF algorithm 'sha1_96' failed 332s | - failed, saving error 'IKE PRF algorithm 'sha1_96' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | token: '-' "sha2" ';' "ecp_521" '' 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: ';' "ecp_521" '' '' 332s | parsing dh: 332s | appending IKE DH algorithm DH21[_0] 332s | token: '' '' '' 332s | parsing 'aes+aes-sha1+sha1-modp8192+modp8192' for IKE 332s | proposal: 'aes+aes-sha1+sha1-modp8192+modp8192' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "aes" '-' 332s | token: '+' "aes" '-' "sha1" '+' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | token: '-' "sha1" '+' "sha1" '-' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '+' "sha1" '-' "modp8192" '+' 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '+' "modp8192" '' 332s ipsec algparse: discarding duplicate IKE PRF algorithm HMAC_SHA1 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '+' "modp8192" '' '' 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: discarding duplicate IKE DH algorithm MODP8192 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing '3des+aes+aes-sha2+sha1+sha1-modp4096+modp8192+modp8192' for IKE 332s | proposal: '3des+aes+aes-sha2+sha1+sha1-modp4096+modp8192+modp8192' 332s | token: '' '' "3des" '+' 332s | token: '' "3des" '+' "aes" '+' 332s | token: '+' "aes" '+' "aes" '-' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | token: '+' "aes" '-' "sha2" '+' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | token: '-' "sha2" '+' "sha1" '+' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '+' "sha1" '+' "sha1" '-' 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '+' "sha1" '-' "modp4096" '+' 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp4096" '+' "modp8192" '+' 332s ipsec algparse: discarding duplicate IKE PRF algorithm HMAC_SHA1 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP4096[_0] 332s | token: '+' "modp8192" '+' "modp8192" '' 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '+' "modp8192" '' '' 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: discarding duplicate IKE DH algorithm MODP8192 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing 'aes+3des+aes-sha1+sha2+sha1-modp8192+modp4096+modp8192' for IKE 332s | proposal: 'aes+3des+aes-sha1+sha2+sha1-modp8192+modp4096+modp8192' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "3des" '+' 332s | token: '+' "3des" '+' "aes" '-' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | token: '+' "aes" '-' "sha1" '+' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s | token: '-' "sha1" '+' "sha2" '+' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '+' "sha2" '+' "sha1" '-' 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '+' "sha1" '-' "modp8192" '+' 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '+' "modp4096" '+' 332s ipsec algparse: discarding duplicate IKE PRF algorithm HMAC_SHA1 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '+' "modp4096" '+' "modp8192" '' 332s | appending IKE DH algorithm MODP4096[_0] 332s | token: '+' "modp8192" '' '' 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s ipsec algparse: discarding duplicate IKE DH algorithm MODP8192 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes+aes+3des-sha1+sha1+sha2-modp8192+modp8192+modp4096' for IKE 332s | proposal: 'aes+aes+3des-sha1+sha1+sha2-modp8192+modp8192+modp4096' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "aes" '+' 332s | token: '+' "aes" '+' "3des" '-' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | token: '+' "3des" '-' "sha1" '+' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | token: '-' "sha1" '+' "sha1" '+' 332s | appending IKE encryption algorithm 3DES_CBC[_0] 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '+' "sha1" '+' "sha2" '-' 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '+' "sha2" '-' "modp8192" '+' 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '-' "modp8192" '+' "modp8192" '+' 332s ipsec algparse: discarding duplicate IKE PRF algorithm HMAC_SHA1 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '+' "modp8192" '+' "modp4096" '' 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '+' "modp4096" '' '' 332s | appending IKE DH algorithm MODP4096[_0] 332s | token: '' '' '' 332s ipsec algparse: discarding duplicate IKE DH algorithm MODP8192 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | parsing 'aes+aes128+aes256' for IKE 332s | proposal: 'aes+aes128+aes256' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "aes128" '+' 332s | token: '+' "aes128" '+' "aes256" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | ike_alg_byname() failed: IKE encryption algorithm 'aes128' is not recognized 332s | token: '+' "aes256" '' '' 332s | appending IKE encryption algorithm AES_CBC[_128] 332s | ike_alg_byname() failed: IKE encryption algorithm 'aes256' is not recognized 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_256] 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC_128 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC_256 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes128+aes+aes256' for IKE 332s | proposal: 'aes128+aes+aes256' 332s | token: '' '' "aes128" '+' 332s | token: '' "aes128" '+' "aes" '+' 332s | ike_alg_byname() failed: IKE encryption algorithm 'aes128' is not recognized 332s | token: '+' "aes" '+' "aes256" '' 332s | appending IKE encryption algorithm AES_CBC[_128] 332s | token: '+' "aes256" '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | ike_alg_byname() failed: IKE encryption algorithm 'aes256' is not recognized 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_256] 332s ipsec algparse: discarding duplicate IKE encryption algorithm AES_CBC_256 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes128+aes256+aes' for IKE 332s | proposal: 'aes128+aes256+aes' 332s | token: '' '' "aes128" '+' 332s | token: '' "aes128" '+' "aes256" '+' 332s | ike_alg_byname() failed: IKE encryption algorithm 'aes128' is not recognized 332s | token: '+' "aes256" '+' "aes" '' 332s | appending IKE encryption algorithm AES_CBC[_128] 332s | ike_alg_byname() failed: IKE encryption algorithm 'aes256' is not recognized 332s | token: '+' "aes" '' '' 332s | appending IKE encryption algorithm AES_CBC[_256] 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes-sha1-modp8192,aes-sha1-modp8192,aes-sha1-modp8192' for IKE 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing 'aes-sha1-modp8192,aes-sha2-modp8192,aes-sha1-modp8192' for IKE 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | proposal: 'aes-sha2-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha2" '-' 332s | token: '-' "sha2" '-' "modp8192" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '-' "modp8192" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | proposal: 'aes-sha1-modp8192' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "modp8192" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "modp8192" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP8192[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm HMAC_SHA1_96[_0] 332s | parsing 'aes_gcm' for IKE 332s | proposal: 'aes_gcm' 332s | token: '' '' "aes_gcm" '' 332s | token: '' "aes_gcm" '' '' 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm NONE[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes_gcm-sha2' for IKE 332s | proposal: 'aes_gcm-sha2' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "sha2" '' 332s | token: '-' "sha2" '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '' '' '' 332s | - succeeded, advancing tokens 332s | appending IKE integrity algorithm NONE[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes_gcm-sha2-modp2048' for IKE 332s | proposal: 'aes_gcm-sha2-modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "sha2" '-' 332s | token: '-' "sha2" '-' "modp2048" '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '-' "modp2048" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm NONE[_0] 332s | parsing 'aes_gcm-sha2;modp2048' for IKE 332s | proposal: 'aes_gcm-sha2;modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "sha2" ';' 332s | token: '-' "sha2" ';' "modp2048" '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: ';' "modp2048" '' '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | appending IKE integrity algorithm NONE[_0] 332s | parsing 'aes_gcm-modp2048' for IKE 332s | proposal: 'aes_gcm-modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "modp2048" '' 332s | token: '-' "modp2048" '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'modp2048' is not recognized 332s | lookup for PRF algorithm 'modp2048' failed 332s | - failed, saving error 'IKE PRF algorithm 'modp2048' is not recognized' and tossing result 332s | parsing integ: 332s | ike_alg_byname() failed: IKE integrity algorithm 'modp2048' is not recognized 332s | lookup for integrity algorithm 'modp2048' failed 332s | - and - failed, returning earlier PRF error 'IKE PRF algorithm 'modp2048' is not recognized' and discarding INTEG error 'IKE integrity algorithm 'modp2048' is not recognized') 332s | parsing 'aes_gcm;modp2048' for IKE 332s | proposal: 'aes_gcm;modp2048' 332s | token: '' '' "aes_gcm" ';' 332s | token: '' "aes_gcm" ';' "modp2048" '' 332s | token: ';' "modp2048" '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing dh: 332s | appending IKE DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm NONE[_0] 332s | parsing 'aes_gcm-none' for IKE 332s | proposal: 'aes_gcm-none' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "none" '' 332s | token: '-' "none" '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'none' is not recognized 332s | lookup for PRF algorithm 'none' failed 332s | - failed, saving error 'IKE PRF algorithm 'none' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm NONE[_0] 332s | token: '' '' '' 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes_gcm-none-sha2' for IKE 332s | proposal: 'aes_gcm-none-sha2' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "none" '-' 332s | token: '-' "none" '-' "sha2" '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'none' is not recognized 332s | lookup for PRF algorithm 'none' failed 332s | - failed, saving error 'IKE PRF algorithm 'none' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm NONE[_0] 332s | token: '-' "sha2" '' '' 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '' '' '' 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing 'aes_gcm-none-sha2-modp2048' for IKE 332s | proposal: 'aes_gcm-none-sha2-modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "none" '-' 332s | token: '-' "none" '-' "sha2" '-' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'none' is not recognized 332s | lookup for PRF algorithm 'none' failed 332s | - failed, saving error 'IKE PRF algorithm 'none' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm NONE[_0] 332s | token: '-' "sha2" '-' "modp2048" '' 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: '-' "modp2048" '' '' 332s | parsing dh: 332s | appending IKE DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm-none-sha2;modp2048' for IKE 332s | proposal: 'aes_gcm-none-sha2;modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "none" '-' 332s | token: '-' "none" '-' "sha2" ';' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'none' is not recognized 332s | lookup for PRF algorithm 'none' failed 332s | - failed, saving error 'IKE PRF algorithm 'none' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm NONE[_0] 332s | token: '-' "sha2" ';' "modp2048" '' 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | token: ';' "modp2048" '' '' 332s | parsing dh: 332s | appending IKE DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | parsing 'aes_gcm-none-modp2048' for IKE 332s | proposal: 'aes_gcm-none-modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "none" '-' 332s | token: '-' "none" '-' "modp2048" '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'none' is not recognized 332s | lookup for PRF algorithm 'none' failed 332s | - failed, saving error 'IKE PRF algorithm 'none' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm NONE[_0] 332s | token: '-' "modp2048" '' '' 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'modp2048' is not recognized 332s | lookup for PRF algorithm 'modp2048' failed 332s | -- failed 'IKE PRF algorithm 'modp2048' is not recognized' 332s | parsing 'aes_gcm-none;modp2048' for IKE 332s | proposal: 'aes_gcm-none;modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "none" ';' 332s | token: '-' "none" ';' "modp2048" '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | ike_alg_byname() failed: IKE PRF algorithm 'none' is not recognized 332s | lookup for PRF algorithm 'none' failed 332s | - failed, saving error 'IKE PRF algorithm 'none' is not recognized' and tossing result 332s | parsing integ: 332s | appending IKE integrity algorithm NONE[_0] 332s | token: ';' "modp2048" '' '' 332s | parsing dh: 332s | appending IKE DH algorithm MODP2048[_0] 332s | token: '' '' '' 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | parsing 'aes_gcm-sha1-none-modp2048' for IKE 332s | proposal: 'aes_gcm-sha1-none-modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "none" '-' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "none" '-' "modp2048" '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm NONE[_0] 332s | token: '-' "modp2048" '' '' 332s | parsing 'aes_gcm-sha1-none;modp2048' for IKE 332s | proposal: 'aes_gcm-sha1-none;modp2048' 332s | token: '' '' "aes_gcm" '-' 332s | token: '' "aes_gcm" '-' "sha1" '-' 332s | token: '-' "sha1" '-' "none" ';' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | parsing prf: 332s | appending IKE PRF algorithm HMAC_SHA1[_0] 332s | token: '-' "none" ';' "modp2048" '' 332s | - succeeded, advancing tokens 332s | parsing dh: 332s | appending IKE DH algorithm NONE[_0] 332s | token: ';' "modp2048" '' '' 332s | parsing 'aes+aes_gcm' for IKE 332s | proposal: 'aes+aes_gcm' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "aes_gcm" '' 332s | token: '+' "aes_gcm" '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_GCM_16[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | parsing ',' for IKE 332s | proposal: '' 332s | token: '' '' "" '' 332s | token: '' "" '' '' 332s | parsing 'aes,' for IKE 332s | proposal: 'aes' 332s | token: '' '' "aes" '' 332s | token: '' "aes" '' '' 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | proposal: '' 332s | token: '' '' "" '' 332s | token: '' "" '' '' 332s | parsing 'aes,,aes' for IKE 332s | proposal: 'aes' 332s | token: '' '' "aes" '' 332s | token: '' "aes" '' '' 332s | token: '' '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_512[_0] 332s | appending IKE PRF algorithm HMAC_SHA2_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_512_256[_0] 332s | appending IKE integrity algorithm HMAC_SHA2_256_128[_0] 332s | appending IKE DH algorithm DH19[_0] 332s | appending IKE DH algorithm DH20[_0] 332s | appending IKE DH algorithm DH21[_0] 332s | appending IKE DH algorithm DH31[_0] 332s | appending IKE DH algorithm MODP4096[_0] 332s | appending IKE DH algorithm MODP3072[_0] 332s | appending IKE DH algorithm MODP2048[_0] 332s | appending IKE DH algorithm MODP8192[_0] 332s | proposal: '' 332s | token: '' '' "" '' 332s | token: '' "" '' '' 332s | parsing ',aes' for IKE 332s | proposal: '' 332s | token: '' '' "" '' 332s | token: '' "" '' '' 332s | parsing '-' for IKE 332s | proposal: '-' 332s | token: '' '' "" '-' 332s | token: '' "" '-' "" '' 332s | parsing '+' for IKE 332s | proposal: '+' 332s | token: '' '' "" '+' 332s | token: '' "" '+' "" '' 332s | parsing ';' for IKE 332s | proposal: ';' 332s | token: '' '' "" ';' 332s | token: '' "" ';' "" '' 332s | parsing 'aes-' for IKE 332s | proposal: 'aes-' 332s | token: '' '' "aes" '-' 332s | token: '' "aes" '-' "" '' 332s | token: '-' "" '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing prf: 332s | - failed, saving error 'IKE PRF algorithm is empty' and tossing result 332s | parsing integ: 332s | - and - failed, returning earlier PRF error 'IKE PRF algorithm is empty' and discarding INTEG error 'IKE integrity algorithm is empty') 332s | parsing 'aes+' for IKE 332s | proposal: 'aes+' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "" '' 332s | token: '+' "" '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing 'aes;' for IKE 332s | proposal: 'aes;' 332s | token: '' '' "aes" ';' 332s | token: '' "aes" ';' "" '' 332s | token: ';' "" '' '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing dh: 332s | ... failed 'IKE DH algorithm is empty' 332s | parsing '-aes' for IKE 332s | proposal: '-aes' 332s | token: '' '' "" '-' 332s | token: '' "" '-' "aes" '' 332s | parsing '+aes' for IKE 332s | proposal: '+aes' 332s | token: '' '' "" '+' 332s | token: '' "" '+' "aes" '' 332s | parsing ';aes' for IKE 332s | proposal: ';aes' 332s | token: '' '' "" ';' 332s | token: '' "" ';' "aes" '' 332s | parsing 'aes+-' for IKE 332s | proposal: 'aes+-' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "" '-' 332s | token: '+' "" '-' "" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing 'aes+;' for IKE 332s | proposal: 'aes+;' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "" ';' 332s | token: '+' "" ';' "" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s | parsing 'aes++' for IKE 332s | proposal: 'aes++' 332s | token: '' '' "aes" '+' 332s | token: '' "aes" '+' "" '+' 332s | token: '+' "" '+' "" '' 332s | appending IKE encryption algorithm AES_CBC[_0] 332s ipsec algparse: leak detective found no leaks 332s ipsec algparse: Encryption algorithms: 332s ipsec algparse: AES_CCM_16 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm, aes_ccm_c 332s ipsec algparse: AES_CCM_12 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm_b 332s ipsec algparse: AES_CCM_8 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm_a 332s ipsec algparse: 3DES_CBC [*192] IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CBC) 3des 332s ipsec algparse: CAMELLIA_CTR {256,192,*128} IKEv1: ESP IKEv2: ESP 332s ipsec algparse: CAMELLIA_CBC {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP NSS(CBC) camellia 332s ipsec algparse: AES_GCM_16 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm, aes_gcm_c 332s ipsec algparse: AES_GCM_12 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm_b 332s ipsec algparse: AES_GCM_8 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm_a 332s ipsec algparse: AES_CTR {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CTR) aesctr 332s ipsec algparse: AES_CBC {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CBC) aes 332s ipsec algparse: NULL_AUTH_AES_GMAC {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_gmac 332s ipsec algparse: NULL [] IKEv1: ESP IKEv2: ESP NULL 332s ipsec algparse: CHACHA20_POLY1305 [*256] IKEv1: IKEv2: IKE ESP NSS(AEAD) chacha20poly1305 332s ipsec algparse: Hash algorithms: 332s ipsec algparse: MD5 IKEv1: IKE IKEv2: NSS 332s ipsec algparse: SHA1 IKEv1: IKE IKEv2: IKE FIPS NSS sha 332s ipsec algparse: SHA2_256 IKEv1: IKE IKEv2: IKE FIPS NSS sha2, sha256 332s ipsec algparse: SHA2_384 IKEv1: IKE IKEv2: IKE FIPS NSS sha384 332s ipsec algparse: SHA2_512 IKEv1: IKE IKEv2: IKE FIPS NSS sha512 332s ipsec algparse: IDENTITY IKEv1: IKEv2: FIPS 332s ipsec algparse: PRF algorithms: 332s ipsec algparse: HMAC_MD5 IKEv1: IKE IKEv2: IKE NSS md5 332s ipsec algparse: HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS NSS sha, sha1 332s ipsec algparse: HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS NSS sha2, sha256, sha2_256 332s ipsec algparse: HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS NSS sha384, sha2_384 332s ipsec algparse: HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS NSS sha512, sha2_512 332s ipsec algparse: AES_XCBC IKEv1: IKEv2: IKE native(XCBC) aes128_xcbc 332s ipsec algparse: Integrity algorithms: 332s ipsec algparse: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH NSS md5, hmac_md5 332s ipsec algparse: HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha, sha1, sha1_96, hmac_sha1 332s ipsec algparse: HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha512, sha2_512, sha2_512_256, hmac_sha2_512 332s ipsec algparse: HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha384, sha2_384, sha2_384_192, hmac_sha2_384 332s ipsec algparse: HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 332s ipsec algparse: HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH 332s ipsec algparse: AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH native(XCBC) aes_xcbc, aes128_xcbc, aes128_xcbc_96 332s ipsec algparse: AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac 332s ipsec algparse: NONE IKEv1: ESP IKEv2: IKE ESP FIPS null 332s ipsec algparse: DH algorithms: 332s ipsec algparse: NONE IKEv1: IKEv2: IKE ESP AH FIPS NSS(MODP) null, dh0 332s ipsec algparse: MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH NSS(MODP) dh5 332s ipsec algparse: MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh14 332s ipsec algparse: MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh15 332s ipsec algparse: MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh16 332s ipsec algparse: MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh17 332s ipsec algparse: MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh18 332s ipsec algparse: DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_256, ecp256 332s ipsec algparse: DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_384, ecp384 332s ipsec algparse: DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_521, ecp521 332s ipsec algparse: DH31 IKEv1: IKE IKEv2: IKE ESP AH NSS(ECP) curve25519 332s ipsec algparse: IPCOMP algorithms: 332s ipsec algparse: DEFLATE IKEv1: ESP AH IKEv2: ESP AH FIPS 332s ipsec algparse: LZS IKEv1: IKEv2: ESP AH FIPS 332s ipsec algparse: LZJH IKEv1: IKEv2: ESP AH FIPS 332s ipsec algparse: testing CAMELLIA_CBC: 332s ipsec algparse: Camellia: 16 bytes with 128-bit key 332s | decode_to_chunk() raw_key: input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_chunk() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: CAMELLIA_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0x07 92 3A 39 EB 0A 81 7D 1C 4D 87 BD B8 2D 1F 1C" 332s | decode_to_chunk() output: 332s | 07 92 3a 39 eb 0a 81 7d 1c 4d 87 bd b8 2d 1f 1c ..:9...}.M...-.. 332s | decode_to_chunk() plaintext: : input "0x80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_chunk() output: 332s | 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() ciphertext: : input "0x07 92 3A 39 EB 0A 81 7D 1C 4D 87 BD B8 2D 1F 1C" 332s | decode_to_chunk() output: 332s | 07 92 3a 39 eb 0a 81 7d 1c 4d 87 bd b8 2d 1f 1c ..:9...}.M...-.. 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: encrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0x07 92 3A 39 EB 0A 81 7D 1C 4D 87 BD B8 2D 1F 1C" 332s | decode_to_chunk() output: 332s | 07 92 3a 39 eb 0a 81 7d 1c 4d 87 bd b8 2d 1f 1c ..:9...}.M...-.. 332s | decode_to_chunk() ciphertext: : input "0x07 92 3A 39 EB 0A 81 7D 1C 4D 87 BD B8 2D 1F 1C" 332s | decode_to_chunk() output: 332s | 07 92 3a 39 eb 0a 81 7d 1c 4d 87 bd b8 2d 1f 1c ..:9...}.M...-.. 332s | decode_to_chunk() plaintext: : input "0x80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_chunk() output: 332s | 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: decrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: updated CBC IV: ok 332s ipsec algparse: Camellia: 16 bytes with 128-bit key 332s | decode_to_chunk() raw_key: input "0x00 11 22 33 44 55 66 77 88 99 AA BB CC DD EE FF" 332s | decode_to_chunk() output: 332s | 00 11 22 33 44 55 66 77 88 99 aa bb cc dd ee ff .."3DUfw........ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: CAMELLIA_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0x14 4D 2B 0F 50 0C 27 B7 EC 2C D1 2D 91 59 6F 37" 332s | decode_to_chunk() output: 332s | 14 4d 2b 0f 50 0c 27 b7 ec 2c d1 2d 91 59 6f 37 .M+.P.'..,.-.Yo7 332s | decode_to_chunk() plaintext: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 " 332s | decode_to_chunk() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ................ 332s | decode_to_chunk() ciphertext: : input "0x14 4D 2B 0F 50 0C 27 B7 EC 2C D1 2D 91 59 6F 37" 332s | decode_to_chunk() output: 332s | 14 4d 2b 0f 50 0c 27 b7 ec 2c d1 2d 91 59 6f 37 .M+.P.'..,.-.Yo7 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: encrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0x14 4D 2B 0F 50 0C 27 B7 EC 2C D1 2D 91 59 6F 37" 332s | decode_to_chunk() output: 332s | 14 4d 2b 0f 50 0c 27 b7 ec 2c d1 2d 91 59 6f 37 .M+.P.'..,.-.Yo7 332s | decode_to_chunk() ciphertext: : input "0x14 4D 2B 0F 50 0C 27 B7 EC 2C D1 2D 91 59 6F 37" 332s | decode_to_chunk() output: 332s | 14 4d 2b 0f 50 0c 27 b7 ec 2c d1 2d 91 59 6f 37 .M+.P.'..,.-.Yo7 332s | decode_to_chunk() plaintext: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 " 332s | decode_to_chunk() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ................ 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: decrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 128-bit key: updated CBC IV: ok 332s ipsec algparse: Camellia: 16 bytes with 256-bit key 332s | decode_to_chunk() raw_key: input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_chunk() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: CAMELLIA_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356db360 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0xB0 C6 B8 8A EA 51 8A B0 9E 84 72 48 E9 1B 1B 9D" 332s | decode_to_chunk() output: 332s | b0 c6 b8 8a ea 51 8a b0 9e 84 72 48 e9 1b 1b 9d .....Q....rH.... 332s | decode_to_chunk() plaintext: : input "0x80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_chunk() output: 332s | 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() ciphertext: : input "0xB0 C6 B8 8A EA 51 8A B0 9E 84 72 48 E9 1B 1B 9D" 332s | decode_to_chunk() output: 332s | b0 c6 b8 8a ea 51 8a b0 9e 84 72 48 e9 1b 1b 9d .....Q....rH.... 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: encrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0xB0 C6 B8 8A EA 51 8A B0 9E 84 72 48 E9 1B 1B 9D" 332s | decode_to_chunk() output: 332s | b0 c6 b8 8a ea 51 8a b0 9e 84 72 48 e9 1b 1b 9d .....Q....rH.... 332s | decode_to_chunk() ciphertext: : input "0xB0 C6 B8 8A EA 51 8A B0 9E 84 72 48 E9 1B 1B 9D" 332s | decode_to_chunk() output: 332s | b0 c6 b8 8a ea 51 8a b0 9e 84 72 48 e9 1b 1b 9d .....Q....rH.... 332s | decode_to_chunk() plaintext: : input "0x80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_chunk() output: 332s | 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: decrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: updated CBC IV: ok 332s ipsec algparse: Camellia: 16 bytes with 256-bit key 332s | decode_to_chunk() raw_key: input "0x00 11 22 33 44 55 66 77 88 99 AA BB CC DD EE FF FF EE DD CC BB AA 99 88 77 66 55 44 33 22 11 00" 332s | decode_to_chunk() output: 332s | 00 11 22 33 44 55 66 77 88 99 aa bb cc dd ee ff .."3DUfw........ 332s | ff ee dd cc bb aa 99 88 77 66 55 44 33 22 11 00 ........wfUD3".. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: CAMELLIA_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356db360 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0xCC 39 FF EE 18 56 D3 EB 61 02 5E 93 21 9B 65 23 " 332s | decode_to_chunk() output: 332s | cc 39 ff ee 18 56 d3 eb 61 02 5e 93 21 9b 65 23 .9...V..a.^.!.e# 332s | decode_to_chunk() plaintext: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01" 332s | decode_to_chunk() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ................ 332s | decode_to_chunk() ciphertext: : input "0xCC 39 FF EE 18 56 D3 EB 61 02 5E 93 21 9B 65 23 " 332s | decode_to_chunk() output: 332s | cc 39 ff ee 18 56 d3 eb 61 02 5e 93 21 9b 65 23 .9...V..a.^.!.e# 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: encrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" 332s | decode_to_mac() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | decode_to_chunk() new IV: : input "0xCC 39 FF EE 18 56 D3 EB 61 02 5E 93 21 9B 65 23 " 332s | decode_to_chunk() output: 332s | cc 39 ff ee 18 56 d3 eb 61 02 5e 93 21 9b 65 23 .9...V..a.^.!.e# 332s | decode_to_chunk() ciphertext: : input "0xCC 39 FF EE 18 56 D3 EB 61 02 5E 93 21 9B 65 23 " 332s | decode_to_chunk() output: 332s | cc 39 ff ee 18 56 d3 eb 61 02 5e 93 21 9b 65 23 .9...V..a.^.!.e# 332s | decode_to_chunk() plaintext: : input "0x00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01" 332s | decode_to_chunk() output: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ................ 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: CAMELLIA_CBC - exit 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: decrypt: ok 332s | verify_bytes() Camellia: 16 bytes with 256-bit key: updated CBC IV: ok 332s ipsec algparse: testing AES_GCM_16: 332s ipsec algparse: empty string 332s | decode_to_chunk() raw_key: input "0xcf063a34d4a9a76c2c86787d3f96db71" 332s | decode_to_chunk() output: 332s | cf 06 3a 34 d4 a9 a7 6c 2c 86 78 7d 3f 96 db 71 ..:4...l,.x}?..q 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7390 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_GCM 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72e0 332s | decode_to_chunk() salted IV: input "0x113b9785971864c83b01c787" 332s | decode_to_chunk() output: 332s | 11 3b 97 85 97 18 64 c8 3b 01 c7 87 .;....d.;... 332s | decode_to_chunk() AAD: input "" 332s | decode_to_chunk() output: 332s | 332s | decode_to_chunk() plaintext: input "" 332s | decode_to_chunk() output: 332s | 332s | decode_to_chunk() ciphertext: input "" 332s | decode_to_chunk() output: 332s | 332s | decode_to_chunk() tag: input "0x72ac8493e3a5228b5d130a69d2510e42" 332s | decode_to_chunk() output: 332s | 72 ac 84 93 e3 a5 22 8b 5d 13 0a 69 d2 51 0e 42 r.....".]..i.Q.B 332s | test_gcm_vector() DECRYPT: aad-size=0 salt-size=4 wire-IV-size=8 text-size=0 tag-size=16 text+tag in: 332s | 72 ac 84 93 e3 a5 22 8b 5d 13 0a 69 d2 51 0e 42 r.....".]..i.Q.B 332s | verify_bytes() empty string: output ciphertext: ok 332s | verify_bytes() empty string: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 72 ac 84 93 e3 a5 22 8b 5d 13 0a 69 d2 51 0e 42 r.....".]..i.Q.B 332s | test_gcm_vector() ENCRYPT: aad-size=0 salt-size=4 wire-IV-size=8 text-size=0 tag-size=16 text+tag in: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | verify_bytes() empty string: output ciphertext: ok 332s | verify_bytes() empty string: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 72 ac 84 93 e3 a5 22 8b 5d 13 0a 69 d2 51 0e 42 r.....".]..i.Q.B 332s ipsec algparse: one block 332s | decode_to_chunk() raw_key: input "0xe98b72a9881a84ca6b76e0f43e68647a" 332s | decode_to_chunk() output: 332s | e9 8b 72 a9 88 1a 84 ca 6b 76 e0 f4 3e 68 64 7a ..r.....kv..>hdz 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7390 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_GCM 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72e0 332s | decode_to_chunk() salted IV: input "0x8b23299fde174053f3d652ba" 332s | decode_to_chunk() output: 332s | 8b 23 29 9f de 17 40 53 f3 d6 52 ba .#)...@S..R. 332s | decode_to_chunk() AAD: input "" 332s | decode_to_chunk() output: 332s | 332s | decode_to_chunk() plaintext: input "0x28286a321293253c3e0aa2704a278032" 332s | decode_to_chunk() output: 332s | 28 28 6a 32 12 93 25 3c 3e 0a a2 70 4a 27 80 32 ((j2..%<>..pJ'.2 332s | decode_to_chunk() ciphertext: input "0x5a3c1cf1985dbb8bed818036fdd5ab42" 332s | decode_to_chunk() output: 332s | 5a 3c 1c f1 98 5d bb 8b ed 81 80 36 fd d5 ab 42 Z<...].....6...B 332s | decode_to_chunk() tag: input "0x23c7ab0f952b7091cd324835043b5eb5" 332s | decode_to_chunk() output: 332s | 23 c7 ab 0f 95 2b 70 91 cd 32 48 35 04 3b 5e b5 #....+p..2H5.;^. 332s | test_gcm_vector() DECRYPT: aad-size=0 salt-size=4 wire-IV-size=8 text-size=16 tag-size=16 text+tag in: 332s | 5a 3c 1c f1 98 5d bb 8b ed 81 80 36 fd d5 ab 42 Z<...].....6...B 332s | 23 c7 ab 0f 95 2b 70 91 cd 32 48 35 04 3b 5e b5 #....+p..2H5.;^. 332s | verify_bytes() one block: output ciphertext: ok 332s | verify_bytes() one block: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 28 28 6a 32 12 93 25 3c 3e 0a a2 70 4a 27 80 32 ((j2..%<>..pJ'.2 332s | 23 c7 ab 0f 95 2b 70 91 cd 32 48 35 04 3b 5e b5 #....+p..2H5.;^. 332s | test_gcm_vector() ENCRYPT: aad-size=0 salt-size=4 wire-IV-size=8 text-size=16 tag-size=16 text+tag in: 332s | 28 28 6a 32 12 93 25 3c 3e 0a a2 70 4a 27 80 32 ((j2..%<>..pJ'.2 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | verify_bytes() one block: output ciphertext: ok 332s | verify_bytes() one block: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 5a 3c 1c f1 98 5d bb 8b ed 81 80 36 fd d5 ab 42 Z<...].....6...B 332s | 23 c7 ab 0f 95 2b 70 91 cd 32 48 35 04 3b 5e b5 #....+p..2H5.;^. 332s ipsec algparse: two blocks 332s | decode_to_chunk() raw_key: input "0xbfd414a6212958a607a0f5d3ab48471d" 332s | decode_to_chunk() output: 332s | bf d4 14 a6 21 29 58 a6 07 a0 f5 d3 ab 48 47 1d ....!)X......HG. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7390 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_GCM 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72e0 332s | decode_to_chunk() salted IV: input "0x86d8ea0ab8e40dcc481cd0e2" 332s | decode_to_chunk() output: 332s | 86 d8 ea 0a b8 e4 0d cc 48 1c d0 e2 ........H... 332s | decode_to_chunk() AAD: input "" 332s | decode_to_chunk() output: 332s | 332s | decode_to_chunk() plaintext: input "0xa6b76a066e63392c9443e60272ceaeb9d25c991b0f2e55e2804e168c05ea591a" 332s | decode_to_chunk() output: 332s | a6 b7 6a 06 6e 63 39 2c 94 43 e6 02 72 ce ae b9 ..j.nc9,.C..r... 332s | d2 5c 99 1b 0f 2e 55 e2 80 4e 16 8c 05 ea 59 1a .\....U..N....Y. 332s | decode_to_chunk() ciphertext: input "0x62171db33193292d930bf6647347652c1ef33316d7feca99d54f1db4fcf513f8" 332s | decode_to_chunk() output: 332s | 62 17 1d b3 31 93 29 2d 93 0b f6 64 73 47 65 2c b...1.)-...dsGe, 332s | 1e f3 33 16 d7 fe ca 99 d5 4f 1d b4 fc f5 13 f8 ..3......O...... 332s | decode_to_chunk() tag: input "0xc28280aa5c6c7a8bd366f28c1cfd1f6e" 332s | decode_to_chunk() output: 332s | c2 82 80 aa 5c 6c 7a 8b d3 66 f2 8c 1c fd 1f 6e ....\lz..f.....n 332s | test_gcm_vector() DECRYPT: aad-size=0 salt-size=4 wire-IV-size=8 text-size=32 tag-size=16 text+tag in: 332s | 62 17 1d b3 31 93 29 2d 93 0b f6 64 73 47 65 2c b...1.)-...dsGe, 332s | 1e f3 33 16 d7 fe ca 99 d5 4f 1d b4 fc f5 13 f8 ..3......O...... 332s | c2 82 80 aa 5c 6c 7a 8b d3 66 f2 8c 1c fd 1f 6e ....\lz..f.....n 332s | verify_bytes() two blocks: output ciphertext: ok 332s | verify_bytes() two blocks: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | a6 b7 6a 06 6e 63 39 2c 94 43 e6 02 72 ce ae b9 ..j.nc9,.C..r... 332s | d2 5c 99 1b 0f 2e 55 e2 80 4e 16 8c 05 ea 59 1a .\....U..N....Y. 332s | c2 82 80 aa 5c 6c 7a 8b d3 66 f2 8c 1c fd 1f 6e ....\lz..f.....n 332s | test_gcm_vector() ENCRYPT: aad-size=0 salt-size=4 wire-IV-size=8 text-size=32 tag-size=16 text+tag in: 332s | a6 b7 6a 06 6e 63 39 2c 94 43 e6 02 72 ce ae b9 ..j.nc9,.C..r... 332s | d2 5c 99 1b 0f 2e 55 e2 80 4e 16 8c 05 ea 59 1a .\....U..N....Y. 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | verify_bytes() two blocks: output ciphertext: ok 332s | verify_bytes() two blocks: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 62 17 1d b3 31 93 29 2d 93 0b f6 64 73 47 65 2c b...1.)-...dsGe, 332s | 1e f3 33 16 d7 fe ca 99 d5 4f 1d b4 fc f5 13 f8 ..3......O...... 332s | c2 82 80 aa 5c 6c 7a 8b d3 66 f2 8c 1c fd 1f 6e ....\lz..f.....n 332s ipsec algparse: two blocks with associated data 332s | decode_to_chunk() raw_key: input "0x95bcde70c094f04e3dd8259cafd88ce8" 332s | decode_to_chunk() output: 332s | 95 bc de 70 c0 94 f0 4e 3d d8 25 9c af d8 8c e8 ...p...N=.%..... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7390 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_GCM 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72e0 332s | decode_to_chunk() salted IV: input "0x12cf097ad22380432ff40a5c" 332s | decode_to_chunk() output: 332s | 12 cf 09 7a d2 23 80 43 2f f4 0a 5c ...z.#.C/..\ 332s | decode_to_chunk() AAD: input "0xc783a0cca10a8d9fb8d27d69659463f2" 332s | decode_to_chunk() output: 332s | c7 83 a0 cc a1 0a 8d 9f b8 d2 7d 69 65 94 63 f2 ..........}ie.c. 332s | decode_to_chunk() plaintext: input "0x32f51e837a9748838925066d69e87180f34a6437e6b396e5643b34cb2ee4f7b1" 332s | decode_to_chunk() output: 332s | 32 f5 1e 83 7a 97 48 83 89 25 06 6d 69 e8 71 80 2...z.H..%.mi.q. 332s | f3 4a 64 37 e6 b3 96 e5 64 3b 34 cb 2e e4 f7 b1 .Jd7....d;4..... 332s | decode_to_chunk() ciphertext: input "0x8a023ba477f5b809bddcda8f55e09064d6d88aaec99c1e141212ea5b08503660" 332s | decode_to_chunk() output: 332s | 8a 02 3b a4 77 f5 b8 09 bd dc da 8f 55 e0 90 64 ..;.w.......U..d 332s | d6 d8 8a ae c9 9c 1e 14 12 12 ea 5b 08 50 36 60 ...........[.P6` 332s | decode_to_chunk() tag: input "0x562f500dae635d60a769b466e15acd1e" 332s | decode_to_chunk() output: 332s | 56 2f 50 0d ae 63 5d 60 a7 69 b4 66 e1 5a cd 1e V/P..c]`.i.f.Z.. 332s | test_gcm_vector() DECRYPT: aad-size=16 salt-size=4 wire-IV-size=8 text-size=32 tag-size=16 text+tag in: 332s | 8a 02 3b a4 77 f5 b8 09 bd dc da 8f 55 e0 90 64 ..;.w.......U..d 332s | d6 d8 8a ae c9 9c 1e 14 12 12 ea 5b 08 50 36 60 ...........[.P6` 332s | 56 2f 50 0d ae 63 5d 60 a7 69 b4 66 e1 5a cd 1e V/P..c]`.i.f.Z.. 332s | verify_bytes() two blocks with associated data: output ciphertext: ok 332s | verify_bytes() two blocks with associated data: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 32 f5 1e 83 7a 97 48 83 89 25 06 6d 69 e8 71 80 2...z.H..%.mi.q. 332s | f3 4a 64 37 e6 b3 96 e5 64 3b 34 cb 2e e4 f7 b1 .Jd7....d;4..... 332s | 56 2f 50 0d ae 63 5d 60 a7 69 b4 66 e1 5a cd 1e V/P..c]`.i.f.Z.. 332s | test_gcm_vector() ENCRYPT: aad-size=16 salt-size=4 wire-IV-size=8 text-size=32 tag-size=16 text+tag in: 332s | 32 f5 1e 83 7a 97 48 83 89 25 06 6d 69 e8 71 80 2...z.H..%.mi.q. 332s | f3 4a 64 37 e6 b3 96 e5 64 3b 34 cb 2e e4 f7 b1 .Jd7....d;4..... 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | verify_bytes() two blocks with associated data: output ciphertext: ok 332s | verify_bytes() two blocks with associated data: TAG: ok 332s | test_gcm_vector() text+tag out: 332s | 8a 02 3b a4 77 f5 b8 09 bd dc da 8f 55 e0 90 64 ..;.w.......U..d 332s | d6 d8 8a ae c9 9c 1e 14 12 12 ea 5b 08 50 36 60 ...........[.P6` 332s | 56 2f 50 0d ae 63 5d 60 a7 69 b4 66 e1 5a cd 1e V/P..c]`.i.f.Z.. 332s ipsec algparse: testing AES_CTR: 332s ipsec algparse: Encrypting 16 octets using AES-CTR with 128-bit key 332s | decode_to_chunk() raw_key: input "0x AE 68 52 F8 12 10 67 CC 4B F7 A5 76 55 77 F3 9E" 332s | decode_to_chunk() output: 332s | ae 68 52 f8 12 10 67 cc 4b f7 a5 76 55 77 f3 9e .hR...g.K..vUw.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 01 ...0............ 332s | decode_to_chunk() Plaintext: input "0x 53 69 6E 67 6C 65 20 62 6C 6F 63 6B 20 6D 73 67" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() Ciphertext: input "0x E4 09 5D 4F B7 A7 B3 79 2D 61 75 A3 26 13 11 B8" 332s | decode_to_chunk() output: 332s | e4 09 5d 4f b7 a7 b3 79 2d 61 75 a3 26 13 11 b8 ..]O...y-au.&... 332s | decode_to_chunk() expected counter-block: : input "0x 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 02" 332s | decode_to_chunk() output: 332s | 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 02 ...0............ 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356dbd00 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00000030000000000000000000000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x2 for 16 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 128-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 01 ...0............ 332s | decode_to_chunk() Ciphertext: input "0x E4 09 5D 4F B7 A7 B3 79 2D 61 75 A3 26 13 11 B8" 332s | decode_to_chunk() output: 332s | e4 09 5d 4f b7 a7 b3 79 2d 61 75 a3 26 13 11 b8 ..]O...y-au.&... 332s | decode_to_chunk() Plaintext: input "0x 53 69 6E 67 6C 65 20 62 6C 6F 63 6B 20 6D 73 67" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() expected counter-block: : input "0x 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 02" 332s | decode_to_chunk() output: 332s | 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 02 ...0............ 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356dbd00 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00000030000000000000000000000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x2 for 16 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 128-bit key: counter-block: ok 332s ipsec algparse: Encrypting 32 octets using AES-CTR with 128-bit key 332s | decode_to_chunk() raw_key: input "0x 7E 24 06 78 17 FA E0 D7 43 D6 CE 1F 32 53 91 63" 332s | decode_to_chunk() output: 332s | 7e 24 06 78 17 fa e0 d7 43 d6 ce 1f 32 53 91 63 ~$.x....C...2S.c 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 6C B6 DB C0 54 3B 59 DA 48 D9 0B 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 6c b6 db c0 54 3b 59 da 48 d9 0b 00 00 00 01 .l...T;Y.H...... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() Ciphertext: input "0x51 04 A1 06 16 8A 72 D9 79 0D 41 EE 8E DA D3 88EB 2E 1E FC 46 DA 57 C8 FC E6 30 DF 91 41 BE 28" 332s | decode_to_chunk() output: 332s | 51 04 a1 06 16 8a 72 d9 79 0d 41 ee 8e da d3 88 Q.....r.y.A..... 332s | eb 2e 1e fc 46 da 57 c8 fc e6 30 df 91 41 be 28 ....F.W...0..A.( 332s | decode_to_chunk() expected counter-block: : input "0x 00 6C B6 DB C0 54 3B 59 DA 48 D9 0B 00 00 00 03" 332s | decode_to_chunk() output: 332s | 00 6c b6 db c0 54 3b 59 da 48 d9 0b 00 00 00 03 .l...T;Y.H...... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8220 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 006cb6dbc0543b59da48d90b00000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x3 for 32 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 128-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 6C B6 DB C0 54 3B 59 DA 48 D9 0B 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 6c b6 db c0 54 3b 59 da 48 d9 0b 00 00 00 01 .l...T;Y.H...... 332s | decode_to_chunk() Ciphertext: input "0x51 04 A1 06 16 8A 72 D9 79 0D 41 EE 8E DA D3 88EB 2E 1E FC 46 DA 57 C8 FC E6 30 DF 91 41 BE 28" 332s | decode_to_chunk() output: 332s | 51 04 a1 06 16 8a 72 d9 79 0d 41 ee 8e da d3 88 Q.....r.y.A..... 332s | eb 2e 1e fc 46 da 57 c8 fc e6 30 df 91 41 be 28 ....F.W...0..A.( 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() expected counter-block: : input "0x 00 6C B6 DB C0 54 3B 59 DA 48 D9 0B 00 00 00 03" 332s | decode_to_chunk() output: 332s | 00 6c b6 db c0 54 3b 59 da 48 d9 0b 00 00 00 03 .l...T;Y.H...... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8220 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 006cb6dbc0543b59da48d90b00000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x3 for 32 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 128-bit key: counter-block: ok 332s ipsec algparse: Encrypting 36 octets using AES-CTR with 128-bit key 332s | decode_to_chunk() raw_key: input "0x 76 91 BE 03 5E 50 20 A8 AC 6E 61 85 29 F9 A0 DC" 332s | decode_to_chunk() output: 332s | 76 91 be 03 5e 50 20 a8 ac 6e 61 85 29 f9 a0 dc v...^P ..na.)... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 E0 01 7B 27 77 7F 3F 4A 17 86 F0 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 e0 01 7b 27 77 7f 3f 4a 17 86 f0 00 00 00 01 ...{'w.?J....... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F20 21 22 23" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 22 23 !"# 332s | decode_to_chunk() Ciphertext: input "0xC1 CF 48 A8 9F 2F FD D9 CF 46 52 E9 EF DB 72 D745 40 A4 2B DE 6D 78 36 D5 9A 5C EA AE F3 10 5325 B2 07 2F" 332s | decode_to_chunk() output: 332s | c1 cf 48 a8 9f 2f fd d9 cf 46 52 e9 ef db 72 d7 ..H../...FR...r. 332s | 45 40 a4 2b de 6d 78 36 d5 9a 5c ea ae f3 10 53 E@.+.mx6..\....S 332s | 25 b2 07 2f %../ 332s | decode_to_chunk() expected counter-block: : input "0x 00 E0 01 7B 27 77 7F 3F 4A 17 86 F0 00 00 00 04" 332s | decode_to_chunk() output: 332s | 00 e0 01 7b 27 77 7f 3f 4a 17 86 f0 00 00 00 04 ...{'w.?J....... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00e0017b27777f3f4a1786f000000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x4 for 36 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 128-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 E0 01 7B 27 77 7F 3F 4A 17 86 F0 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 e0 01 7b 27 77 7f 3f 4a 17 86 f0 00 00 00 01 ...{'w.?J....... 332s | decode_to_chunk() Ciphertext: input "0xC1 CF 48 A8 9F 2F FD D9 CF 46 52 E9 EF DB 72 D745 40 A4 2B DE 6D 78 36 D5 9A 5C EA AE F3 10 5325 B2 07 2F" 332s | decode_to_chunk() output: 332s | c1 cf 48 a8 9f 2f fd d9 cf 46 52 e9 ef db 72 d7 ..H../...FR...r. 332s | 45 40 a4 2b de 6d 78 36 d5 9a 5c ea ae f3 10 53 E@.+.mx6..\....S 332s | 25 b2 07 2f %../ 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F20 21 22 23" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 22 23 !"# 332s | decode_to_chunk() expected counter-block: : input "0x 00 E0 01 7B 27 77 7F 3F 4A 17 86 F0 00 00 00 04" 332s | decode_to_chunk() output: 332s | 00 e0 01 7b 27 77 7f 3f 4a 17 86 f0 00 00 00 04 ...{'w.?J....... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00e0017b27777f3f4a1786f000000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x4 for 36 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 128-bit key: counter-block: ok 332s ipsec algparse: Encrypting 16 octets using AES-CTR with 192-bit key 332s | decode_to_chunk() raw_key: input "0x16 AF 5B 14 5F C9 F5 79 C1 75 F9 3E 3B FB 0E ED86 3D 06 CC FD B7 85 15" 332s | decode_to_chunk() output: 332s | 16 af 5b 14 5f c9 f5 79 c1 75 f9 3e 3b fb 0e ed ..[._..y.u.>;... 332s | 86 3d 06 cc fd b7 85 15 .=...... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 24 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 24-bytes 332s | base: base-key@0x2aa356db360 (40-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 00 00 48 36 73 3C 14 7D 6D 93 CB 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 00 00 48 36 73 3c 14 7d 6d 93 cb 00 00 00 01 ...H6s<.}m...... 332s | decode_to_chunk() Plaintext: input "0x 53 69 6E 67 6C 65 20 62 6C 6F 63 6B 20 6D 73 67" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() Ciphertext: input "0x 4B 55 38 4F E2 59 C9 C8 4E 79 35 A0 03 CB E9 28" 332s | decode_to_chunk() output: 332s | 4b 55 38 4f e2 59 c9 c8 4e 79 35 a0 03 cb e9 28 KU8O.Y..Ny5....( 332s | decode_to_chunk() expected counter-block: : input "0x 00 00 00 48 36 73 3C 14 7D 6D 93 CB 00 00 00 02" 332s | decode_to_chunk() output: 332s | 00 00 00 48 36 73 3c 14 7d 6d 93 cb 00 00 00 02 ...H6s<.}m...... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356dbce0 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 0000004836733c147d6d93cb00000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x2 for 16 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 192-bit key: encrypt: ok 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 192-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 00 00 48 36 73 3C 14 7D 6D 93 CB 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 00 00 48 36 73 3c 14 7d 6d 93 cb 00 00 00 01 ...H6s<.}m...... 332s | decode_to_chunk() Ciphertext: input "0x 4B 55 38 4F E2 59 C9 C8 4E 79 35 A0 03 CB E9 28" 332s | decode_to_chunk() output: 332s | 4b 55 38 4f e2 59 c9 c8 4e 79 35 a0 03 cb e9 28 KU8O.Y..Ny5....( 332s | decode_to_chunk() Plaintext: input "0x 53 69 6E 67 6C 65 20 62 6C 6F 63 6B 20 6D 73 67" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() expected counter-block: : input "0x 00 00 00 48 36 73 3C 14 7D 6D 93 CB 00 00 00 02" 332s | decode_to_chunk() output: 332s | 00 00 00 48 36 73 3c 14 7d 6d 93 cb 00 00 00 02 ...H6s<.}m...... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356dbce0 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 0000004836733c147d6d93cb00000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x2 for 16 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 192-bit key: decrypt: ok 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 192-bit key: counter-block: ok 332s ipsec algparse: Encrypting 32 octets using AES-CTR with 192-bit key 332s | decode_to_chunk() raw_key: input "0x7C 5C B2 40 1B 3D C3 3C 19 E7 34 08 19 E0 F6 9C67 8C 3D B8 E6 F6 A9 1A" 332s | decode_to_chunk() output: 332s | 7c 5c b2 40 1b 3d c3 3c 19 e7 34 08 19 e0 f6 9c |\.@.=.<..4..... 332s | 67 8c 3d b8 e6 f6 a9 1a g.=..... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 24 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 24-bytes 332s | base: base-key@0x2aa356db360 (40-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 96 B0 3B 02 0C 6E AD C2 CB 50 0D 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 96 b0 3b 02 0c 6e ad c2 cb 50 0d 00 00 00 01 ...;..n...P..... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() Ciphertext: input "0x45 32 43 FC 60 9B 23 32 7E DF AA FA 71 31 CD 9F84 90 70 1C 5A D4 A7 9C FC 1F E0 FF 42 F4 FB 00" 332s | decode_to_chunk() output: 332s | 45 32 43 fc 60 9b 23 32 7e df aa fa 71 31 cd 9f E2C.`.#2~...q1.. 332s | 84 90 70 1c 5a d4 a7 9c fc 1f e0 ff 42 f4 fb 00 ..p.Z.......B... 332s | decode_to_chunk() expected counter-block: : input "0x 00 96 B0 3B 02 0C 6E AD C2 CB 50 0D 00 00 00 03" 332s | decode_to_chunk() output: 332s | 00 96 b0 3b 02 0c 6e ad c2 cb 50 0d 00 00 00 03 ...;..n...P..... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 0096b03b020c6eadc2cb500d00000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x3 for 32 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 192-bit key: encrypt: ok 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 192-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 96 B0 3B 02 0C 6E AD C2 CB 50 0D 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 96 b0 3b 02 0c 6e ad c2 cb 50 0d 00 00 00 01 ...;..n...P..... 332s | decode_to_chunk() Ciphertext: input "0x45 32 43 FC 60 9B 23 32 7E DF AA FA 71 31 CD 9F84 90 70 1C 5A D4 A7 9C FC 1F E0 FF 42 F4 FB 00" 332s | decode_to_chunk() output: 332s | 45 32 43 fc 60 9b 23 32 7e df aa fa 71 31 cd 9f E2C.`.#2~...q1.. 332s | 84 90 70 1c 5a d4 a7 9c fc 1f e0 ff 42 f4 fb 00 ..p.Z.......B... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() expected counter-block: : input "0x 00 96 B0 3B 02 0C 6E AD C2 CB 50 0D 00 00 00 03" 332s | decode_to_chunk() output: 332s | 00 96 b0 3b 02 0c 6e ad c2 cb 50 0d 00 00 00 03 ...;..n...P..... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 0096b03b020c6eadc2cb500d00000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x3 for 32 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 192-bit key: decrypt: ok 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 192-bit key: counter-block: ok 332s ipsec algparse: Encrypting 36 octets using AES-CTR with 192-bit key 332s | decode_to_chunk() raw_key: input "0x02 BF 39 1E E8 EC B1 59 B9 59 61 7B 09 65 27 9BF5 9B 60 A7 86 D3 E0 FE" 332s | decode_to_chunk() output: 332s | 02 bf 39 1e e8 ec b1 59 b9 59 61 7b 09 65 27 9b ..9....Y.Ya{.e'. 332s | f5 9b 60 a7 86 d3 e0 fe ..`..... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 24 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 24-bytes 332s | base: base-key@0x2aa356db360 (40-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 07 BD FD 5C BD 60 27 8D CC 09 12 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 07 bd fd 5c bd 60 27 8d cc 09 12 00 00 00 01 ....\.`'........ 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F20 21 22 23" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 22 23 !"# 332s | decode_to_chunk() Ciphertext: input "0x96 89 3F C5 5E 5C 72 2F 54 0B 7D D1 DD F7 E7 58D2 88 BC 95 C6 91 65 88 45 36 C8 11 66 2F 21 88AB EE 09 35" 332s | decode_to_chunk() output: 332s | 96 89 3f c5 5e 5c 72 2f 54 0b 7d d1 dd f7 e7 58 ..?.^\r/T.}....X 332s | d2 88 bc 95 c6 91 65 88 45 36 c8 11 66 2f 21 88 ......e.E6..f/!. 332s | ab ee 09 35 ...5 332s | decode_to_chunk() expected counter-block: : input "0x 00 07 BD FD 5C BD 60 27 8D CC 09 12 00 00 00 04" 332s | decode_to_chunk() output: 332s | 00 07 bd fd 5c bd 60 27 8d cc 09 12 00 00 00 04 ....\.`'........ 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 0007bdfd5cbd60278dcc091200000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x4 for 36 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 192-bit key: encrypt: ok 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 192-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 07 BD FD 5C BD 60 27 8D CC 09 12 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 07 bd fd 5c bd 60 27 8d cc 09 12 00 00 00 01 ....\.`'........ 332s | decode_to_chunk() Ciphertext: input "0x96 89 3F C5 5E 5C 72 2F 54 0B 7D D1 DD F7 E7 58D2 88 BC 95 C6 91 65 88 45 36 C8 11 66 2F 21 88AB EE 09 35" 332s | decode_to_chunk() output: 332s | 96 89 3f c5 5e 5c 72 2f 54 0b 7d d1 dd f7 e7 58 ..?.^\r/T.}....X 332s | d2 88 bc 95 c6 91 65 88 45 36 c8 11 66 2f 21 88 ......e.E6..f/!. 332s | ab ee 09 35 ...5 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F20 21 22 23" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 22 23 !"# 332s | decode_to_chunk() expected counter-block: : input "0x 00 07 BD FD 5C BD 60 27 8D CC 09 12 00 00 00 04" 332s | decode_to_chunk() output: 332s | 00 07 bd fd 5c bd 60 27 8d cc 09 12 00 00 00 04 ....\.`'........ 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 0007bdfd5cbd60278dcc091200000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x4 for 36 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 192-bit key: decrypt: ok 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 192-bit key: counter-block: ok 332s ipsec algparse: Encrypting 16 octets using AES-CTR with 256-bit key 332s | decode_to_chunk() raw_key: input "0x77 6B EF F2 85 1D B0 6F 4C 8A 05 42 C8 69 6F 6C6A 81 AF 1E EC 96 B4 D3 7F C1 D6 89 E6 C1 C1 04" 332s | decode_to_chunk() output: 332s | 77 6b ef f2 85 1d b0 6f 4c 8a 05 42 c8 69 6f 6c wk.....oL..B.iol 332s | 6a 81 af 1e ec 96 b4 d3 7f c1 d6 89 e6 c1 c1 04 j............... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356db360 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 00 00 60 DB 56 72 C9 7A A8 F0 B2 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 00 00 60 db 56 72 c9 7a a8 f0 b2 00 00 00 01 ...`.Vr.z....... 332s | decode_to_chunk() Plaintext: input "0x 53 69 6E 67 6C 65 20 62 6C 6F 63 6B 20 6D 73 67" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() Ciphertext: input "0x 14 5A D0 1D BF 82 4E C7 56 08 63 DC 71 E3 E0 C0" 332s | decode_to_chunk() output: 332s | 14 5a d0 1d bf 82 4e c7 56 08 63 dc 71 e3 e0 c0 .Z....N.V.c.q... 332s | decode_to_chunk() expected counter-block: : input "0x 00 00 00 60 DB 56 72 C9 7A A8 F0 B2 00 00 00 02" 332s | decode_to_chunk() output: 332s | 00 00 00 60 db 56 72 c9 7a a8 f0 b2 00 00 00 02 ...`.Vr.z....... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356dbce0 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00000060db5672c97aa8f0b200000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x2 for 16 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 256-bit key: encrypt: ok 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 256-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 00 00 60 DB 56 72 C9 7A A8 F0 B2 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 00 00 60 db 56 72 c9 7a a8 f0 b2 00 00 00 01 ...`.Vr.z....... 332s | decode_to_chunk() Ciphertext: input "0x 14 5A D0 1D BF 82 4E C7 56 08 63 DC 71 E3 E0 C0" 332s | decode_to_chunk() output: 332s | 14 5a d0 1d bf 82 4e c7 56 08 63 dc 71 e3 e0 c0 .Z....N.V.c.q... 332s | decode_to_chunk() Plaintext: input "0x 53 69 6E 67 6C 65 20 62 6C 6F 63 6B 20 6D 73 67" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() expected counter-block: : input "0x 00 00 00 60 DB 56 72 C9 7A A8 F0 B2 00 00 00 02" 332s | decode_to_chunk() output: 332s | 00 00 00 60 db 56 72 c9 7a a8 f0 b2 00 00 00 02 ...`.Vr.z....... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356dbce0 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00000060db5672c97aa8f0b200000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x2 for 16 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 256-bit key: decrypt: ok 332s | verify_bytes() Encrypting 16 octets using AES-CTR with 256-bit key: counter-block: ok 332s ipsec algparse: Encrypting 32 octets using AES-CTR with 256-bit key 332s | decode_to_chunk() raw_key: input "0xF6 D6 6D 6B D5 2D 59 BB 07 96 36 58 79 EF F8 86C6 6D D5 1A 5B 6A 99 74 4B 50 59 0C 87 A2 38 84" 332s | decode_to_chunk() output: 332s | f6 d6 6d 6b d5 2d 59 bb 07 96 36 58 79 ef f8 86 ..mk.-Y...6Xy... 332s | c6 6d d5 1a 5b 6a 99 74 4b 50 59 0c 87 a2 38 84 .m..[j.tKPY...8. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356db360 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 FA AC 24 C1 58 5E F1 5A 43 D8 75 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 fa ac 24 c1 58 5e f1 5a 43 d8 75 00 00 00 01 ...$.X^.ZC.u.... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() Ciphertext: input "0xF0 5E 23 1B 38 94 61 2C 49 EE 00 0B 80 4E B2 A9B8 30 6B 50 8F 83 9D 6A 55 30 83 1D 93 44 AF 1C" 332s | decode_to_chunk() output: 332s | f0 5e 23 1b 38 94 61 2c 49 ee 00 0b 80 4e b2 a9 .^#.8.a,I....N.. 332s | b8 30 6b 50 8f 83 9d 6a 55 30 83 1d 93 44 af 1c .0kP...jU0...D.. 332s | decode_to_chunk() expected counter-block: : input "0x 00 FA AC 24 C1 58 5E F1 5A 43 D8 75 00 00 00 03" 332s | decode_to_chunk() output: 332s | 00 fa ac 24 c1 58 5e f1 5a 43 d8 75 00 00 00 03 ...$.X^.ZC.u.... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00faac24c1585ef15a43d87500000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x3 for 32 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 256-bit key: encrypt: ok 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 256-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 FA AC 24 C1 58 5E F1 5A 43 D8 75 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 fa ac 24 c1 58 5e f1 5a 43 d8 75 00 00 00 01 ...$.X^.ZC.u.... 332s | decode_to_chunk() Ciphertext: input "0xF0 5E 23 1B 38 94 61 2C 49 EE 00 0B 80 4E B2 A9B8 30 6B 50 8F 83 9D 6A 55 30 83 1D 93 44 AF 1C" 332s | decode_to_chunk() output: 332s | f0 5e 23 1b 38 94 61 2c 49 ee 00 0b 80 4e b2 a9 .^#.8.a,I....N.. 332s | b8 30 6b 50 8f 83 9d 6a 55 30 83 1d 93 44 af 1c .0kP...jU0...D.. 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() expected counter-block: : input "0x 00 FA AC 24 C1 58 5E F1 5A 43 D8 75 00 00 00 03" 332s | decode_to_chunk() output: 332s | 00 fa ac 24 c1 58 5e f1 5a 43 d8 75 00 00 00 03 ...$.X^.ZC.u.... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 00faac24c1585ef15a43d87500000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x3 for 32 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 256-bit key: decrypt: ok 332s | verify_bytes() Encrypting 32 octets using AES-CTR with 256-bit key: counter-block: ok 332s ipsec algparse: Encrypting 36 octets using AES-CTR with 256-bit key 332s | decode_to_chunk() raw_key: input "0xFF 7A 61 7C E6 91 48 E4 F1 72 6E 2F 43 58 1D E2AA 62 D9 F8 05 53 2E DF F1 EE D6 87 FB 54 15 3D" 332s | decode_to_chunk() output: 332s | ff 7a 61 7c e6 91 48 e4 f1 72 6e 2f 43 58 1d e2 .za|..H..rn/CX.. 332s | aa 62 d9 f8 05 53 2e df f1 ee d6 87 fb 54 15 3d .b...S.......T.= 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a0 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CTR 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356db360 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f0 332s | decode_to_mac() input counter-block: : input "0x 00 1C C5 B7 51 A5 1D 70 A1 C1 11 48 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 1c c5 b7 51 a5 1d 70 a1 c1 11 48 00 00 00 01 ....Q..p...H.... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F20 21 22 23" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 22 23 !"# 332s | decode_to_chunk() Ciphertext: input "0xEB 6C 52 82 1D 0B BB F7 CE 75 94 46 2A CA 4F AAB4 07 DF 86 65 69 FD 07 F4 8C C0 B5 83 D6 07 1F1E C0 E6 B8" 332s | decode_to_chunk() output: 332s | eb 6c 52 82 1d 0b bb f7 ce 75 94 46 2a ca 4f aa .lR......u.F*.O. 332s | b4 07 df 86 65 69 fd 07 f4 8c c0 b5 83 d6 07 1f ....ei.......... 332s | 1e c0 e6 b8 .... 332s | decode_to_chunk() expected counter-block: : input "0x 00 1C C5 B7 51 A5 1D 70 A1 C1 11 48 00 00 00 04" 332s | decode_to_chunk() output: 332s | 00 1c c5 b7 51 a5 1d 70 a1 c1 11 48 00 00 00 04 ....Q..p...H.... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 001cc5b751a51d70a1c1114800000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x4 for 36 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 256-bit key: encrypt: ok 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 256-bit key: counter-block: ok 332s | decode_to_mac() input counter-block: : input "0x 00 1C C5 B7 51 A5 1D 70 A1 C1 11 48 00 00 00 01" 332s | decode_to_mac() output: 332s | 00 1c c5 b7 51 a5 1d 70 a1 c1 11 48 00 00 00 01 ....Q..p...H.... 332s | decode_to_chunk() Ciphertext: input "0xEB 6C 52 82 1D 0B BB F7 CE 75 94 46 2A CA 4F AAB4 07 DF 86 65 69 FD 07 F4 8C C0 B5 83 D6 07 1F1E C0 E6 B8" 332s | decode_to_chunk() output: 332s | eb 6c 52 82 1d 0b bb f7 ce 75 94 46 2a ca 4f aa .lR......u.F*.O. 332s | b4 07 df 86 65 69 fd 07 f4 8c c0 b5 83 d6 07 1f ....ei.......... 332s | 1e c0 e6 b8 .... 332s | decode_to_chunk() Plaintext: input "0x00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F20 21 22 23" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 22 23 !"# 332s | decode_to_chunk() expected counter-block: : input "0x 00 1C C5 B7 51 A5 1D 70 A1 C1 11 48 00 00 00 04" 332s | decode_to_chunk() output: 332s | 00 1c c5 b7 51 a5 1d 70 a1 c1 11 48 00 00 00 04 ....Q..p...H.... 332s | cipher_op_ctr_nss() enter AES_CTR 0x2aa356d8080 use IKEv1 IV wire_iv 0 count 0 332s | ctr_param: count 32 iv 001cc5b751a51d70a1c1114800000001 332s | cipher_op_ctr_nss() counter-block updated from 0x1 to 0x4 for 36 bytes 332s | do_aes_ctr: exit 332s | cipher_op_context_destroy_ctr_nss() 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 256-bit key: decrypt: ok 332s | verify_bytes() Encrypting 36 octets using AES-CTR with 256-bit key: counter-block: ok 332s ipsec algparse: testing AES_CBC: 332s ipsec algparse: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key 332s | decode_to_chunk() raw_key: input "0x06a9214036b8a15b512e03d534120006" 332s | decode_to_chunk() output: 332s | 06 a9 21 40 36 b8 a1 5b 51 2e 03 d5 34 12 00 06 ..!@6..[Q...4... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x3dafba429d9eb430b422da802c9fac41" 332s | decode_to_mac() output: 332s | 3d af ba 42 9d 9e b4 30 b4 22 da 80 2c 9f ac 41 =..B...0."..,..A 332s | decode_to_chunk() new IV: : input "0xe353779c1079aeb82708942dbe77181a" 332s | decode_to_chunk() output: 332s | e3 53 77 9c 10 79 ae b8 27 08 94 2d be 77 18 1a .Sw..y..'..-.w.. 332s | decode_to_chunk() plaintext: : input "Single block msg" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | decode_to_chunk() ciphertext: : input "0xe353779c1079aeb82708942dbe77181a" 332s | decode_to_chunk() output: 332s | e3 53 77 9c 10 79 ae b8 27 08 94 2d be 77 18 1a .Sw..y..'..-.w.. 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x3dafba429d9eb430b422da802c9fac41" 332s | decode_to_mac() output: 332s | 3d af ba 42 9d 9e b4 30 b4 22 da 80 2c 9f ac 41 =..B...0."..,..A 332s | decode_to_chunk() new IV: : input "0xe353779c1079aeb82708942dbe77181a" 332s | decode_to_chunk() output: 332s | e3 53 77 9c 10 79 ae b8 27 08 94 2d be 77 18 1a .Sw..y..'..-.w.. 332s | decode_to_chunk() ciphertext: : input "0xe353779c1079aeb82708942dbe77181a" 332s | decode_to_chunk() output: 332s | e3 53 77 9c 10 79 ae b8 27 08 94 2d be 77 18 1a .Sw..y..'..-.w.. 332s | decode_to_chunk() plaintext: : input "Single block msg" 332s | decode_to_chunk() output: 332s | 53 69 6e 67 6c 65 20 62 6c 6f 63 6b 20 6d 73 67 Single block msg 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key: updated CBC IV: ok 332s ipsec algparse: Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key 332s | decode_to_chunk() raw_key: input "0xc286696d887c9aa0611bbb3e2025a45a" 332s | decode_to_chunk() output: 332s | c2 86 69 6d 88 7c 9a a0 61 1b bb 3e 20 25 a4 5a ..im.|..a..> %.Z 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x562e17996d093d28ddb3ba695a2e6f58" 332s | decode_to_mac() output: 332s | 56 2e 17 99 6d 09 3d 28 dd b3 ba 69 5a 2e 6f 58 V...m.=(...iZ.oX 332s | decode_to_chunk() new IV: : input "0xd296cd94c2cccf8a3a863028b5e1dc0a7586602d253cfff91b8266bea6d61ab1" 332s | decode_to_chunk() output: 332s | d2 96 cd 94 c2 cc cf 8a 3a 86 30 28 b5 e1 dc 0a ........:.0(.... 332s | 75 86 60 2d 25 3c ff f9 1b 82 66 be a6 d6 1a b1 u.`-%<....f..... 332s | decode_to_chunk() plaintext: : input "0x000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() ciphertext: : input "0xd296cd94c2cccf8a3a863028b5e1dc0a7586602d253cfff91b8266bea6d61ab1" 332s | decode_to_chunk() output: 332s | d2 96 cd 94 c2 cc cf 8a 3a 86 30 28 b5 e1 dc 0a ........:.0(.... 332s | 75 86 60 2d 25 3c ff f9 1b 82 66 be a6 d6 1a b1 u.`-%<....f..... 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x562e17996d093d28ddb3ba695a2e6f58" 332s | decode_to_mac() output: 332s | 56 2e 17 99 6d 09 3d 28 dd b3 ba 69 5a 2e 6f 58 V...m.=(...iZ.oX 332s | decode_to_chunk() new IV: : input "0xd296cd94c2cccf8a3a863028b5e1dc0a7586602d253cfff91b8266bea6d61ab1" 332s | decode_to_chunk() output: 332s | d2 96 cd 94 c2 cc cf 8a 3a 86 30 28 b5 e1 dc 0a ........:.0(.... 332s | 75 86 60 2d 25 3c ff f9 1b 82 66 be a6 d6 1a b1 u.`-%<....f..... 332s | decode_to_chunk() ciphertext: : input "0xd296cd94c2cccf8a3a863028b5e1dc0a7586602d253cfff91b8266bea6d61ab1" 332s | decode_to_chunk() output: 332s | d2 96 cd 94 c2 cc cf 8a 3a 86 30 28 b5 e1 dc 0a ........:.0(.... 332s | 75 86 60 2d 25 3c ff f9 1b 82 66 be a6 d6 1a b1 u.`-%<....f..... 332s | decode_to_chunk() plaintext: : input "0x000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key: updated CBC IV: ok 332s ipsec algparse: Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key 332s | decode_to_chunk() raw_key: input "0x6c3ea0477630ce21a2ce334aa746c2cd" 332s | decode_to_chunk() output: 332s | 6c 3e a0 47 76 30 ce 21 a2 ce 33 4a a7 46 c2 cd l>.Gv0.!..3J.F.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0xc782dc4c098c66cbd9cd27d825682c81" 332s | decode_to_mac() output: 332s | c7 82 dc 4c 09 8c 66 cb d9 cd 27 d8 25 68 2c 81 ...L..f...'.%h,. 332s | decode_to_chunk() new IV: : input "0xd0a02b3836451753d493665d33f0e8862dea54cdb293abc7506939276772f8d5021c19216bad525c8579695d83ba2684" 332s | decode_to_chunk() output: 332s | d0 a0 2b 38 36 45 17 53 d4 93 66 5d 33 f0 e8 86 ..+86E.S..f]3... 332s | 2d ea 54 cd b2 93 ab c7 50 69 39 27 67 72 f8 d5 -.T.....Pi9'gr.. 332s | 02 1c 19 21 6b ad 52 5c 85 79 69 5d 83 ba 26 84 ...!k.R\.yi]..&. 332s | decode_to_chunk() plaintext: : input "This is a 48-byte message (exactly 3 AES blocks)" 332s | decode_to_chunk() output: 332s | 54 68 69 73 20 69 73 20 61 20 34 38 2d 62 79 74 This is a 48-byt 332s | 65 20 6d 65 73 73 61 67 65 20 28 65 78 61 63 74 e message (exact 332s | 6c 79 20 33 20 41 45 53 20 62 6c 6f 63 6b 73 29 ly 3 AES blocks) 332s | decode_to_chunk() ciphertext: : input "0xd0a02b3836451753d493665d33f0e8862dea54cdb293abc7506939276772f8d5021c19216bad525c8579695d83ba2684" 332s | decode_to_chunk() output: 332s | d0 a0 2b 38 36 45 17 53 d4 93 66 5d 33 f0 e8 86 ..+86E.S..f]3... 332s | 2d ea 54 cd b2 93 ab c7 50 69 39 27 67 72 f8 d5 -.T.....Pi9'gr.. 332s | 02 1c 19 21 6b ad 52 5c 85 79 69 5d 83 ba 26 84 ...!k.R\.yi]..&. 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0xc782dc4c098c66cbd9cd27d825682c81" 332s | decode_to_mac() output: 332s | c7 82 dc 4c 09 8c 66 cb d9 cd 27 d8 25 68 2c 81 ...L..f...'.%h,. 332s | decode_to_chunk() new IV: : input "0xd0a02b3836451753d493665d33f0e8862dea54cdb293abc7506939276772f8d5021c19216bad525c8579695d83ba2684" 332s | decode_to_chunk() output: 332s | d0 a0 2b 38 36 45 17 53 d4 93 66 5d 33 f0 e8 86 ..+86E.S..f]3... 332s | 2d ea 54 cd b2 93 ab c7 50 69 39 27 67 72 f8 d5 -.T.....Pi9'gr.. 332s | 02 1c 19 21 6b ad 52 5c 85 79 69 5d 83 ba 26 84 ...!k.R\.yi]..&. 332s | decode_to_chunk() ciphertext: : input "0xd0a02b3836451753d493665d33f0e8862dea54cdb293abc7506939276772f8d5021c19216bad525c8579695d83ba2684" 332s | decode_to_chunk() output: 332s | d0 a0 2b 38 36 45 17 53 d4 93 66 5d 33 f0 e8 86 ..+86E.S..f]3... 332s | 2d ea 54 cd b2 93 ab c7 50 69 39 27 67 72 f8 d5 -.T.....Pi9'gr.. 332s | 02 1c 19 21 6b ad 52 5c 85 79 69 5d 83 ba 26 84 ...!k.R\.yi]..&. 332s | decode_to_chunk() plaintext: : input "This is a 48-byte message (exactly 3 AES blocks)" 332s | decode_to_chunk() output: 332s | 54 68 69 73 20 69 73 20 61 20 34 38 2d 62 79 74 This is a 48-byt 332s | 65 20 6d 65 73 73 61 67 65 20 28 65 78 61 63 74 e message (exact 332s | 6c 79 20 33 20 41 45 53 20 62 6c 6f 63 6b 73 29 ly 3 AES blocks) 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key: updated CBC IV: ok 332s ipsec algparse: Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key 332s | decode_to_chunk() raw_key: input "0x56e47a38c5598974bc46903dba290349" 332s | decode_to_chunk() output: 332s | 56 e4 7a 38 c5 59 89 74 bc 46 90 3d ba 29 03 49 V.z8.Y.t.F.=.).I 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74a8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_CBC 332s | flags: ENCRYPT+DECRYPT 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73f8 332s | decode_to_mac() IV: : input "0x8ce82eefbea0da3c44699ed7db51b7d9" 332s | decode_to_mac() output: 332s | 8c e8 2e ef be a0 da 3c 44 69 9e d7 db 51 b7 d9 ...........U 332s | decode_to_chunk() plaintext: : input "0xa0a1a2a3a4a5a6a7a8a9aaabacadaeafb0b1b2b3b4b5b6b7b8b9babbbcbdbebfc0c1c2c3c4c5c6c7c8c9cacbcccdcecfd0d1d2d3d4d5d6d7d8d9dadbdcdddedf" 332s | decode_to_chunk() output: 332s | a0 a1 a2 a3 a4 a5 a6 a7 a8 a9 aa ab ac ad ae af ................ 332s | b0 b1 b2 b3 b4 b5 b6 b7 b8 b9 ba bb bc bd be bf ................ 332s | c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 ca cb cc cd ce cf ................ 332s | d0 d1 d2 d3 d4 d5 d6 d7 d8 d9 da db dc dd de df ................ 332s | decode_to_chunk() ciphertext: : input "0xc30e32ffedc0774e6aff6af0869f71aa0f3af07a9a31a9c684db207eb0ef8e4e35907aa632c3ffdf868bb7b29d3d46ad83ce9f9a102ee99d49a53e87f4c3da55" 332s | decode_to_chunk() output: 332s | c3 0e 32 ff ed c0 77 4e 6a ff 6a f0 86 9f 71 aa ..2...wNj.j...q. 332s | 0f 3a f0 7a 9a 31 a9 c6 84 db 20 7e b0 ef 8e 4e .:.z.1.... ~...N 332s | 35 90 7a a6 32 c3 ff df 86 8b b7 b2 9d 3d 46 ad 5.z.2........=F. 332s | 83 ce 9f 9a 10 2e e9 9d 49 a5 3e 87 f4 c3 da 55 ........I.>....U 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key: encrypt: ok 332s | verify_bytes() Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key: updated CBC IV: ok 332s | decode_to_mac() IV: : input "0x8ce82eefbea0da3c44699ed7db51b7d9" 332s | decode_to_mac() output: 332s | 8c e8 2e ef be a0 da 3c 44 69 9e d7 db 51 b7 d9 ...........U 332s | decode_to_chunk() ciphertext: : input "0xc30e32ffedc0774e6aff6af0869f71aa0f3af07a9a31a9c684db207eb0ef8e4e35907aa632c3ffdf868bb7b29d3d46ad83ce9f9a102ee99d49a53e87f4c3da55" 332s | decode_to_chunk() output: 332s | c3 0e 32 ff ed c0 77 4e 6a ff 6a f0 86 9f 71 aa ..2...wNj.j...q. 332s | 0f 3a f0 7a 9a 31 a9 c6 84 db 20 7e b0 ef 8e 4e .:.z.1.... ~...N 332s | 35 90 7a a6 32 c3 ff df 86 8b b7 b2 9d 3d 46 ad 5.z.2........=F. 332s | 83 ce 9f 9a 10 2e e9 9d 49 a5 3e 87 f4 c3 da 55 ........I.>....U 332s | decode_to_chunk() plaintext: : input "0xa0a1a2a3a4a5a6a7a8a9aaabacadaeafb0b1b2b3b4b5b6b7b8b9babbbcbdbebfc0c1c2c3c4c5c6c7c8c9cacbcccdcecfd0d1d2d3d4d5d6d7d8d9dadbdcdddedf" 332s | decode_to_chunk() output: 332s | a0 a1 a2 a3 a4 a5 a6 a7 a8 a9 aa ab ac ad ae af ................ 332s | b0 b1 b2 b3 b4 b5 b6 b7 b8 b9 ba bb bc bd be bf ................ 332s | c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 ca cb cc cd ce cf ................ 332s | d0 d1 d2 d3 d4 d5 d6 d7 d8 d9 da db dc dd de df ................ 332s | NSS ike_alg_nss_cbc: AES_CBC - enter (nil) 332s | using IKEv1 IV 332s | NSS ike_alg_nss_cbc: AES_CBC - exit 332s | verify_bytes() Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key: decrypt: ok 332s | verify_bytes() Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key: updated CBC IV: ok 332s ipsec algparse: testing AES_XCBC: 332s ipsec algparse: RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "" 332s | decode_to_chunk() output: 332s | 332s | decode_to_chunk() test_prf_vector: input "0x75f0251d528ac01c4573dfd584d79f29" 332s | decode_to_chunk() output: 332s | 75 f0 25 1d 52 8a c0 1c 45 73 df d5 84 d7 9f 29 u.%.R...Es.....) 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356d82f0 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9ba0 length 0) 332s | 332s | XCBC: data 332s | 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[0] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: M[n] 332s | 332s | XCBC: M[n] 332s | 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 41 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e A....:..X......n 332s | XCBC: MAC 332s | 75 f0 25 1d 52 8a c0 1c 45 73 df d5 84 d7 9f 29 u.%.R...Es.....) 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | 75 f0 25 1d 52 8a c0 1c 45 73 df d5 84 d7 9f 29 u.%.R...Es.....) 332s | chunk output 332s | 75 f0 25 1d 52 8a c0 1c 45 73 df d5 84 d7 9f 29 u.%.R...Es.....) 332s | verify_bytes() RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356d82f0 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@(nil) (size 0) 332s | PRF symkey interface: symkey message-key@NULL 332s | symkey message NULL key has no bytes 332s | XCBC: data 332s | 332s | K extracting all 16 bytes of key@0x2aa356d9c70 332s | K: symkey-key@0x2aa356d9c70 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[0] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: M[n] 332s | 332s | XCBC: M[n] 332s | 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 41 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e A....:..X......n 332s | XCBC: MAC 332s | 75 f0 25 1d 52 8a c0 1c 45 73 df d5 84 d7 9f 29 u.%.R...Es.....) 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc0b0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input extracting all 16 bytes of key@0x2aa356dc0b0 332s | RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: c7 b8 8e ac 71 ad d2 f7 a4 ae 60 fa aa b5 a0 9c 332s | RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input extracted len 16 bytes at 0x2aa356dc090 332s | unwrapped: 332s | 75 f0 25 1d 52 8a c0 1c 45 73 df d5 84 d7 9f 29 u.%.R...Es.....) 332s | verify_bytes() RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input: symkey: ok 332s ipsec algparse: RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0x000102" 332s | decode_to_chunk() output: 332s | 00 01 02 ... 332s | decode_to_chunk() test_prf_vector: input "0x5b376580ae2f19afe7219ceef172756f" 332s | decode_to_chunk() output: 332s | 5b 37 65 80 ae 2f 19 af e7 21 9c ee f1 72 75 6f [7e../...!...ruo 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356d82f0 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9ba0 length 3) 332s | 00 01 02 ... 332s | XCBC: data 332s | 00 01 02 ... 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356db6b0 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[1] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: M[n] 332s | 00 01 02 ... 332s | XCBC: M[n] 332s | 00 01 02 ... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | c1 a6 a9 21 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e ...!.:..X......n 332s | XCBC: MAC 332s | 5b 37 65 80 ae 2f 19 af e7 21 9c ee f1 72 75 6f [7e../...!...ruo 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | 5b 37 65 80 ae 2f 19 af e7 21 9c ee f1 72 75 6f [7e../...!...ruo 332s | chunk output 332s | 5b 37 65 80 ae 2f 19 af e7 21 9c ee f1 72 75 6f [7e../...!...ruo 332s | verify_bytes() RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356d82f0 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 3 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 3-bytes 332s | base: base-key@0x2aa356dc3f0 (19-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 3) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (3-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 3 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (3-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 70 79 da bd 39 73 78 cd 8c f8 ff aa 76 13 f0 6e 332s | symkey message extracted len 16 bytes at 0x2aa356db6b0 332s | unwrapped: 332s | 00 01 02 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 01 02 ... 332s | K extracting all 16 bytes of key@0x2aa356dc0b0 332s | K: symkey-key@0x2aa356dc0b0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[1] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: M[n] 332s | 00 01 02 ... 332s | XCBC: M[n] 332s | 00 01 02 ... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | c1 a6 a9 21 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e ...!.:..X......n 332s | XCBC: MAC 332s | 5b 37 65 80 ae 2f 19 af e7 21 9c ee f1 72 75 6f [7e../...!...ruo 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc3f0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input extracting all 16 bytes of key@0x2aa356dc3f0 332s | RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 65 cd 67 36 92 ce 2d ff a8 b4 cf 97 8f ef 71 01 332s | RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 5b 37 65 80 ae 2f 19 af e7 21 9c ee f1 72 75 6f [7e../...!...ruo 332s | verify_bytes() RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input: symkey: ok 332s ipsec algparse: RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0xd2a246fa349b68a79998a4394ff7a263" 332s | decode_to_chunk() output: 332s | d2 a2 46 fa 34 9b 68 a7 99 98 a4 39 4f f7 a2 63 ..F.4.h....9O..c 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356d82f0 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9ba0 length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | XCBC: Computing E[1] using K2 332s | XCBC: K2 332s | bd 86 2f fb 97 ad 2f b8 f8 b8 91 f6 03 2f 36 cb ../.../....../6. 332s | XCBC: E[n-1] 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: M[n] 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: M[n]^E[n-1]^K2 332s | bd 87 2d f8 93 a8 29 bf f0 b1 9b fd 0f 22 38 c4 ..-...)......"8. 332s | XCBC: MAC 332s | d2 a2 46 fa 34 9b 68 a7 99 98 a4 39 4f f7 a2 63 ..F.4.h....9O..c 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | d2 a2 46 fa 34 9b 68 a7 99 98 a4 39 4f f7 a2 63 ..F.4.h....9O..c 332s | chunk output 332s | d2 a2 46 fa 34 9b 68 a7 99 98 a4 39 4f f7 a2 63 ..F.4.h....9O..c 332s | verify_bytes() RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356d82f0 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 16) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 16 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | symkey message extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | K extracting all 16 bytes of key@0x2aa356dc3f0 332s | K: symkey-key@0x2aa356dc3f0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356d8080 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | XCBC: Computing E[1] using K2 332s | XCBC: K2 332s | bd 86 2f fb 97 ad 2f b8 f8 b8 91 f6 03 2f 36 cb ../.../....../6. 332s | XCBC: E[n-1] 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: M[n] 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: M[n]^E[n-1]^K2 332s | bd 87 2d f8 93 a8 29 bf f0 b1 9b fd 0f 22 38 c4 ..-...)......"8. 332s | XCBC: MAC 332s | d2 a2 46 fa 34 9b 68 a7 99 98 a4 39 4f f7 a2 63 ..F.4.h....9O..c 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc0b0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input extracting all 16 bytes of key@0x2aa356dc0b0 332s | RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 0d 0d 61 c8 ce 62 23 f1 ba c9 e4 31 09 fd c6 69 332s | RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input extracted len 16 bytes at 0x2aa356d8080 332s | unwrapped: 332s | d2 a2 46 fa 34 9b 68 a7 99 98 a4 39 4f f7 a2 63 ..F.4.h....9O..c 332s | verify_bytes() RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input: symkey: ok 332s ipsec algparse: RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f10111213" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | decode_to_chunk() test_prf_vector: input "0x47f51b4564966215b8985c63055ed308" 332s | decode_to_chunk() output: 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356d82f0 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9ba0 length 20) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356db9a0 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[2] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 1d 04 48 fa cf 4d 9c 6f 55 b9 93 da 09 80 3d b3 ..H..M.oU.....=. 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | cc b2 f1 48 ed 77 08 69 0d be 33 56 c1 6e ed dd ...H.w.i..3V.n.. 332s | XCBC: MAC 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | chunk output 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | verify_bytes() RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356d82f0 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 20 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 20-bytes 332s | base: base-key@0x2aa356dc3f0 (36-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 20) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 20 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 7c 62 75 05 e3 58 a9 24 bd 7f 9f 2c b8 78 0b 52 332s | symkey message extracted len 32 bytes at 0x2aa356dbd20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | K extracting all 16 bytes of key@0x2aa356dc0b0 332s | K: symkey-key@0x2aa356dc0b0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356db6b0 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[2] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 1d 04 48 fa cf 4d 9c 6f 55 b9 93 da 09 80 3d b3 ..H..M.oU.....=. 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | cc b2 f1 48 ed 77 08 69 0d be 33 56 c1 6e ed dd ...H.w.i..3V.n.. 332s | XCBC: MAC 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc3f0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input extracting all 16 bytes of key@0x2aa356dc3f0 332s | RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 29 2b a6 31 65 3e be c0 f2 80 52 4f 9f 45 81 88 332s | RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input extracted len 16 bytes at 0x2aa356db6b0 332s | unwrapped: 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | verify_bytes() RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input: symkey: ok 332s ipsec algparse: RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | decode_to_chunk() test_prf_vector: input "0xf54f0ec8d2b9f3d36807734bd5283fd4" 332s | decode_to_chunk() output: 332s | f5 4f 0e c8 d2 b9 f3 d3 68 07 73 4b d5 28 3f d4 .O......h.sK.(?. 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356dbd20 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d82f0 length 32) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | XCBC: Computing E[2] using K2 332s | XCBC: K2 332s | bd 86 2f fb 97 ad 2f b8 f8 b8 91 f6 03 2f 36 cb ../.../....../6. 332s | XCBC: E[n-1] 332s | 1d 04 48 fa cf 4d 9c 6f 55 b9 93 da 09 80 3d b3 ..H..M.oU.....=. 332s | XCBC: M[n] 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | XCBC: M[n]^E[n-1]^K2 332s | b0 93 75 12 4c f5 a5 c0 b5 18 18 37 16 b2 15 67 ..u.L......7...g 332s | XCBC: MAC 332s | f5 4f 0e c8 d2 b9 f3 d3 68 07 73 4b d5 28 3f d4 .O......h.sK.(?. 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | f5 4f 0e c8 d2 b9 f3 d3 68 07 73 4b d5 28 3f d4 .O......h.sK.(?. 332s | chunk output 332s | f5 4f 0e c8 d2 b9 f3 d3 68 07 73 4b d5 28 3f d4 .O......h.sK.(?. 332s | verify_bytes() RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356dbd20 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356dc0b0 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 32) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 32 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 41 09 3e 5d cd 0a 67 b8 4f d9 f9 92 50 7d 9b 35 332s | symkey message extracted len 32 bytes at 0x2aa356dca10 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | K extracting all 16 bytes of key@0x2aa356dc3f0 332s | K: symkey-key@0x2aa356dc3f0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | XCBC: Computing E[2] using K2 332s | XCBC: K2 332s | bd 86 2f fb 97 ad 2f b8 f8 b8 91 f6 03 2f 36 cb ../.../....../6. 332s | XCBC: E[n-1] 332s | 1d 04 48 fa cf 4d 9c 6f 55 b9 93 da 09 80 3d b3 ..H..M.oU.....=. 332s | XCBC: M[n] 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | XCBC: M[n]^E[n-1]^K2 332s | b0 93 75 12 4c f5 a5 c0 b5 18 18 37 16 b2 15 67 ..u.L......7...g 332s | XCBC: MAC 332s | f5 4f 0e c8 d2 b9 f3 d3 68 07 73 4b d5 28 3f d4 .O......h.sK.(?. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc0b0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input extracting all 16 bytes of key@0x2aa356dc0b0 332s | RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 15 50 d7 94 8c 47 31 23 77 4f a5 7b 31 8d ea 50 332s | RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input extracted len 16 bytes at 0x2aa356db9a0 332s | unwrapped: 332s | f5 4f 0e c8 d2 b9 f3 d3 68 07 73 4b d5 28 3f d4 .O......h.sK.(?. 332s | verify_bytes() RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input: symkey: ok 332s ipsec algparse: RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f2021" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 ! 332s | decode_to_chunk() test_prf_vector: input "0xbecbb3bccdb518a30677d5481fb6b4d8" 332s | decode_to_chunk() output: 332s | be cb b3 bc cd b5 18 a3 06 77 d5 48 1f b6 b4 d8 .........w.H.... 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356d9ba0 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356d82f0 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d8320 length 34) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 ! 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 ! 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[3] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 09 02 5e 5a 67 25 20 72 44 14 5c 6b 80 66 85 79 ..^Zg% rD.\k.f.y 332s | XCBC: M[n] 332s | 20 21 ! 332s | XCBC: M[n] 332s | 20 21 ! 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | e8 84 75 fb c5 1f b4 74 1c 13 fc e7 48 88 55 17 ..u....t....H.U. 332s | XCBC: MAC 332s | be cb b3 bc cd b5 18 a3 06 77 d5 48 1f b6 b4 d8 .........w.H.... 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | be cb b3 bc cd b5 18 a3 06 77 d5 48 1f b6 b4 d8 .........w.H.... 332s | chunk output 332s | be cb b3 bc cd b5 18 a3 06 77 d5 48 1f b6 b4 d8 .........w.H.... 332s | verify_bytes() RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356d82f0 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 34 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 34-bytes 332s | base: base-key@0x2aa356dc3f0 (50-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 34) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (34-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 34 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (34-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 48 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 41 09 3e 5d cd 0a 67 b8 4f d9 f9 92 50 7d 9b 35 dc 94 98 ca d5 51 4b a5 d2 f6 bd 45 1e 67 96 df 332s | symkey message extracted len 48 bytes at 0x2aa356db9c0 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 00 00 00 00 00 00 00 00 00 00 00 00 00 00 !.............. 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f ................ 332s | 20 21 ! 332s | K extracting all 16 bytes of key@0x2aa356dc0b0 332s | K: symkey-key@0x2aa356dc0b0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[3] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 09 02 5e 5a 67 25 20 72 44 14 5c 6b 80 66 85 79 ..^Zg% rD.\k.f.y 332s | XCBC: M[n] 332s | 20 21 ! 332s | XCBC: M[n] 332s | 20 21 ! 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | e8 84 75 fb c5 1f b4 74 1c 13 fc e7 48 88 55 17 ..u....t....H.U. 332s | XCBC: MAC 332s | be cb b3 bc cd b5 18 a3 06 77 d5 48 1f b6 b4 d8 .........w.H.... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc3f0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input extracting all 16 bytes of key@0x2aa356dc3f0 332s | RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: f5 53 53 e2 90 77 c0 d7 3c 54 d7 83 9d 07 f1 aa 332s | RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input extracted len 16 bytes at 0x2aa356db590 332s | unwrapped: 332s | be cb b3 bc cd b5 18 a3 06 77 d5 48 1f b6 b4 d8 .........w.H.... 332s | verify_bytes() RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input: symkey: ok 332s ipsec algparse: RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0xf0dafee895db30253761103b5d84528f" 332s | decode_to_chunk() output: 332s | f0 da fe e8 95 db 30 25 37 61 10 3b 5d 84 52 8f ......0%7a.;].R. 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db6b0 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356dbd20 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9da0 length 1000) 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 ........ 332s | XCBC: data 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 ........ 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[63] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 5c 88 af cc 1e 1e 83 fc c4 2c 0c e4 12 12 f5 17 \........,...... 332s | XCBC: M[n] 332s | 00 00 00 00 00 00 00 00 ........ 332s | XCBC: M[n] 332s | 00 00 00 00 00 00 00 00 ........ 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 9d 2f 04 6d bc 24 17 fa 1c 2b ac 68 da fc 25 79 ./.m.$...+.h..%y 332s | XCBC: MAC 332s | f0 da fe e8 95 db 30 25 37 61 10 3b 5d 84 52 8f ......0%7a.;].R. 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | f0 da fe e8 95 db 30 25 37 61 10 3b 5d 84 52 8f ......0%7a.;].R. 332s | chunk output 332s | f0 da fe e8 95 db 30 25 37 61 10 3b 5d 84 52 8f ......0%7a.;].R. 332s | verify_bytes() RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356dbd20 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 1000 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 1000-bytes 332s | base: base-key@0x2aa356dc0b0 (1016-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 1000) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (1000-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 1000 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (1000-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 1008 332s | wrapper: (SECItemType)682: f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 f9... 332s | symkey message extracted len 1008 bytes at 0x2aa356da980 332s | unwrapped: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | 00 00 00 00 00 00 00 00 ........ 332s | K extracting all 16 bytes of key@0x2aa356dc3f0 332s | K: symkey-key@0x2aa356dc3f0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dbf20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[63] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 5c 88 af cc 1e 1e 83 fc c4 2c 0c e4 12 12 f5 17 \........,...... 332s | XCBC: M[n] 332s | 00 00 00 00 00 00 00 00 ........ 332s | XCBC: M[n] 332s | 00 00 00 00 00 00 00 00 ........ 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 9d 2f 04 6d bc 24 17 fa 1c 2b ac 68 da fc 25 79 ./.m.$...+.h..%y 332s | XCBC: MAC 332s | f0 da fe e8 95 db 30 25 37 61 10 3b 5d 84 52 8f ......0%7a.;].R. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc0b0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input extracting all 16 bytes of key@0x2aa356dc0b0 332s | RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 86 ee 8d 9f ef 23 6b e5 54 43 7f 89 b5 2f ec d9 332s | RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input extracted len 16 bytes at 0x2aa356db9a0 332s | unwrapped: 332s | f0 da fe e8 95 db 30 25 37 61 10 3b 5d 84 52 8f ......0%7a.;].R. 332s | verify_bytes() RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input: symkey: ok 332s ipsec algparse: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f10111213" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | decode_to_chunk() test_prf_vector: input "0x47f51b4564966215b8985c63055ed308" 332s | decode_to_chunk() output: 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 16) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356dbd20 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9ba0 length 20) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356dc730 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[2] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 1d 04 48 fa cf 4d 9c 6f 55 b9 93 da 09 80 3d b3 ..H..M.oU.....=. 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | cc b2 f1 48 ed 77 08 69 0d be 33 56 c1 6e ed dd ...H.w.i..3V.n.. 332s | XCBC: MAC 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | chunk output 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | verify_bytes() RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16): prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc0b0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 16=16 just right 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356dbd20 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 20 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 20-bytes 332s | base: base-key@0x2aa356dc3f0 (36-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356d9c70 (size 20) 332s | PRF symkey interface: symkey message-key@0x2aa356d9c70 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 20 bytes of key@0x2aa356d9c70 332s | symkey message: symkey-key@0x2aa356d9c70 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 7c 62 75 05 e3 58 a9 24 bd 7f 9f 2c b8 78 0b 52 332s | symkey message extracted len 32 bytes at 0x2aa356d82f0 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | K extracting all 16 bytes of key@0x2aa356dc0b0 332s | K: symkey-key@0x2aa356dc0b0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 332s | K extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | XCBC: K1 332s | c3 52 80 57 54 23 7f 31 1a c0 ff f4 e3 e0 3e 78 .R.WT#.1......>x 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[2] using K3 332s | XCBC: K3 332s | c1 a7 ab a1 a2 3a 94 06 58 07 a0 8c c8 ee d0 6e .....:..X......n 332s | XCBC: E[n-1] 332s | 1d 04 48 fa cf 4d 9c 6f 55 b9 93 da 09 80 3d b3 ..H..M.oU.....=. 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | cc b2 f1 48 ed 77 08 69 0d be 33 56 c1 6e ed dd ...H.w.i..3V.n.. 332s | XCBC: MAC 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc3f0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) extracting all 16 bytes of key@0x2aa356dc3f0 332s | RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16): symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 29 2b a6 31 65 3e be c0 f2 80 52 4f 9f 45 81 88 332s | RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) extracted len 16 bytes at 0x2aa356d8220 332s | unwrapped: 332s | 47 f5 1b 45 64 96 62 15 b8 98 5c 63 05 5e d3 08 G..Ed.b...\c.^.. 332s | verify_bytes() RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16): symkey: ok 332s ipsec algparse: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) 332s | decode_to_chunk() test_prf_vector: input "0x00010203040506070809" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 .......... 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f10111213" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | decode_to_chunk() test_prf_vector: input "0x0fa087af7d866e7653434e602fdde835" 332s | decode_to_chunk() output: 332s | 0f a0 87 af 7d 86 6e 76 53 43 4e 60 2f dd e8 35 ....}.nvSCN`/..5 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 10) 332s | 00 01 02 03 04 05 06 07 08 09 .......... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 10 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 10-bytes 332s | base: base-key@0x2aa356db360 (26-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 10<16 too small, padding with zeros 332s | CONCATENATE_BASE_AND_DATA: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356dc3f0 (10-bytes, EXTRACT_KEY_FROM_KEY) 332s | params: 16-bytes@0x3ffe33f7270 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7270 332s | PRF chunk interface PRF AES_XCBC 0x2aa356dbd20 332s | PRF chunk interface PRF AES_XCBC update message (0x2aa356d9ba0 length 20) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | K extracting all 16 bytes of key@0x2aa356d9c70 332s | K: symkey-key@0x2aa356d9c70 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1111695477: ab a7 18 53 1d 68 e4 6e 91 95 61 66 f7 58 4c 55 332s | K extracted len 16 bytes at 0x2aa356db6b0 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 00 00 00 00 00 00 ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 00 00 00 00 00 00 ................ 332s | XCBC: K1 332s | 50 ca b2 4d 03 34 45 5e 40 7b 25 0f dd 7c f8 d5 P..M.4E^@{%..|.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7148 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7150 332s | Computing E[2] using K3 332s | XCBC: K3 332s | 8e f7 48 db 56 f1 f7 26 24 72 f2 c5 63 b0 3f 88 ..H.V..&$r..c.?. 332s | XCBC: E[n-1] 332s | fe 1f 63 e9 65 1a 4b bb 3c cc cd 0d cc 83 e4 30 ..c.e.K.<......0 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 60 f9 39 21 b3 eb bc 9d 18 be 3f c8 af 33 db b8 `.9!......?..3.. 332s | XCBC: MAC 332s | 0f a0 87 af 7d 86 6e 76 53 43 4e 60 2f dd e8 35 ....}.nvSCN`/..5 332s | PRF chunk interface PRF AES_XCBC final length 16 332s | 0f a0 87 af 7d 86 6e 76 53 43 4e 60 2f ddinitializing NSS db 332s running pluto selftest 332s e8 35 ....}.nvSCN`/..5 332s | chunk output 332s | 0f a0 87 af 7d 86 6e 76 53 43 4e 60 2f dd e8 35 ....}.nvSCN`/..5 332s | verify_bytes() RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10): prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 10 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 10-bytes 332s | base: base-key@0x2aa356dc3f0 (26-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC init key symkey-key@0x2aa356d9c70 (size 10) 332s | PRF symkey interface: key symkey-key@0x2aa356d9c70 (10-bytes, EXTRACT_KEY_FROM_KEY) 332s | XCBC: Key 10<16 too small, padding with zeros 332s | CONCATENATE_BASE_AND_DATA: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d9c70 (10-bytes, EXTRACT_KEY_FROM_KEY) 332s | params: 16-bytes@0x3ffe33f7330 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7330 332s | PRF symkey interface PRF AES_XCBC 0x2aa356dbd20 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 20 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 20-bytes 332s | base: base-key@0x2aa356dc0b0 (36-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF AES_XCBC update symkey message-key@0x2aa356dc3f0 (size 20) 332s | PRF symkey interface: symkey message-key@0x2aa356dc3f0 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | symkey message extracting all 20 bytes of key@0x2aa356dc3f0 332s | symkey message: symkey-key@0x2aa356dc3f0 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 7c 62 75 05 e3 58 a9 24 bd 7f 9f 2c b8 78 0b 52 332s | symkey message extracted len 32 bytes at 0x2aa356d8320 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | K extracting all 16 bytes of key@0x2aa356db360 332s | K: symkey-key@0x2aa356db360 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: ab a7 18 53 1d 68 e4 6e 91 95 61 66 f7 58 4c 55 332s | K extracted len 16 bytes at 0x2aa356dc090 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 00 00 00 00 00 00 ................ 332s | XCBC: K: 332s | 00 01 02 03 04 05 06 07 08 09 00 00 00 00 00 00 ................ 332s | XCBC: K1 332s | 50 ca b2 4d 03 34 45 5e 40 7b 25 0f dd 7c f8 d5 P..M.4E^@{%..|.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7188 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7190 332s | Computing E[2] using K3 332s | XCBC: K3 332s | 8e f7 48 db 56 f1 f7 26 24 72 f2 c5 63 b0 3f 88 ..H.V..&$r..c.?. 332s | XCBC: E[n-1] 332s | fe 1f 63 e9 65 1a 4b bb 3c cc cd 0d cc 83 e4 30 ..c.e.K.<......0 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n] 332s | 10 11 12 13 .... 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 60 f9 39 21 b3 eb bc 9d 18 be 3f c8 af 33 db b8 `.9!......?..3.. 332s | XCBC: MAC 332s | 0f a0 87 af 7d 86 6e 76 53 43 4e 60 2f dd e8 35 ....}.nvSCN`/..5 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73a0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc750 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72b0 332s | PRF symkey interface PRF AES_XCBC final-key@0x2aa356dc0b0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) extracting all 16 bytes of key@0x2aa356dc0b0 332s | RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10): symkey-key@0x2aa356dc0b0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 97 b8 db b3 4c f6 fe 29 50 83 73 f4 bc 90 08 cf 332s | RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) extracted len 16 bytes at 0x2aa356dc090 332s | unwrapped: 332s | 0f a0 87 af 7d 86 6e 76 53 43 4e 60 2f dd e8 35 ....}.nvSCN`/..5 332s | verify_bytes() RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10): symkey: ok 332s ipsec algparse: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0fedcb" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | ed cb .. 332s | decode_to_chunk() test_prf_vector: input "0x000102030405060708090a0b0c0d0e0f10111213" 332s | decode_to_chunk() output: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | 10 11 12 13 .... 332s | decode_to_chunk() test_prf_vector: input "0x8cd3c93ae598a9803006ffb67c40e9e4" 332s | decode_to_chunk() output: 332s | 8c d3 c9 3a e5 98 a9 80 30 06 ff b6 7c 40 e9 e4 ...:....0...|@.. 332s | PRF chunk interface PRF AES_XCBC init key hunk 0x2aa356db690 (length 18) 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | ed cb .. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73b0 332s | key-offset: 0, key-size: 18 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 18-bytes 332s | base: base-key@0x2aa356d9c70 (34-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72c0 332s | XCBC: Key 18>16 too big, rehashing to size 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f71b8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f71c0 332s | draft_chunk extracting all 18 bytes of key@0x2aa356dc0b0 332s | draft_chunk: symkey-key@0x2aa356dc0b0 (18-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 2f 41 be c6 4d 54 55 b0 54 3e cf 44 7d 36 34 15 332s | draft_chunk extracted len 32 bytes at 0x2aa356d8320 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | ed cb 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | ed cb .. 332s | K extracting all 16 bytes of key@0x2aa356d9c70 332s | K: symkey-key@0x2aa356d9c70 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 332s | K extracted len 16 bytes at 0x2aa356dc730 332s | unwrapped: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: K: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: K1 332s | e1 4d 5d 0e e2 77 15 df 08 b4 15 2b a2 3d a8 e0 .M]..w.....+.=.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7058 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7060 332s | Computing E[2] using K3 332s | XCBC: K3 332s | 8d 34 ef cb 3b d5 45 ca 06 2a ec df ef 7c 0b fa .4..;.E..*...|.. 332s | XCBC: E[n-1] 332s | 0b 72 b2 ae 0a 37 79 81 75 6a d5 9c 79 c0 e6 96 .r...7y.uj..y... 332s | XCBC: M[n] 332s | ed cb .. 332s | XCBC: M[n] 332s | ed cb .. 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 6b 8d dd 65 31 e2 3c 4b 73 40 39 43 96 bc ed 6c k..e1.16 too big, rehashing to size 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7278 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7280 332s | draft_chunk extracting all 18 bytes of key@0x2aa356dc3f0 332s | draft_chunk: symkey-key@0x2aa356dc3f0 (18-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: siBuffer: 9c 01 a6 f8 a8 c2 b1 16 08 35 4d 8a d0 d3 25 0b 2f 41 be c6 4d 54 55 b0 54 3e cf 44 7d 36 34 15 332s | draft_chunk extracted len 32 bytes at 0x2aa356dbd20 332s | unwrapped: 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | ed cb 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: data 332s | 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f ................ 332s | ed cb .. 332s | K extracting all 16 bytes of key@0x2aa356dc0b0 332s | K: symkey-key@0x2aa356dc0b0 (16-bytes, AES_ECB) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)1023: f9 64 0d a6 9f 86 2d ee cf 09 7f 29 07 69 82 a9 332s | K extracted len 16 bytes at 0x2aa356db590 332s | unwrapped: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: K: 332s | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | XCBC: K1 332s | e1 4d 5d 0e e2 77 15 df 08 b4 15 2b a2 3d a8 e0 .M]..w.....+.=.. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7118 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: AES_ECB 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7120 332s | Computing E[2] using K3 332s | XCBC: K3 332s | 8d 34 ef cb 3b d5 45 ca 06 2a ec df ef 7c 0b fa .4..;.E..*...|.. 332s | XCBC: E[n-1] 332s | 0b 72 b2 ae 0a 37 79 81 75 6a d5 9c 79 c0 e6 96 .r...7y.uj..y... 332s | XCBC: M[n] 332s | ed cb .. 332s | XCBC: M[n] 332s | ed cb .. 332s | XCBC: M[n]:80...^E[n-1]^K3 332s | 6b 8d dd 65 31 e2 3c 4b 73 40 39 43 96 bc ed 6c k..e1.j.....n1.].8 332s | PRF chunk interface PRF HMAC_MD5 init key hunk 0x2aa356d9ba0 (length 4) 332s | 4a 65 66 65 Jefe 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f72f0 332s | key-offset: 0, key-size: 4 332s | EXTRACT_KEY_FROM_KEY: 332s | target: MD5_HMAC 332s | flags: SIGN 332s | key_size: 4-bytes 332s | base: base-key@0x2aa356db360 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72f8 332s | PRF chunk interface prf: created HMAC_MD5 context 0x2aa356db6d0 from key-key@0x2aa356dc3f0 332s | PRF chunk interface prf: begin HMAC_MD5 with context 0x2aa356db6d0 from key-key@0x2aa356dc3f0 332s | PRF chunk interface PRF HMAC_MD5 0x2aa356dbdb0 332s | PRF chunk interface PRF HMAC_MD5 update message (0x2aa356dbd20 length 28) 332s | 77 68 61 74 20 64 6f 20 79 61 20 77 61 6e 74 20 what do ya want 332s | 66 6f 72 20 6e 6f 74 68 69 6e 67 3f for nothing? 332s | PRF chunk interface PRF HMAC_MD5 final length 16 332s | 75 0c 78 3e 6a b0 b5 03 ea a8 6e 31 0a 5d b7 38 u.x>j.....n1.].8 332s | chunk output 332s | 75 0c 78 3e 6a b0 b5 03 ea a8 6e 31 0a 5d b7 38 u.x>j.....n1.].8 332s | verify_bytes() RFC 2104: MD5_HMAC test 2: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 4 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 4-bytes 332s | base: base-key@0x2aa356db360 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF HMAC_MD5 init key symkey-key@0x2aa356dc3f0 (size 4) 332s | PRF symkey interface: key symkey-key@0x2aa356dc3f0 (4-bytes, EXTRACT_KEY_FROM_KEY) 332s | key-offset: 0, key-size: 4 332s | EXTRACT_KEY_FROM_KEY: 332s | target: MD5_HMAC 332s | flags: SIGN 332s | key_size: 4-bytes 332s | base: base-key@0x2aa356dc3f0 (4-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73b0 332s | PRF symkey interface prf: created HMAC_MD5 context 0x2aa356dc890 from key symkey-key@0x2aa356db360 332s | PRF symkey interface prf: begin HMAC_MD5 with context 0x2aa356dc890 from key symkey-key@0x2aa356db360 332s | PRF symkey interface PRF HMAC_MD5 0x2aa356d82f0 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 28 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 28-bytes 332s | base: base-key@0x2aa356d9c70 (44-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF HMAC_MD5 update symkey message-key@0x2aa356dc0b0 (size 28) 332s | PRF symkey interface: symkey message-key@0x2aa356dc0b0 (28-bytes, EXTRACT_KEY_FROM_KEY) 332s | nss hmac digest hack extracting all 28 bytes of key@0x2aa356dc0b0 332s | nss hmac digest hack: symkey-key@0x2aa356dc0b0 (28-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 14 dc 95 ca df fb 59 46 30 60 a5 a1 e6 2e 78 fd fa 07 07 89 6e a4 c6 b2 fb b6 1d 85 54 e9 97 30 332s | nss hmac digest hack extracted len 32 bytes at 0x2aa356e2cc0 332s | unwrapped: 332s | 77 68 61 74 20 64 6f 20 79 61 20 77 61 6e 74 20 what do ya want 332s | 66 6f 72 20 6e 6f 74 68 69 6e 67 3f 00 00 00 00 for nothing?.... 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73c8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72d8 332s | PRF symkey interface PRF HMAC_MD5 final-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 2104: MD5_HMAC test 2 extracting all 16 bytes of key@0x2aa356db360 332s | RFC 2104: MD5_HMAC test 2: symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 11 43 20 40 4a fe f5 fa 52 49 0a 71 74 1c f9 c2 332s | RFC 2104: MD5_HMAC test 2 extracted len 16 bytes at 0x2aa356db6b0 332s | unwrapped: 332s | 75 0c 78 3e 6a b0 b5 03 ea a8 6e 31 0a 5d b7 38 u.x>j.....n1.].8 332s | verify_bytes() RFC 2104: MD5_HMAC test 2: symkey: ok 332s ipsec algparse: RFC 2104: MD5_HMAC test 3 332s | decode_to_chunk() test_prf_vector: input "0xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" 332s | decode_to_chunk() output: 332s | aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa ................ 332s | decode_to_chunk() test_prf_vector: input "0xDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD" 332s | decode_to_chunk() output: 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd .. 332s | decode_to_chunk() test_prf_vector: input "0x56be34521d144c88dbb8c733f0e8b3f6" 332s | decode_to_chunk() output: 332s | 56 be 34 52 1d 14 4c 88 db b8 c7 33 f0 e8 b3 f6 V.4R..L....3.... 332s | PRF chunk interface PRF HMAC_MD5 init key hunk 0x2aa356d8220 (length 16) 332s | aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f72f0 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: MD5_HMAC 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72f8 332s | PRF chunk interface prf: created HMAC_MD5 context 0x2aa356dc7e0 from key-key@0x2aa356db360 332s | PRF chunk interface prf: begin HMAC_MD5 with context 0x2aa356dc7e0 from key-key@0x2aa356db360 332s | PRF chunk interface PRF HMAC_MD5 0x2aa356d8320 332s | PRF chunk interface PRF HMAC_MD5 update message (0x2aa356db320 length 50) 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd .. 332s | PRF chunk interface PRF HMAC_MD5 final length 16 332s | 56 be 34 52 1d 14 4c 88 db b8 c7 33 f0 e8 b3 f6 V.4R..L....3.... 332s | chunk output 332s | 56 be 34 52 1d 14 4c 88 db b8 c7 33 f0 e8 b3 f6 V.4R..L....3.... 332s | verify_bytes() RFC 2104: MD5_HMAC test 3: prf OUT: ok 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF HMAC_MD5 init key symkey-key@0x2aa356db360 (size 16) 332s | PRF symkey interface: key symkey-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: MD5_HMAC 332s | flags: SIGN 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356db360 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f73b0 332s | PRF symkey interface prf: created HMAC_MD5 context 0x2aa356e0c40 from key symkey-key@0x2aa356dc3f0 332s | PRF symkey interface prf: begin HMAC_MD5 with context 0x2aa356e0c40 from key symkey-key@0x2aa356dc3f0 332s | PRF symkey interface PRF HMAC_MD5 0x2aa356dbd20 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f7518 332s | key-offset: 0, key-size: 50 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 50-bytes 332s | base: base-key@0x2aa356d9c70 (66-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7428 332s | PRF symkey interface PRF HMAC_MD5 update symkey message-key@0x2aa356dc0b0 (size 50) 332s | PRF symkey interface: symkey message-key@0x2aa356dc0b0 (50-bytes, EXTRACT_KEY_FROM_KEY) 332s | nss hmac digest hack extracting all 50 bytes of key@0x2aa356dc0b0 332s | nss hmac digest hack: symkey-key@0x2aa356dc0b0 (50-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 64 332s | wrapper: (SECItemType)682: d8 32 ca bc 66 7d 4b d3 33 1b 5e 87 19 8d f2 c8 d8 32 ca bc 66 7d 4b d3 33 1b 5e 87 19 8d f2 c8 d8 32 ca bc 66 7d 4b d3 33 1b 5e 87 19 8d f2 c8 3a 0e 1d 84 f7 3b bf 95 43 3d af e2 fa 98 ca 18 332s | nss hmac digest hack extracted len 64 bytes at 0x2aa356dbde0 332s | unwrapped: 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd ................ 332s | dd dd 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f73c8 332s | key-offset: 0, key-size: 16 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 16-bytes 332s | base: base-key@0x2aa356d9c70 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f72d8 332s | PRF symkey interface PRF HMAC_MD5 final-key@0x2aa356dc3f0 (size 16) 332s | PRF symkey interface: key-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | output: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | RFC 2104: MD5_HMAC test 3 extracting all 16 bytes of key@0x2aa356dc3f0 332s | RFC 2104: MD5_HMAC test 3: symkey-key@0x2aa356dc3f0 (16-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 16 332s | wrapper: (SECItemType)682: 5d de c7 b9 0d 16 65 1c 56 72 29 97 2a 7f 19 cf 332s | RFC 2104: MD5_HMAC test 3 extracted len 16 bytes at 0x2aa356db9a0 332s | unwrapped: 332s | 56 be 34 52 1d 14 4c 88 db b8 c7 33 f0 e8 b3 f6 V.4R..L....3.... 332s | verify_bytes() RFC 2104: MD5_HMAC test 3: symkey: ok 332s ipsec algparse: testing HMAC_SHA1: 332s ipsec algparse: CAVP: IKEv2 key derivation with HMAC-SHA1 332s | decode_to_chunk() test_kdf_vector: input "0x32b50d5f4a3763f3" 332s | decode_to_chunk() output: 332s | 32 b5 0d 5f 4a 37 63 f3 2.._J7c. 332s | decode_to_chunk() test_kdf_vector: input "0x9206a04b26564cb1" 332s | decode_to_chunk() output: 332s | 92 06 a0 4b 26 56 4c b1 ...K&VL. 332s | decode_to_chunk() test_kdf_vector: input "0x34c9e7c188868785" 332s | decode_to_chunk() output: 332s | 34 c9 e7 c1 88 86 87 85 4....... 332s | decode_to_chunk() test_kdf_vector: input "0x3ff77d760d2b2199" 332s | decode_to_chunk() output: 332s | 3f f7 7d 76 0d 2b 21 99 ?.}v.+!. 332s | decode_to_chunk() test_kdf_vector: input "0x4b2c1f971981a8ad8d0abeafabf38cf75fc8349c148142465ed9c8b516b8be52" 332s | decode_to_chunk() output: 332s | 4b 2c 1f 97 19 81 a8 ad 8d 0a be af ab f3 8c f7 K,.............. 332s | 5f c8 34 9c 14 81 42 46 5e d9 c8 b5 16 b8 be 52 _.4...BF^......R 332s | decode_to_chunk() test_kdf_vector: input "0x863f3c9d06efd39d2b907b97f8699e5dd5251ef64a2a176f36ee40c87d4f9330" 332s | decode_to_chunk() output: 332s | 86 3f 3c 9d 06 ef d3 9d 2b 90 7b 97 f8 69 9e 5d .?<.....+.{..i.] 332s | d5 25 1e f6 4a 2a 17 6f 36 ee 40 c8 7d 4f 93 30 .%..J*.o6.@.}O.0 332s | decode_to_chunk() test_kdf_vector: input "0xa9a7b222b59f8f48645f28a1db5b5f5d7479cba7" 332s | decode_to_chunk() output: 332s | a9 a7 b2 22 b5 9f 8f 48 64 5f 28 a1 db 5b 5f 5d ..."...Hd_(..[_] 332s | 74 79 cb a7 ty.. 332s | decode_to_chunk() test_kdf_vector: input "0x63e81194946ebd05df7df5ebf5d8750056bf1f1d" 332s | decode_to_chunk() output: 332s | 63 e8 11 94 94 6e bd 05 df 7d f5 eb f5 d8 75 00 c....n...}....u. 332s | 56 bf 1f 1d V... 332s | decode_to_chunk() test_kdf_vector: input "0xa14293677cc80ff8f9cc0eee30d895da9d8f405666e30ef0dfcb63c634a46002a2a63080e514a062768b76606f9fa5e992204fc5a670bde3f10d6b027113936a5c55b648a194ae587b0088d52204b702c979fa280870d2ed41efa9c549fd11198af1670b143d384bd275c5f594cf266b05ebadca855e4249520a441a81157435a7a56cc4" 332s | decode_to_chunk() output: 332s | a1 42 93 67 7c c8 0f f8 f9 cc 0e ee 30 d8 95 da .B.g|.......0... 332s | 9d 8f 40 56 66 e3 0e f0 df cb 63 c6 34 a4 60 02 ..@Vf.....c.4.`. 332s | a2 a6 30 80 e5 14 a0 62 76 8b 76 60 6f 9f a5 e9 ..0....bv.v`o... 332s | 92 20 4f c5 a6 70 bd e3 f1 0d 6b 02 71 13 93 6a . O..p....k.q..j 332s | 5c 55 b6 48 a1 94 ae 58 7b 00 88 d5 22 04 b7 02 \U.H...X{..."... 332s | c9 79 fa 28 08 70 d2 ed 41 ef a9 c5 49 fd 11 19 .y.(.p..A...I... 332s | 8a f1 67 0b 14 3d 38 4b d2 75 c5 f5 94 cf 26 6b ..g..=8K.u....&k 332s | 05 eb ad ca 85 5e 42 49 52 0a 44 1a 81 15 74 35 .....^BIR.D...t5 332s | a7 a5 6c c4 ..l. 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74f0 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356db360 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7400 332s | NSS_IKE_PRF_DERIVE: 332s | target: NSS_IKE_PRF_PLUS_DERIVE 332s | base: base-key@0x2aa356dc3f0 (32-bytes, EXTRACT_KEY_FROM_KEY) 332s | params: 56-bytes@0x3ffe33f7420 332s | CAVP: IKEv2 key derivation with HMAC-SHA1 extracting all 20 bytes of key@0x2aa356db360 332s | CAVP: IKEv2 key derivation with HMAC-SHA1: symkey-key@0x2aa356db360 (20-bytes, NSS_IKE_PRF_PLUS_DERIVE) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: be 12 14 b3 a7 e9 ef b5 25 c2 f5 2a a7 bf fb a4 b3 1c 27 cf 94 1c d2 9c 4f b8 b9 61 12 9e a2 43 332s | CAVP: IKEv2 key derivation with HMAC-SHA1 extracted len 32 bytes at 0x2aa356dbdb0 332s | unwrapped: 332s | a9 a7 b2 22 b5 9f 8f 48 64 5f 28 a1 db 5b 5f 5d ..."...Hd_(..[_] 332s | 74 79 cb a7 00 00 00 00 00 00 00 00 00 00 00 00 ty.............. 332s | verify_bytes() CAVP: IKEv2 key derivation with HMAC-SHA1: skeyseed: ok 332s | NSS_IKE_PRF_PLUS_DERIVE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 132-bytes 332s | base: base-key@0x2aa356db360 (20-bytes, NSS_IKE_PRF_PLUS_DERIVE) 332s | params: 40-bytes@0x3ffe33f73c0 332s | CAVP: IKEv2 key derivation with HMAC-SHA1 extracting all 132 bytes of key@0x2aa356dc0b0 332s | CAVP: IKEv2 key derivation with HMAC-SHA1: symkey-key@0x2aa356dc0b0 (132-bytes, EXTRACT_KEY_FROM_KEY) 332s | sizeof bytes 144 332s | wrapper: (SECItemType)682: 46 3f 4f 45 20 1a 5b 80 f4 9a c4 70 2a c9 5e e3 78 08 f0 20 b0 72 42 23 f8 62 a4 93 5f 7c ef e0 fa 19 4b 47 41 b0 e7 7e 1e eb b8 9f 28 eb c1 9f ef 09 1d 74 5c 98 07 9f 9e e5 69 88 d6 1b 95 78 88 83 a9 53 e2 6c 21 c3 92 9b ae d5 2e e1 65 ce 16 2e 7a f0 70 7a 1d 3a 12 74 b5 0e 5b 37 cf 08 08 80 65 0e 10 8c 08 80 69 a7 73 a3 3a 76 af dc 22 3d 2a eb 7b 45 ac d8 0f d7 ef 7d 58 ab b9 bd 08 c1 47 9f 29 c6 de 6b e0 d1 34 6e 45 67 0b ac 332s | CAVP: IKEv2 key derivation with HMAC-SHA1 extracted len 144 bytes at 0x2aa356e2a90 332s | unwrapped: 332s | a1 42 93 67 7c c8 0f f8 f9 cc 0e ee 30 d8 95 da .B.g|.......0... 332s | 9d 8f 40 56 66 e3 0e f0 df cb 63 c6 34 a4 60 02 ..@Vf.....c.4.`. 332s | a2 a6 30 80 e5 14 a0 62 76 8b 76 60 6f 9f a5 e9 ..0....bv.v`o... 332s | 92 20 4f c5 a6 70 bd e3 f1 0d 6b 02 71 13 93 6a . O..p....k.q..j 332s | 5c 55 b6 48 a1 94 ae 58 7b 00 88 d5 22 04 b7 02 \U.H...X{..."... 332s | c9 79 fa 28 08 70 d2 ed 41 ef a9 c5 49 fd 11 19 .y.(.p..A...I... 332s | 8a f1 67 0b 14 3d 38 4b d2 75 c5 f5 94 cf 26 6b ..g..=8K.u....&k 332s | 05 eb ad ca 85 5e 42 49 52 0a 44 1a 81 15 74 35 .....^BIR.D...t5 332s | a7 a5 6c c4 00 00 00 00 00 00 00 00 00 00 00 00 ..l............. 332s | verify_bytes() CAVP: IKEv2 key derivation with HMAC-SHA1: DKM: ok 332s | key-offset: 0, key-size: 20 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 20-bytes 332s | base: base-key@0x2aa356dc0b0 (132-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f74f8 332s | CONCATENATE_DATA_AND_BASE: 332s | target: EXTRACT_KEY_FROM_KEY 332s | base: base-key@0x2aa356d8350 (16-bytes, AES_KEY_GEN) 332s | params: 16-bytes@0x3ffe33f74f0 332s | key-offset: 0, key-size: 32 332s | EXTRACT_KEY_FROM_KEY: 332s | target: EXTRACT_KEY_FROM_KEY 332s | key_size: 32-bytes 332s | base: base-key@0x2aa356dc1f0 (48-bytes, EXTRACT_KEY_FROM_KEY) 332s | operation: FLAGS_ONLY 332s | params: 8-bytes@0x3ffe33f7400 332s | NSS_IKE_PRF_DERIVE: 332s | target: NSS_IKE_PRF_PLUS_DERIVE 332s | base: base-key@0x2aa356d9c70 (20-bytes, EXTRACT_KEY_FROM_KEY) 332s | params: 56-bytes@0x3ffe33f7418 332s | CAVP: IKEv2 key derivation with HMAC-SHA1 extracting all 20 bytes of key@0x2aa356dc1f0 332s | CAVP: IKEv2 key derivation with HMAC-SHA1: symkey-key@0x2aa356dc1f0 (20-bytes, NSS_IKE_PRF_PLUS_DERIVE) 332s | sizeof bytes 32 332s | wrapper: (SECItemType)682: 66 33 71 6e 25 1d 4e 6c d1 22 e9 3b 44 fc 21 e3 18 37 71 48 3f 1b e6 d2 33 38 08 1e c8 d2 c6 68 332s | CAVP: IKEv2 key derivation with HMAC-SHA1 extracted len 32 bytes at 0x2aa356d8320 332s | unwrapped: 332s | 63 e8 11 94 94 6e bd 05 df 7d f5 eb f5 d8 75 00 c....n...}....u. 332s | 56 bf 1f 1d 00 00 00 00 00 00 00 00 00 00 00 00 V............... 332s | verify_bytes() CAVP: IKEv2 key derivation with HMAC-SHA1: skeyseed_rekey: ok 332s ipsec algparse: leak detective found no leaks 332s /usr/libexec/ipsec/pluto: adjusting nssdir to /tmp/tmp.1Ht6R9CmGp 332s /usr/libexec/ipsec/pluto: selftest: skipping lock 332s /usr/libexec/ipsec/pluto: selftest: skipping control socket 332s /usr/libexec/ipsec/pluto: selftest: skipping fork 332s Starting Pluto (Libreswan Version 5.2 IKEv2 IKEv1 XFRM XFRMI esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) (NSS-KDF) DNSSEC SYSTEMD_WATCHDOG LABELED_IPSEC (SELINUX) LIBCAP_NG LINUX_AUDIT AUTH_PAM NETWORKMANAGER CURL(non-NSS) LDAP(non-NSS) NFTABLES CAT NFLOG) pid:6398 332s operating system: Linux 6.18.0 [Linux 6.18.0-9-generic #9-Ubuntu SMP Mon Jan 12 15:39:23 UTC 2026 s390x] 332s core dump dir: /run/pluto 332s secrets file: /etc/ipsec.secrets 332s Initializing NSS using read-only database "sql:/tmp/tmp.1Ht6R9CmGp" 332s FIPS Mode: OFF 332s NSS crypto library initialized 332s FIPS mode disabled for pluto daemon 332s FIPS HMAC integrity support [not required] 332s libcap-ng capng_apply failed to apply changes, err=-5. see: man capng_apply 332s libcap-ng support [enabled] 332s Linux audit support [enabled] 332s leak-detective disabled 332s NSS crypto [enabled] 332s XAUTH PAM support [enabled] 332s initializing libevent in pthreads mode: headers: 2.1.12-stable (2010c00); library: 2.1.12-stable (2010c00) 332s NAT-Traversal: keep-alive period 20s 332s ERROR: xfrmi is not supported, failed to create ipsec-interface ipsec1 bound to lo 332s ipsec-interface is not working: xfrmi is not supported 332s IPsec Interface [disabled] 332s refreshed session resume keys, issuing key 1 332s Encryption algorithms: 332s AES_CCM_16 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm, aes_ccm_c 332s AES_CCM_12 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm_b 332s AES_CCM_8 {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_ccm_a 332s 3DES_CBC [*192] IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CBC) 3des 332s CAMELLIA_CTR {256,192,*128} IKEv1: ESP IKEv2: ESP 332s CAMELLIA_CBC {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP NSS(CBC) camellia 332s AES_GCM_16 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm, aes_gcm_c 332s AES_GCM_12 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm_b 332s AES_GCM_8 {256,192,*128} IKEv1: ESP IKEv2: IKE ESP FIPS NSS(AEAD) aes_gcm_a 332s AES_CTR {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CTR) aesctr 332s AES_CBC {256,192,*128} IKEv1: IKE ESP IKEv2: IKE ESP FIPS NSS(CBC) aes 332s NULL_AUTH_AES_GMAC {256,192,*128} IKEv1: ESP IKEv2: ESP FIPS aes_gmac 332s NULL [] IKEv1: ESP IKEv2: ESP NULL 332s CHACHA20_POLY1305 [*256] IKEv1: IKEv2: IKE ESP NSS(AEAD) chacha20poly1305 332s Hash algorithms: 332s MD5 IKEv1: IKE IKEv2: NSS 332s SHA1 IKEv1: IKE IKEv2: IKE FIPS NSS sha 332s SHA2_256 IKEv1: IKE IKEv2: IKE FIPS NSS sha2, sha256 332s SHA2_384 IKEv1: IKE IKEv2: IKE FIPS NSS sha384 332s SHA2_512 IKEv1: IKE IKEv2: IKE FIPS NSS sha512 332s IDENTITY IKEv1: IKEv2: FIPS 332s PRF algorithms: 332s HMAC_MD5 IKEv1: IKE IKEv2: IKE NSS md5 332s HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS NSS sha, sha1 332s HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS NSS sha2, sha256, sha2_256 332s HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS NSS sha384, sha2_384 332s HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS NSS sha512, sha2_512 332s AES_XCBC IKEv1: IKEv2: IKE native(XCBC) aes128_xcbc 332s Integrity algorithms: 332s HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH NSS md5, hmac_md5 332s HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha, sha1, sha1_96, hmac_sha1 332s HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha512, sha2_512, sha2_512_256, hmac_sha2_512 332s HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha384, sha2_384, sha2_384_192, hmac_sha2_384 332s HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 332s HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH 332s AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH native(XCBC) aes_xcbc, aes128_xcbc, aes128_xcbc_96 332s AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac 332s NONE IKEv1: ESP IKEv2: IKE ESP FIPS null 332s DH algorithms: 332s NONE IKEv1: IKEv2: IKE ESP AH FIPS NSS(MODP) null, dh0 332s MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH NSS(MODP) dh5 332s MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh14 332s MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh15 332s MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh16 332s MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh17 332s MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS NSS(MODP) dh18 332s DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_256, ecp256 332s DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_384, ecp384 332s DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS NSS(ECP) ecp_521, ecp521 332s DH31 IKEv1: IKE IKEv2: IKE ESP AH NSS(ECP) curve25519 332s IPCOMP algorithms: 332s DEFLATE IKEv1: ESP AH IKEv2: ESP AH FIPS 332s LZS IKEv1: IKEv2: ESP AH FIPS 332s LZJH IKEv1: IKEv2: ESP AH FIPS 332s testing CAMELLIA_CBC: 332s Camellia: 16 bytes with 128-bit key 332s Camellia: 16 bytes with 128-bit key 332s Camellia: 16 bytes with 256-bit key 332s Camellia: 16 bytes with 256-bit key 332s testing AES_GCM_16: 332s empty string 332s one block 332s two blocks 332s two blocks with associated data 332s testing AES_CTR: 332s Encrypting 16 octets using AES-CTR with 128-bit key 332s Encrypting 32 octets using AES-CTR with 128-bit key 332s Encrypting 36 octets using AES-CTR with 128-bit key 332s Encrypting 16 octets using AES-CTR with 192-bit key 332s Encrypting 32 octets using AES-CTR with 192-bit key 332s Encrypting 36 octets using AES-CTR with 192-bit key 332s Encrypting 16 octets using AES-CTR with 256-bit key 332s Encrypting 32 octets using AES-CTR with 256-bit key 332s Encrypting 36 octets using AES-CTR with 256-bit key 332s testing AES_CBC: 332s Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key 332s Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key 332s Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key 332s Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key 332s testing AES_XCBC: 332s RFC 3566 Test Case 1: AES-XCBC-MAC-96 with 0-byte input 332s RFC 3566 Test Case 2: AES-XCBC-MAC-96 with 3-byte input 332s RFC 3566 Test Case 3: AES-XCBC-MAC-96 with 16-byte input 332s RFC 3566 Test Case 4: AES-XCBC-MAC-96 with 20-byte input 332s RFC 3566 Test Case 5: AES-XCBC-MAC-96 with 32-byte input 332s RFC 3566 Test Case 6: AES-XCBC-MAC-96 with 34-byte input 332s RFC 3566 Test Case 7: AES-XCBC-MAC-96 with 1000-byte input 332s RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) 332s RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) 332s RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) 332s testing HMAC_MD5: 332s RFC 2104: MD5_HMAC test 1 332s RFC 2104: MD5_HMAC test 2 332s RFC 2104: MD5_HMAC test 3 332s testing HMAC_SHA1: 332s CAVP: IKEv2 key derivation with HMAC-SHA1 332s selftest: exiting pluto 333s autopkgtest [06:22:57]: test cryptocheck: -----------------------] 333s autopkgtest [06:22:57]: test cryptocheck: - - - - - - - - - - results - - - - - - - - - - 333s cryptocheck PASS 333s autopkgtest [06:22:57]: test cavp: preparing testbed 354s Creating nova instance adt-resolute-s390x-libreswan-20260203-061724-juju-7f2275-prod-proposed-migration-environment-2-f74c4111-d049-4c60-87aa-23f7d03f22aa from image adt/ubuntu-resolute-s390x-server-20260203.img (UUID 733879ca-10c9-4d0b-9d4a-492c78d47079)... 395s autopkgtest [06:23:59]: testbed dpkg architecture: s390x 396s autopkgtest [06:24:00]: testbed apt version: 3.1.14 396s autopkgtest [06:24:00]: @@@@@@@@@@@@@@@@@@@@ test bed setup 396s autopkgtest [06:24:00]: testbed release detected to be: resolute 397s autopkgtest [06:24:01]: updating testbed package index (apt update) 397s Get:1 http://ftpmaster.internal/ubuntu resolute-proposed InRelease [124 kB] 397s Hit:2 http://ftpmaster.internal/ubuntu resolute InRelease 397s Hit:3 http://ftpmaster.internal/ubuntu resolute-updates InRelease 397s Hit:4 http://ftpmaster.internal/ubuntu resolute-security InRelease 397s Get:5 http://ftpmaster.internal/ubuntu resolute-proposed/multiverse Sources [27.8 kB] 397s Get:6 http://ftpmaster.internal/ubuntu resolute-proposed/universe Sources [1270 kB] 398s Get:7 http://ftpmaster.internal/ubuntu resolute-proposed/main Sources [269 kB] 398s Get:8 http://ftpmaster.internal/ubuntu resolute-proposed/restricted Sources [5260 B] 398s Get:9 http://ftpmaster.internal/ubuntu resolute-proposed/main s390x Packages [295 kB] 398s Get:10 http://ftpmaster.internal/ubuntu resolute-proposed/universe s390x Packages [1037 kB] 398s Get:11 http://ftpmaster.internal/ubuntu resolute-proposed/multiverse s390x Packages [7580 B] 398s Fetched 3036 kB in 1s (3392 kB/s) 399s Reading package lists... 400s Hit:1 http://ftpmaster.internal/ubuntu resolute-proposed InRelease 400s Hit:2 http://ftpmaster.internal/ubuntu resolute InRelease 400s Hit:3 http://ftpmaster.internal/ubuntu resolute-updates InRelease 400s Hit:4 http://ftpmaster.internal/ubuntu resolute-security InRelease 402s Reading package lists... 403s Reading package lists... 403s Building dependency tree... 403s Reading state information... 403s Calculating upgrade... 403s The following packages will be upgraded: 403s ca-certificates systemd-hwe-hwdb 403s 2 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 403s Need to get 166 kB of archives. 403s After this operation, 1024 B of additional disk space will be used. 403s Get:1 http://ftpmaster.internal/ubuntu resolute-proposed/main s390x ca-certificates all 20250419build1 [163 kB] 403s Get:2 http://ftpmaster.internal/ubuntu resolute/main s390x systemd-hwe-hwdb all 259.0.1 [3152 B] 403s dpkg-preconfigure: unable to re-open stdin: No such file or directory 403s Fetched 166 kB in 0s (4070 kB/s) 404s (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 61953 files and directories currently installed.) 404s Preparing to unpack .../ca-certificates_20250419build1_all.deb ... 404s Unpacking ca-certificates (20250419build1) over (20250419) ... 404s Preparing to unpack .../systemd-hwe-hwdb_259.0.1_all.deb ... 404s Unpacking systemd-hwe-hwdb (259.0.1) over (257.7.1) ... 404s Setting up ca-certificates (20250419build1) ... 407s Updating certificates in /etc/ssl/certs... 408s 0 added, 0 removed; done. 408s Setting up systemd-hwe-hwdb (259.0.1) ... 409s Processing triggers for udev (259-1ubuntu3) ... 410s Processing triggers for man-db (2.13.1-1) ... 411s Processing triggers for ca-certificates (20250419build1) ... 411s Updating certificates in /etc/ssl/certs... 412s 0 added, 0 removed; done. 412s Running hooks in /etc/ca-certificates/update.d... 412s done. 412s autopkgtest [06:24:16]: upgrading testbed (apt dist-upgrade and autopurge) 412s Reading package lists... 412s Building dependency tree... 412s Reading state information... 413s Calculating upgrade... 413s 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 413s Reading package lists... 413s Building dependency tree... 413s Reading state information... 413s Solving dependencies... 413s 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. 417s Reading package lists... 417s Building dependency tree... 417s Reading state information... 417s Solving dependencies... 417s The following NEW packages will be installed: 417s dns-root-data libevent-2.1-7t64 libevent-pthreads-2.1-7t64 libldns3t64 417s libnss3-tools libreswan libunbound8 417s 0 upgraded, 7 newly installed, 0 to remove and 0 not upgraded. 417s Need to get 2943 kB of archives. 417s After this operation, 11.8 MB of additional disk space will be used. 417s Get:1 http://ftpmaster.internal/ubuntu resolute/main s390x dns-root-data all 2025080400 [5908 B] 417s Get:2 http://ftpmaster.internal/ubuntu resolute/main s390x libnss3-tools s390x 2:3.120-1 [637 kB] 417s Get:3 http://ftpmaster.internal/ubuntu resolute/main s390x libevent-pthreads-2.1-7t64 s390x 2.1.12-stable-10build1 [8060 B] 417s Get:4 http://ftpmaster.internal/ubuntu resolute/universe s390x libldns3t64 s390x 1.8.4-2build1 [170 kB] 417s Get:5 http://ftpmaster.internal/ubuntu resolute/main s390x libevent-2.1-7t64 s390x 2.1.12-stable-10build1 [144 kB] 417s Get:6 http://ftpmaster.internal/ubuntu resolute/main s390x libunbound8 s390x 1.24.2-1ubuntu1 [464 kB] 417s Get:7 http://ftpmaster.internal/ubuntu resolute/universe s390x libreswan s390x 5.2-2.2ubuntu1 [1515 kB] 418s Fetched 2943 kB in 0s (12.3 MB/s) 418s Selecting previously unselected package dns-root-data. 418s (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 61954 files and directories currently installed.) 418s Preparing to unpack .../0-dns-root-data_2025080400_all.deb ... 418s Unpacking dns-root-data (2025080400) ... 418s Selecting previously unselected package libnss3-tools. 418s Preparing to unpack .../1-libnss3-tools_2%3a3.120-1_s390x.deb ... 418s Unpacking libnss3-tools (2:3.120-1) ... 418s Selecting previously unselected package libevent-pthreads-2.1-7t64:s390x. 418s Preparing to unpack .../2-libevent-pthreads-2.1-7t64_2.1.12-stable-10build1_s390x.deb ... 418s Unpacking libevent-pthreads-2.1-7t64:s390x (2.1.12-stable-10build1) ... 418s Selecting previously unselected package libldns3t64:s390x. 418s Preparing to unpack .../3-libldns3t64_1.8.4-2build1_s390x.deb ... 418s Unpacking libldns3t64:s390x (1.8.4-2build1) ... 418s Selecting previously unselected package libevent-2.1-7t64:s390x. 418s Preparing to unpack .../4-libevent-2.1-7t64_2.1.12-stable-10build1_s390x.deb ... 418s Unpacking libevent-2.1-7t64:s390x (2.1.12-stable-10build1) ... 418s Selecting previously unselected package libunbound8:s390x. 418s Preparing to unpack .../5-libunbound8_1.24.2-1ubuntu1_s390x.deb ... 418s Unpacking libunbound8:s390x (1.24.2-1ubuntu1) ... 418s Selecting previously unselected package libreswan. 418s Preparing to unpack .../6-libreswan_5.2-2.2ubuntu1_s390x.deb ... 418s Unpacking libreswan (5.2-2.2ubuntu1) ... 418s Setting up libldns3t64:s390x (1.8.4-2build1) ... 418s Setting up libevent-pthreads-2.1-7t64:s390x (2.1.12-stable-10build1) ... 418s Setting up libevent-2.1-7t64:s390x (2.1.12-stable-10build1) ... 418s Setting up dns-root-data (2025080400) ... 418s Setting up libunbound8:s390x (1.24.2-1ubuntu1) ... 418s Setting up libnss3-tools (2:3.120-1) ... 418s Setting up libreswan (5.2-2.2ubuntu1) ... 418s ipsec.service is a disabled or a static unit, not starting it. 418s Processing triggers for man-db (2.13.1-1) ... 420s Processing triggers for libc-bin (2.42-2ubuntu4) ... 447s autopkgtest [06:24:51]: test cavp: [----------------------- 447s Testing installed CAVP binary: /usr/libexec/ipsec/cavp 449s test: IKE v2 449s Reading from ikev2.fax 453s test: IKE v1 Digital Signature Authentication 453s Reading from ikev1_dsa.fax 456s test: IKE v1 Pre-shared Key Authentication 456s Reading from ikev1_psk.fax 458s /tmp/autopkgtest.AKBPDo/build.nlM/src 458s autopkgtest [06:25:02]: test cavp: -----------------------] 459s autopkgtest [06:25:03]: test cavp: - - - - - - - - - - results - - - - - - - - - - 459s cavp PASS 459s autopkgtest [06:25:03]: @@@@@@@@@@@@@@@@@@@@ summary 459s opportunistic SKIP exit status 77 and marked as skippable 459s cryptocheck PASS 459s cavp PASS