ikev2: add hint to the log when IDs do not match 47/30947/5
authorFilip Tehlar <ftehlar@cisco.com>
Tue, 26 Jan 2021 22:06:48 +0000 (22:06 +0000)
committerBeno�t Ganne <bganne@cisco.com>
Thu, 4 Feb 2021 18:12:13 +0000 (18:12 +0000)
Type: improvement
Ticket: VPP-1908

Change-Id: I1d86ea18fcb6174b86c449d5d9403fd0e5715318
Signed-off-by: Filip Tehlar <ftehlar@cisco.com>
src/plugins/ikev2/ikev2.c

index 8bb3277..0236764 100644 (file)
@@ -1666,7 +1666,11 @@ ikev2_sa_auth (ikev2_sa_t * sa)
             sel_p = p;
             break;
           }
-
+       else
+         {
+           ikev2_elog_uint (IKEV2_LOG_ERROR, "shared key mismatch! ispi %lx",
+                            sa->ispi);
+         }
       }
     else if (sa_auth->method == IKEV2_AUTH_METHOD_RSA_SIG)
       {
@@ -1679,6 +1683,11 @@ ikev2_sa_auth (ikev2_sa_t * sa)
             sel_p = p;
             break;
           }
+       else
+         {
+           ikev2_elog_uint (IKEV2_LOG_ERROR,
+                            "cert verification failed! ispi %lx", sa->ispi);
+         }
       }
 
     vec_free(auth);