/testing/guestbin/swan-prep
east #
 PATH/bin/pk12util -i /testing/x509/strongswan/strongEast.p12 -d sql:/etc/ipsec.d -w /testing/x509/nss-pw
pk12util: PKCS12 IMPORT SUCCESSFUL
east #
 # Tuomo: why doesn't ipsec checknss --settrust work here?
east #
 certutil -M -d sql:/etc/ipsec.d -n "strongSwan CA - strongSwan" -t CT,,
east #
 #ipsec start
east #
 ipsec pluto --config /etc/ipsec.conf --leak-detective
east #
 ../../guestbin/wait-until-pluto-started
east #
 ipsec auto --add westnet-eastnet-ikev2
002 "westnet-eastnet-ikev2": added IKEv2 connection
east #
 ipsec whack --impair suppress-retransmits
east #
 ipsec whack --impair force-v2-auth-method:ecdsa_sha2_384_p384
east #
 ipsec whack --impair omit-v2n-signature-hash-algorithms
east #
 echo "initdone"
initdone
east #
 ipsec whack --shutdown
east #
 
