<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="et">
	<id>https://kuutorvaja.eenet.ee/w/index.php?action=history&amp;feed=atom&amp;title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine</id>
	<title>OpenVPN ja Eesti ID-kaardi kasutamine - Redigeerimiste ajalugu</title>
	<link rel="self" type="application/atom+xml" href="https://kuutorvaja.eenet.ee/w/index.php?action=history&amp;feed=atom&amp;title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine"/>
	<link rel="alternate" type="text/html" href="https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;action=history"/>
	<updated>2026-04-17T20:07:57Z</updated>
	<subtitle>Selle lehekülje redigeerimiste ajalugu</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;diff=12491&amp;oldid=prev</id>
		<title>Imre: Kustutatud kogu lehekülje sisu</title>
		<link rel="alternate" type="text/html" href="https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;diff=12491&amp;oldid=prev"/>
		<updated>2009-06-26T11:46:21Z</updated>

		<summary type="html">&lt;p&gt;Kustutatud kogu lehekülje sisu&lt;/p&gt;
&lt;a href=&quot;https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;amp;diff=12491&amp;amp;oldid=12488&quot;&gt;Näita muudatusi&lt;/a&gt;</summary>
		<author><name>Imre</name></author>
	</entry>
	<entry>
		<id>https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;diff=12488&amp;oldid=prev</id>
		<title>Imre – 26. juuni 2009, kell 11:08</title>
		<link rel="alternate" type="text/html" href="https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;diff=12488&amp;oldid=prev"/>
		<updated>2009-06-26T11:08:05Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;et&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;←Vanem redaktsioon&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Redaktsioon: 26. juuni 2009, kell 11:08&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;1. rida:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;1. rida:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Eesti ID-kaardi kasutamine&lt;/del&gt;===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Sissejuhatus&lt;/ins&gt;===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;OpenVPN lahendust saab seadistada käima selliselt, et kasutaja autentimiseks kasutatakse tema Eesti ID-kaardi isikutuvastuse ehk autentimise sertifikaati. Esitatud juhtumil on süsteemi kasutajad kõik Eesti ID-kaardi omanikud, kusjuures ei kontrollita tühistusnimekirju ega muud sellist ja lahendus ei ole tõenäoliselt otseselt kasutatav.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;OpenVPN lahendust saab seadistada käima selliselt, et kasutaja autentimiseks kasutatakse tema Eesti ID-kaardi isikutuvastuse ehk autentimise sertifikaati. Esitatud juhtumil on süsteemi kasutajad kõik Eesti ID-kaardi omanikud, kusjuures ei kontrollita tühistusnimekirju ega muud sellist ja lahendus ei ole tõenäoliselt otseselt kasutatav.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Imre</name></author>
	</entry>
	<entry>
		<id>https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;diff=12407&amp;oldid=prev</id>
		<title>Imre: Uus lehekülg: ===Eesti ID-kaardi kasutamine===  OpenVPN lahendust saab seadistada käima selliselt, et kasutaja autentimiseks kasutatakse tema Eesti ID-kaardi isikutuvastuse ehk autentimise sertifi...</title>
		<link rel="alternate" type="text/html" href="https://kuutorvaja.eenet.ee/w/index.php?title=OpenVPN_ja_Eesti_ID-kaardi_kasutamine&amp;diff=12407&amp;oldid=prev"/>
		<updated>2009-06-24T15:36:37Z</updated>

		<summary type="html">&lt;p&gt;Uus lehekülg: ===Eesti ID-kaardi kasutamine===  OpenVPN lahendust saab seadistada käima selliselt, et kasutaja autentimiseks kasutatakse tema Eesti ID-kaardi isikutuvastuse ehk autentimise sertifi...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Uus lehekülg&lt;/b&gt;&lt;/p&gt;&lt;div&gt;===Eesti ID-kaardi kasutamine===&lt;br /&gt;
&lt;br /&gt;
OpenVPN lahendust saab seadistada käima selliselt, et kasutaja autentimiseks kasutatakse tema Eesti ID-kaardi isikutuvastuse ehk autentimise sertifikaati. Esitatud juhtumil on süsteemi kasutajad kõik Eesti ID-kaardi omanikud, kusjuures ei kontrollita tühistusnimekirju ega muud sellist ja lahendus ei ole tõenäoliselt otseselt kasutatav.&lt;br /&gt;
&lt;br /&gt;
====OpenVPN server Debianil====&lt;br /&gt;
&lt;br /&gt;
Serveri poolel sobib kasutada nt sellist seadistusfaili&lt;br /&gt;
&lt;br /&gt;
  port 1194&lt;br /&gt;
  proto udp&lt;br /&gt;
  dev tun0&lt;br /&gt;
  ca /etc/openvpn/SK-CA.pem&lt;br /&gt;
  cert /etc/openvpn/vpn.loomaaed.tartu.ee-cert.pem&lt;br /&gt;
  key /etc/openvpn/vpn.loomaaed.tartu.ee-key.pem&lt;br /&gt;
  &lt;br /&gt;
  dh /etc/openvpn/dh2048.pem&lt;br /&gt;
  server 172.16.1.0 255.255.255.0&lt;br /&gt;
  ifconfig-pool-persist /tmp/ipp.txt&lt;br /&gt;
  keepalive 10 120&lt;br /&gt;
  comp-lzo&lt;br /&gt;
  user nobody&lt;br /&gt;
  group nogroup&lt;br /&gt;
  persist-key&lt;br /&gt;
  persist-tun&lt;br /&gt;
  status /var/log/openvpn-status.log&lt;br /&gt;
  verb 3&lt;br /&gt;
&lt;br /&gt;
Kus SK-CA.pem faili on ühendatud kokku neli sertifikaati, neid saab kopeerida Sertifitseerimiskeskuse kodulehehelt, www.sk.ee&lt;br /&gt;
&lt;br /&gt;
  # cat KLASS3-SK.PEM.pem ESTEID-SK-2007.PEM.pem JUUR-SK.PEM.pem &amp;gt; /etc/openvpn/SK-CA.pem&lt;br /&gt;
&lt;br /&gt;
kusjuures vpn.loomaaed.tartu.ee-cert.pem ja vpn.loomaaed.tartu.ee-key.pem vastavad SK poolt väljastatud nö serveri sertifikaadile.&lt;br /&gt;
&lt;br /&gt;
SK on väljastanud KLASS3-SK ja ESTEID-SK-2007 serifikaadid oma juursertifikaadi JUUR-SK suhtes; kasutajate ID-kaartidel olevad sertifikaadid on väljastatud ESTEID-SK-2007 suhtes ning nö serverite sertifikaate väljastatakse KLASS3-SK suhtes.&lt;br /&gt;
&lt;br /&gt;
====OpenVPN klint Debianil====&lt;br /&gt;
&lt;br /&gt;
Selleks, et OpenVPN klient saaks ennast autentida ID-kaardi abil VPN kasutajana peab kliendi arvutis olema tehtud Eesti ID-kaardi kasutamiseks vajalikud ettevalmistused, nt nii nagu on kirjeldatud palas http://kuutorvaja.eenet.ee/wiki/Eesti_ID-kaardi_kasutamine_Debianiga&lt;br /&gt;
&lt;br /&gt;
Ettevalmistuste edukuse kontrollimiseks sobib öelda nt&lt;br /&gt;
&lt;br /&gt;
  # openvpn --show-pkcs11-ids /usr/lib/opensc-pkcs11.so&lt;br /&gt;
  &lt;br /&gt;
  The following objects are available for use.&lt;br /&gt;
  Each object shown below may be used as parameter to&lt;br /&gt;
  --pkcs11-id option please remember to use single quote mark.&lt;br /&gt;
  &lt;br /&gt;
  Certificate&lt;br /&gt;
       DN:             /C=EE/O=ESTEID/OU=authentication/CN=OOLBERG,IMRE,37003212713/SN=OOLBERG/GN=IMRE/serialNumber=37003212713&lt;br /&gt;
       Serial:         48843168&lt;br /&gt;
       Serialized id:  AS\x20Sertifitseerimiskeskus/PKCS\x20\x2315\x20SCard/A0055728/ID\x2Dkaart\x20\x28PIN1\x2C\x20Isikutuvastus\x29/01&lt;br /&gt;
  &lt;br /&gt;
  Certificate&lt;br /&gt;
       DN:             /C=EE/O=ESTEID/OU=digital signature/CN=OOLBERG,IMRE,37003212713/SN=OOLBERG/GN=IMRE/serialNumber=37003212713&lt;br /&gt;
       Serial:         48843169&lt;br /&gt;
       Serialized id:  AS\x20Sertifitseerimiskeskus/PKCS\x20\x2315\x20SCard/A0055728/ID\x2Dkaart\x20\x28PIN2\x2C\x20Allkirjastamine\x29/02&lt;br /&gt;
&lt;br /&gt;
Kliendi poolel sobib kasutada nt sellist seadistusfaili, \ märgid on varjestatud&lt;br /&gt;
&lt;br /&gt;
  client&lt;br /&gt;
  dev tun&lt;br /&gt;
  proto udp&lt;br /&gt;
  remote 192.168.10.199&lt;br /&gt;
  resolv-retry infinite&lt;br /&gt;
  nobind&lt;br /&gt;
  persist-key&lt;br /&gt;
  persist-tun&lt;br /&gt;
  ca /etc/openvpn/SK-CA.pem&lt;br /&gt;
  &lt;br /&gt;
  pkcs11-providers  /usr/lib/opensc-pkcs11.so&lt;br /&gt;
  pkcs11-id &amp;quot;AS\\x20Sertifitseerimiskeskus/PKCS\\x20\\x2315\\x20SCard/A0055728/ID\\x2Dkaart\\x20\\x28PIN1\\x2C\\x20Isikutuvastus\\x29/01&amp;quot;&lt;br /&gt;
  &lt;br /&gt;
  comp-lzo&lt;br /&gt;
  verb 3&lt;br /&gt;
&lt;br /&gt;
====Kasutamine====&lt;br /&gt;
&lt;br /&gt;
Eesti-ID kaardi kasutamisel esitatakse serveri poolel selline logi, muu hulgas võib tähele panna, et kasutatakse 1024 bit võtmeid&lt;br /&gt;
&lt;br /&gt;
  # openvpn --config openvpn.conf&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 OpenVPN 2.1_rc11 x86_64-pc-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] built on Sep 18 2008&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 Diffie-Hellman initialized with 2048 bit key&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 /usr/bin/openssl-vulnkey -q -b 1024 -m &amp;lt;modulus omitted&amp;gt;&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 ROUTE default_gateway=192.168.10.254&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 TUN/TAP device tun0 opened&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 TUN/TAP TX queue length set to 100&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 /sbin/ifconfig tun0 172.16.1.1 pointopoint 172.16.1.2 mtu 1500&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 /sbin/route add -net 172.16.1.0 netmask 255.255.255.0 gw 172.16.1.2&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 GID set to nogroup&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 UID set to nobody&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 Socket Buffers: R=[124928-&amp;gt;131072] S=[124928-&amp;gt;131072]&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 UDPv4 link local (bound): [undef]:1194&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 UDPv4 link remote: [undef]&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 MULTI: multi_init called, r=256 v=256&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 IFCONFIG POOL: base=172.16.1.4 size=62&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 IFCONFIG POOL LIST&lt;br /&gt;
  Sun Apr 26 09:03:34 2009 Initialization Sequence Completed&lt;br /&gt;
  &lt;br /&gt;
  Sun Apr 26 09:09:02 2009 MULTI: multi_create_instance called&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 Re-using SSL/TLS context&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 LZO compression initialized&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 Local Options hash (VER=V4): &amp;#039;530fdded&amp;#039;&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 Expected Remote Options hash (VER=V4): &amp;#039;41690919&amp;#039;&lt;br /&gt;
  Sun Apr 26 09:09:02 2009 192.168.10.101:44287 TLS: Initial packet from 192.168.10.101:44287, sid=c50c829f 8e240ecc&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 VERIFY OK: depth=2, /emailAddress=pki@sk.ee/C=EE/O=AS_Sertifitseerimiskeskus/CN=Juur-SK&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 VERIFY OK: depth=1, /C=EE/O=AS_Sertifitseerimiskeskus/OU=ESTEID/CN=ESTEID-SK_2007&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 VERIFY OK: depth=0, /C=EE/O=ESTEID/OU=authentication/CN=OOLBERG_IMRE_37003212713/SN=OOLBERG  /GN=IMRE/serialNumber=37003212713&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 Data Channel Encrypt: Cipher &amp;#039;BF-CBC&amp;#039; initialized with 128 bit key&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 Data Channel Encrypt: Using 160 bit message hash &amp;#039;SHA1&amp;#039; for HMAC authentication&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 Data Channel Decrypt: Cipher &amp;#039;BF-CBC&amp;#039; initialized with 128 bit key&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 Data Channel Decrypt: Using 160 bit message hash &amp;#039;SHA1&amp;#039; for HMAC authentication&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 192.168.10.101:44287 [OOLBERG_IMRE_37003212713] Peer Connection Initiated with 192.168.10.101:44287&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 OOLBERG_IMRE_37003212713/192.168.10.101:44287 MULTI: Learn: 172.16.1.6 -&amp;gt; OOLBERG_IMRE_37003212713/192.168.10.101:44287&lt;br /&gt;
  Sun Apr 26 09:09:13 2009 OOLBERG_IMRE_37003212713/192.168.10.101:44287 MULTI: primary virtual IP for OOLBERG_IMRE_37003212713/192.168.10.101:44287: 172.16.1.6&lt;br /&gt;
  Sun Apr 26 09:09:14 2009 OOLBERG_IMRE_37003212713/192.168.10.101:44287 PUSH: Received control message: &amp;#039;PUSH_REQUEST&amp;#039;&lt;br /&gt;
  Sun Apr 26 09:09:14 2009 OOLBERG_IMRE_37003212713/192.168.10.101:44287 SENT CONTROL [OOLBERG_IMRE_37003212713]: &amp;#039;PUSH_REPLY,route 172.16.1.1,topology net30,ping 10,ping-restart 120,ifconfig 172.16.1.6 172.16.1.5&amp;#039; (status=1)&lt;br /&gt;
&lt;br /&gt;
ning kliendi poolel selline, mõned ID-kaardi kasutamisega seotud veateated on eemaldatud&lt;br /&gt;
&lt;br /&gt;
  # openvpn --config openvpn.conf&lt;br /&gt;
  Sun Apr 26 12:07:12 2009 OpenVPN 2.1_rc11 i486-pc-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] built on Sep 18 2008&lt;br /&gt;
  Sun Apr 26 12:07:12 2009 PKCS#11: Adding PKCS#11 provider &amp;#039;/usr/lib/opensc-pkcs11.so&amp;#039;&lt;br /&gt;
  Sun Apr 26 12:07:17 2009 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.&lt;br /&gt;
  Sun Apr 26 12:07:17 2009 /usr/bin/openssl-vulnkey -q -b 1024 -m &amp;lt;modulus omitted&amp;gt;&lt;br /&gt;
  [opensc-pkcs11] pkcs11-global.c:176:C_Initialize: C_Initialize(): Cryptoki already initialized&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 LZO compression initialized&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 Local Options hash (VER=V4): &amp;#039;41690919&amp;#039;&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 Expected Remote Options hash (VER=V4): &amp;#039;530fdded&amp;#039;&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 Socket Buffers: R=[111616-&amp;gt;131072] S=[111616-&amp;gt;131072]&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 UDPv4 link local: [undef]&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 UDPv4 link remote: 192.168.10.199:1194&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 TLS: Initial packet from 192.168.10.199:1194, sid=eef2a782 22a5670e&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 VERIFY OK: depth=2, /emailAddress=pki@sk.ee/C=EE/O=AS_Sertifitseerimiskeskus/CN=Juur-SK&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 VERIFY OK: depth=1, /emailAddress=pki@sk.ee/C=EE/O=AS_Sertifitseerimiskeskus/OU=Sertifitseerimisteenused/serialNumber=1/CN=KLASS3-SK&lt;br /&gt;
  Sun Apr 26 12:07:18 2009 VERIFY OK: depth=0, /CN=vpn.loomaaed.tartu.ee/O=Tartu Loomaaed/L=Tartu/ST=Tartu/C=EE&lt;br /&gt;
  &lt;br /&gt;
  Enter ID-kaart (PIN1, Isikutuvastus) token Password:&lt;br /&gt;
  &lt;br /&gt;
  Sun Apr 26 12:07:29 2009 Data Channel Encrypt: Cipher &amp;#039;BF-CBC&amp;#039; initialized with 128 bit key&lt;br /&gt;
  Sun Apr 26 12:07:29 2009 Data Channel Encrypt: Using 160 bit message hash &amp;#039;SHA1&amp;#039; for HMAC authentication&lt;br /&gt;
  Sun Apr 26 12:07:29 2009 Data Channel Decrypt: Cipher &amp;#039;BF-CBC&amp;#039; initialized with 128 bit key&lt;br /&gt;
  Sun Apr 26 12:07:29 2009 Data Channel Decrypt: Using 160 bit message hash &amp;#039;SHA1&amp;#039; for HMAC authentication&lt;br /&gt;
  Sun Apr 26 12:07:29 2009 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA&lt;br /&gt;
  Sun Apr 26 12:07:29 2009 [www.ria.ee] Peer Connection Initiated with 192.168.10.199:1194&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 SENT CONTROL [vpn.loomaaed.tartu.ee]: &amp;#039;PUSH_REQUEST&amp;#039; (status=1)&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 PUSH: Received control message: &amp;#039;PUSH_REPLY,route 172.16.1.1,topology net30,ping 10,ping-restart 120,ifconfig 172.16.1.6 172.16.1.5&amp;#039;&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 OPTIONS IMPORT: timers and/or timeouts modified&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 OPTIONS IMPORT: --ifconfig/up options modified&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 OPTIONS IMPORT: route options modified&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 ROUTE default_gateway=192.168.10.254&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 TUN/TAP device tun1 opened&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 TUN/TAP TX queue length set to 100&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 /sbin/ifconfig tun1 172.16.1.6 pointopoint 172.16.1.5 mtu 1500&lt;br /&gt;
  [opensc-pkcs11] pkcs11-global.c:176:C_Initialize: C_Initialize(): Cryptoki already initialized&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 /sbin/route add -net 172.16.1.1 netmask 255.255.255.255 gw 172.16.1.5&lt;br /&gt;
  [opensc-pkcs11] pkcs11-global.c:176:C_Initialize: C_Initialize(): Cryptoki already initialized&lt;br /&gt;
  Sun Apr 26 12:07:30 2009 Initialization Sequence Completed&lt;/div&gt;</summary>
		<author><name>Imre</name></author>
	</entry>
</feed>