daneos@xi ~/src/openconnect-7.07 $ sudo ./openconnect --juniper -v -v --script=./vpnc-script --interface=vpn0 --no-cert-check https://vpn-white.maxiv.lu.se [sudo] password for daneos: WARNING: Juniper Network Connect support is experimental. It will probably be superseded by Junos Pulse support. GET https://vpn-white.maxiv.lu.se/ Attempting to connect to server 194.47.252.72:443 Connected to 194.47.252.72:443 SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 302 Found Location: https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/welcome.cgi Content-Type: text/html; charset=utf-8 Set-Cookie: DSSIGNIN=url_default; path=/dana-na/; expires=Thu, 31-Dec-2037 00:00:00 GMT; secure Set-Cookie: DSIVS=; path=/; expires=Thu, 01 Jan 1970 22:00:00 GMT; secure Set-Cookie: DSSignInURL=/; path=/; secure Connection: close Content-Length: 0 HTTP body length: (0) GET https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/welcome.cgi SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Date: Wed, 02 Nov 2016 15:51:32 GMT x-frame-options: SAMEORIGIN Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 HTTP body http 1.0 (-1) frmLogin username:XXXXXXXXXX password: POST https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/login.cgi SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 302 Moved location: https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/welcome.cgi?p=defender&id=state_2be929e48799dd8c94a8b8d2fbdc8fd6 Content-Type: text/html; charset=utf-8 Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 HTTP body http 1.0 (-1) GET https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/welcome.cgi?p=defender&id=state_2be929e48799dd8c94a8b8d2fbdc8fd6 SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Date: Wed, 02 Nov 2016 15:51:42 GMT Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 X-Frame-Options: SAMEORIGIN HTTP body http 1.0 (-1) Ignoring unknown form submit item 'secidactionCancel' frmDefender password: POST https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/login.cgi SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 302 Moved location: https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/welcome.cgi?p=user-confirm&id=state_2be929e48799dd8c94a8b8d2fbdc8fd6 Content-Type: text/html; charset=utf-8 Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 HTTP body http 1.0 (-1) GET https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/welcome.cgi?p=user-confirm&id=state_2be929e48799dd8c94a8b8d2fbdc8fd6 SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Date: Wed, 02 Nov 2016 15:51:53 GMT Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 X-Frame-Options: SAMEORIGIN HTTP body http 1.0 (-1) Ignoring unknown form submit item 'btnCancel' POST https://vpn-white.maxiv.lu.se/dana-na/auth/url_default/login.cgi SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 302 Moved Set-Cookie: DSASSERTREF=x; path=/; expires=Thu, 01 Jan 1970 22:00:00 GMT; secure Set-Cookie: DSID=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX; path=/; secure Set-Cookie: DSFirstAccess=1478101913; path=/; secure Date: Wed, 02 Nov 2016 15:51:53 GMT location: https://vpn-white.maxiv.lu.se/dana/home/starter0.cgi?check=yes Content-Type: text/html; charset=utf-8 Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 Content-Length: 0 HTTP body length: (0) GET https://vpn-white.maxiv.lu.se/dana/home/starter0.cgi?check=yes SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 200 OK Content-type: text/html; charset=utf-8 Set-Cookie: DSLastAccess=1478101919; path=/; Secure Connection: close Pragma: no-cache Cache-Control: no-store Expires: -1 X-Frame-Options: SAMEORIGIN HTTP body http 1.0 (-1) SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 200 OK Content-type: application/octet-stream Pragma: no-cache NCP-Version: 3 Set-Cookie: DSLastAccess=1478101919; path=/; Secure Connection: close X-Frame-Options: SAMEORIGIN SSL negotiation with vpn-white.maxiv.lu.se Server certificate verify failed: unable to get local issuer certificate Connected to HTTPS on vpn-white.maxiv.lu.se Got HTTP response: HTTP/1.1 200 OK Content-type: application/octet-stream Pragma: no-cache NCP-Version: 3 Set-Cookie: DSLastAccess=1478101919; path=/; Secure Connection: close X-Frame-Options: SAMEORIGIN 0000: 0f 00 00 04 00 00 00 02 00 78 69 bb 01 00 00 00 0010: 00 Read 3 bytes of SSL record Read 343 bytes of SSL record Got KMP message 301 of length 321 Got KMP message 301 of size 321 Unknown TLV group 3 attr 1 len 1: 01 Unknown TLV group 3 attr 2 len 1: 01 Received split include route 0.0.0.0/0.0.0.0 Received MTU 1400 from server Received DNS server 194.47.252.134 Received DNS server 194.47.252.135 Received DNS search domain maxiv.lu.se Unknown TLV group 2 attr 3 len 4: 01 00 00 00 ESP compression: 0 ESP encryption: 0x02 (AES-128) ESP HMAC: 0x02 (SHA1) ESP key lifetime: 1200 seconds ESP key lifetime: 0 bytes ESP replay protection: 1 Unknown TLV group 8 attr 11 len 4: 00 00 00 00 ESP port: 4500 ESP to SSL fallback: 15 seconds Unknown TLV group 8 attr 8 len 4: 00 00 00 3c Received internal IP address 194.47.255.220 Received netmask 255.255.255.255 Received internal gateway address 10.200.200.200 ESP SPI (outbound): 39a090ab 64 bytes of ESP secrets