The roadwarrior carol sets up a connection to gateway moon. carol uses the Extensible Authentication Protocol in association with an MD5 challenge and response protocol (EAP-MD5) to authenticate against the gateway. The EAP identity and password of the user is kept in ipsec.secrets on the gateway moon and is entered interactively on the client carol using the command ipsec stroke user-creds home carol "Ar3etTnp". Gateway moon additionally uses an RSA signature to authenticate itself against carol.