IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

[Users] x.509 and ipsec.secrets

From: Marc (marc-web_at_gmx.net)
Date: Wed Mar 27 2002 - 18:22:31 CET


Hello all,

I have a problem using freeS/WAN with multiple tunnels. There are some
tunnels running via the common way (rsasig).

Now I want to add some Roadwarriors to connect to that Gateway, that
shall be done via certificates. So far so good, my trouble is that I
don't know how to handle the private key stuff. The one I use for the
"common"-connections is in RSA : {.....} format, the one I created for
x.509 is not. The documentations says it is possible to have several
private keys in /etc/ipsec.secrets, but which ID does the key need ?

I tried:

C=DE, ST=state, O=organization, CN=user_at_host 0.0.0.0 : RSA ....
C=DE, ST=state, O=organization, CN=user_at_host %any : RSA ...

but it does not work. When I remove the "old" key and set the x.509 key
as key for all connectiona (: RSA ...) the Roasdwarrior connection
worked.

So Roadwarrior in general works. On the other hand I cannot use the
x.509 key for my old connections, because I am not able to extract
rsasigs, which are neccessary for my old connections.

has anyone a clue on this ?

Thanks in advance

Regards

Marc
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:19:47 CEST