IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

Re: [Users] Error message "only know how to do auth=esp or auth=ah"

From: Gerhard Gessler (gessler_at_iabg.de)
Date: Tue Apr 23 2002 - 12:49:34 CEST


Gerhard Hofmann schrieb:
>
> Hi list,
>
> I get an error message in /var/log/messages:
>
> ipsec__plutorun: ipsec_auto: fatal error in "roadwarrior
> > ": only know how to do auth=esp or auth=ah
>
> I have set auth=rsasig in the section "conn %default" in my ipsec.conf

Hi Gerhard,

I thing you are confusing here two things:

With "authby" you can specify how the IKE-Daemons (Pluto) authenticate
each other (rsasig or PSK).
With "auth" you can specify if IP packet authentication on the network
layer is done via ESP header (default) or an additional AH header.

So changing auth=rsasig to authby=rsasig should be enough for you if you
don't have any other special requirements.

Hope this helps,

        Gerhard

>
> What can cause this problem? I have installed X.509 patches so I think this
> option should be valid.
>
> TIA
> Gerhard Hofmann
>
> _______________________________________________
> Users mailing list
> Users_at_lists.freeswan.org
> http://lists.freeswan.org/mailman/listinfo/users

-- 
---------------------------------------------------
Gerhard Geßler

Communication Networks, IABG mbH Einsteinstr. 20 85521 Ottobrunn, Germany

Telefon: +49 89 6088 - 2021 Fax: +49 89 6088 - 2845

E-Mail: gessler_at_iabg.de _______________________________________________ Users mailing list Users_at_lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:19:53 CEST