IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

[Users] Re: Help: Win2k <-> Freeswan w/ X509

From: Philip Reetz (p.reetz_at_linet-services.de)
Date: Thu May 02 2002 - 10:29:01 CEST


Andreas Steffen wrote:
> What does the ipsec.conf on the W2k side look like. W2k cannot
> find the CA certificate belonging to
>
> rightid="C=DE, ST=NDS, O=testag, OU=rweinsunit, CN=rweinsname,
> E=rweinsemail"
>
> Regards
>
> Andreas

The ipsec.conf I used with the Ipsec tool for windows:

conn notebook
   left=%any
   right=xxx.yyy.zzz.110
   rightsubnet=192.168.0.0/255.255.255.0
   rightca="C=DE, S=NDS, L=Braunschweig, O=testag, OU=caunit, CN=caname
E=caemail"
   network=both
   auto=start
   pfs=yes

The rightca string is the same when I look in the properties of the ca
certificate in the mmc. Are you sure it can not find the certificate.
The oakley log says somthing from not accepting the user credentials.
Last week I had the problem with windows saying can not find certificate
which I get rid of by making new certs with very unique DNs.

Thanks for the time and help.

Ciao,
Philip

-- 
LINET Services
Bunkus, Geisler und Reetz GbR

Rebenring 33 Tel.: 0531-280 191 71 38106 Braunschweig Fax.: 0531-280 191 72

http://www.linet-services.de mailto:info_at_linet-services.de

_______________________________________________ Users mailing list Users_at_lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:19:57 CEST