IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

[Users] 1.98b + x509 + Windows 2000

From: Mariusz Drozdziel (nova_at_tucznik.net)
Date: Mon Jul 08 2002 - 16:00:52 CEST


Hi,

        I use FreeS/WAN 1.98b patched to support x.509 based
authorization. On my gateway side i setup authby=rsasig by i
receive such error while trying to establish connection by
w2k client:

---------------- cut ----------------
 | *****parse ISAKMP Transform Payload (ISAKMP):
 | next payload type: ISAKMP_NEXT_T
 | length: 36
 | transform number: 2
 | transform ID: KEY_IKE
 | ******parse ISAKMP Oakley attribute:
 | af+type: OAKLEY_ENCRYPTION_ALGORITHM
 | length/value: 5
 | [5 is OAKLEY_3DES_CBC]
 | ******parse ISAKMP Oakley attribute:
 | af+type: OAKLEY_HASH_ALGORITHM
 | length/value: 1
 | [1 is OAKLEY_MD5]
 | ******parse ISAKMP Oakley attribute:
 | af+type: OAKLEY_GROUP_DESCRIPTION
 | length/value: 2
 | [2 is OAKLEY_GROUP_MODP1024]
 | ******parse ISAKMP Oakley attribute:
 | af+type: OAKLEY_AUTHENTICATION_METHOD
 | length/value: 3
 | [3 is OAKLEY_RSA_SIG]
 "roadwarrior"[2] xxx.xxx.xxx.xxx #2: policy does not allow \
OAKLEY_RSA_SIG authentication. Attribute OAKLEY_AUTHENTICATION_METHOD
---------------- cut ----------------

Where should i define this 'policy' to allow OAKLEY_RSA_SIG?

I read many list archives but didn't find a solution there.

-- 
                                                    Mariusz.
 
== Mariusz Drozdziel <nova_at_tucznik.net> == 2:482/52_at_fidonet.org ==
== NOVA1-RIPE == GPG: 7CE2776F99C2C8F4613F E858D7DD1DA39F779A94 ==
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:20:19 CEST