|
|||||||||||
|
[Design] Re: [Users] multiple ipsec.secrets entries
From: Paul Wouters <paul(at)xtdnet.nl>
Date: Wed Feb 26 2003 - 06:51:22 EST
(I have CC:ed this to design@ since I believe this is a design problem) > I then noticed this on the gateway logs: Feb 25 19:25:32 sparta
> The other three connections [understandably] could not be made.
Though 1.96 is an old version, I've recently encountered the same problem. You can find some information in the man page for ipsec.secrets, and there it says you can use multiple secrets, and that the "most exact" match for a secret is used. If you just want multiple road warriors to connect to your gateway, each using their own certificate, by far the easiest approach is to use a "certificate agency" that signs all the certificates of your roadwarriors. Then you only need to load the certificate of the CA on the gateway. You can use this together with a revocation list to disallow certain signed certifictes which administratively no longer should be valid, but are still valid technically (as specified in the signature of the ca). A good link on how to accomplish this is: http://www.natecarlson.com/linux/ipsec-x509.php Perhaps DHR and Stefan can comment on how it might be possible to get X509 and RSA secrets to co-exist in Pluto? And if so, then perhaps Claudia can put this information in the FAQ? Paul Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Wed Feb 26 07:17:56 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:32 EDT |
||||||||||
|
|||||||||||