|
|||||||||||
|
Re: [Users] [QUESTION] IPsec
From: Andreas Steffen <andreas.steffen(at)strongsec.net>
Date: Fri Mar 28 2003 - 14:42:31 EST
Martin Zwickel wrote:
>>Martin Zwickel wrote: >> >> >>This is a bug in the X.509 patch 1.2.1 for freeswan-2.00-rc. I have >>released a single line fix on this list today. > > > sorry, but i can't find the fix in the ML. Use the freshly released version 1.2.2 for freeswan-2.00-rc2. >
>>>conn tt >>># vpn server: >>> right=Y.Y.Y.Y >>> rightsubnet=192.168.1.0/255.255.255.0 >>> rightrsasigkey=%cert >> >>Where is rightcert designating FreeS/WAN's own >>certificate? The peer side will not be able to authenticate >>you. > > > so my leftid cert isn't enough? leftid is the expected ID of the peer > what should i use as the rightcert?
rightcert is the certificate of the vpn server. It will be sent to the peer. > do i have to install another cert on my side? and where can i get it
>>># my side: >>> left=X.X.X.X >>> leftsubnet=192.168.0.0/255.255.255.0 >>> leftrsasigkey=%cert >>> leftid="/C=DE/ST=Thueringen/L=Augsburg/O=Technotrend >>>AG/CN=Martin Zwickel/Email=martin.zwickel@technotrend.de" >>> compress=yes >>> keyingtries=1 >>> pfs=yes >> > > > Regards, > Martin Regards Andreas Andreas Steffen e-mail: andreas.steffen@strongsec.com strongSec GmbH home: http://www.strongsec.com Alter Zürichweg 20 phone: +41 1 730 80 64CH-8952 Schlieren (Switzerland) fax: +41 1 730 80 65 ==========================================[strong internet security]=== _______________________________________________Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Fri Mar 28 19:53:08 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:12 EDT |
||||||||||
|
|||||||||||