|
|||||||||||
|
Re: isakmpd does not initiate connections but wait for others
From: Hakan Olsson <ho(at)crt.se>
Date: Mon Mar 03 2003 - 10:19:53 EST On Mon, 3 Mar 2003, Alexandre wrote:
Yes, this is it. I missed this earlier. 3DES-SHA with DES-SHA for phase 1 is ok, but it is not ok to mix PFS and non-PFS suites for phase 2. This is mandated by the RFCs. (PFS suites include a group description.) I could have sworn I added a section to isakmpd(8) or isakmpd.conf(5) warning about exactly this (expected) behaviour a year or two ago. Can't find it now though. I'll see if I can find and re-add it.
...
Here, the suite does not include a group description (it's not a PFS suite), and "no group" differs from the previous "<some> group" (probably DH group 2), so you get the error. /H -- Håkan OlssonReceived on Mon Mar 3 10:21:06 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:48:30 EDT |
||||||||||
|
|||||||||||