Re: IPSEC help

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: john decot <johndecot@...>
Cc: <freebsd-security@...>
Date: Thursday, November 15, 2007 - 9:04 am

Hi John,

On Thu, Nov 15, 2007 at 03:14:04AM -0800, john decot wrote:

[...]

Log file contents would be helpful. Anyway - I had these statements in
my config file a while ago, when I used racoon with certificates:

remote anonymous {
[...]
ca_type x509 "cacert.pem";
certificate_type x509 "foo.net.pem" "foo.key-nopass";
peers_certfile x509 "bar.pem";
send_cert on;
my_identifier asn1dn;
peers_identifier asn1dn "C=foo, ST=foo, L=foo, O=foo, CN=bar/emailAddress=foo";
verify_identifier on;
[...]
}

You'll have to fill in the correct values for peers_identifier asn1dn,
of course.

HTH
--
Viele Gruesse // Best regards
Bjoern Engels
:wq!
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: GSSAPI Key Exchange in sshd?, Stefan Lambrev, (Thu Sep 20, 4:21 am)
Changing root password, Dave Johnson, (Tue Aug 11, 11:38 am)
OPIE Challenge sequence, Ivan Grover, (Tue Jul 8, 6:16 am)
CVE-2008-4609, Andrew Storms, (Tue Sep 8, 2:56 pm)
IPSEC help , john decot, (Thu Nov 15, 7:14 am)
Re: CVE-2008-4609, Dag-Erling Smørgrav, (Tue Sep 8, 5:37 pm)
RE: Changing root password, Jérôme Le Gal, (Tue Aug 11, 12:49 pm)
RE: Changing root password, Jérôme Le Gal, (Tue Aug 11, 12:38 pm)
Re: OPIE Challenge sequence, Peter Jeremy, (Tue Jul 8, 7:30 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Tue Jul 8, 7:22 am)
Re: IPSEC help, Bjoern Engels, (Thu Nov 15, 9:04 am)