On 2008/04/27 14:18, Marten Rizwan wrote:this isn't exactly ports@ material...CC'd/reply-to set to misc. I haven't been able to figure out yet though. I want to simultaneously connect to two IPsec servers, both of which are OpenBSD boxes and both of them use X509 certificates. These two servers are managed by different administrators and are absolutely unrelated. Hence, their X509 certs are created with different CAs. In both cases, I haven't been given opportunity to provide my own CSR for them to generate my certificate. Hence, I'm given two pair of keys/certs for each server. Basically, the two CSRs are signed using two different private keys. What this means to me is that I need to have two separate /etc/isakmpd/priavte/local.key for each server. I believe that /etc/isakmpd/priavte/local.key is glued in isakmpd and I have no way of specifying a separate local.key for each server I'm connecting to. Am I missing something? By the way, I obviously use ipsecctl(8) to configure IPsec. I haven't tried this, and it's not in the manual as far as I can see, but it looks like isakmpd looks in files named after the identity of the local peer (i.e. srcid) before it tries local.key. If you get it working, let me know the details and I'll try and come up with something for the manual...
| David Newall | Re: Slow DOWN, please!!! |
| Linus Torvalds | Re: O_DIRECT question |
| Ingo Molnar | Re: 2.6.24-rc4-git5: Reported regressions from 2.6.23 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
git: | |
| Junio C Hamano | Re: [RFC] Git User's Survey 2008 |
| Junichi Uekawa | Re: [ANNOUNCE] GIT 1.5.4 |
| Marcus Griep | [PATCH] git-svn: Make it scream by minimizing temp files |
| Bill Lear | Meaning of "fatal: protocol error: bad line length character"? |
| Richard Stallman | Real men don't attack straw men |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| farhan ahmed | Re: bash for root? (was: Re: libiconv problem ) |
| Tony Sarendal | bgpd causing black-holes with bgp-only setup |
| Krishna Kumar | [PATCH 9/10 REV5] [IPoIB] Implement batching |
| jamal | Re: [PATCH 2/3][NET_BATCH] net core use batching |
| Andi Kleen | [PATCH] Disable TSO for non standard qdiscs |
| James Chapman | Re: [PATCH][PPPOL2TP]: Fix SMP oops in pppol2tp driver |
