login
Header Space

 
 

Re: vpn, isakmpd, and X509 certificates

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Cc: Stuart Henderson <stu@...>
Date: Sunday, April 27, 2008 - 3:15 pm

Hello Stuart,

apologize for sending this to ports@, my mistake.

Great idea, I just systraced isakmpd and it does look for srcid of the local peer, which in my case is FQDN.
Notice that if your FQDN is for example level1.blah.org, the key should be placed as "/etc/isakmpd/private/level1.blah.org" *without* .key extension.

here is the relevant part from systrace:
        native-fsread: filename eq "/etc/isakmpd/private/level1.blah.org" then permit
        native-fsread: filename eq "/etc/isakmpd/private/local.key" then permit
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: vpn, isakmpd, and X509 certificates, Marten Rizwan, (Sun Apr 27, 3:15 pm)
speck-geostationary