Networking Forums

Networking Forums > Computer Networking > Linux Networking > Road Warrior: certificates or not?

Reply
Thread Tools Display Modes

Road Warrior: certificates or not?

 
 
tohyob@yahoo.com
Guest
Posts: n/a

 
      11-02-2007, 05:07 AM
Hi,
I need to know whether it is necessary setup certificates authorities
and certificates if I want to create a net-to-(linux)laptop VPN by
means of Openswan. I have difficulties while using only RSA keys: the
gateway on the net side says that ip must be known... I set "left=
%any".
What have I to check?

 
Reply With Quote
 
 
 
 
Burkhard Ott
Guest
Posts: n/a

 
      11-02-2007, 08:01 AM
Am Thu, 01 Nov 2007 23:07:50 -0700 schrieb tohyob:

> I need to know whether it is necessary setup certificates authorities
> and certificates if I want to create a net-to-(linux)laptop VPN by
> means of Openswan. I have difficulties while using only RSA keys: the
> gateway on the net side says that ip must be known... I set "left=
> %any".
> What have I to check?


Usually in you config shoulb something like this:
[..]
leftcert=foo.pem
leftrsasigkey=%cert
rightcert=bar.pem
rightid=@remoteid (optional)
rightrsasigkey=%cert
authby=rsasig
[..]

The certificate will be checked in Phase1, you need to put your CA key,
your CA and the client certs in the right dirs under /etc/ipsec.d/....

For RSA only you put those Keys usually in a DNS, Openswan checks then the
key via fqdn.

cheers
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Virgin BB in /our/ road? PeterC Broadband 10 10-13-2010 12:54 PM
Can't get online after road trip rabblerowzer@yahoo.com Wireless Internet 1 09-27-2007 06:28 PM
What would generate RF to take out whole road BB? Paul C Broadband 7 04-04-2006 07:36 AM
Email on the road BRG Broadband 19 03-24-2005 08:21 AM
For the GPRS / CDMA Road Wireless Road Warrior . . . Negiti Wireless Internet 0 10-07-2003 09:44 PM



1 2 3 4 5 6 7 8 9 10 11