Re: Re: [Users] multiple ipsec.secrets entries

Michael Richardson <[email protected]> Sun, 02 Mar 2003 19:17:52 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Andreas" == Andreas Steffen <[email protected]> writes:
    Andreas> Standard FreeS/WAN explicitly does not allow multiple anomymous
    Andreas> RSA private keys in ipsec.secrets because it cannot differentiate
    Andreas> them. This is why the warning

    >> Pluto[24727]: "roadwarrior-net" 206.26.195.236 #6:
    Andreas>     multiple ipsec.secrets entries with distinct secrets match
    Andreas>     endpoints: 
    Andreas>     first secret used

    Andreas> is generated.

  Hugh, perhaps we could start marking the keys more explicitely?

    Andreas>    parameter. Since X.509-1.1.6 for freeswan-2.00 alread supports
    Andreas>    both X.509 and OpenPGP certificates, as a thirk class, a link

  OpenPGP? that sounds exciting!

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBPmKfL4qHRg3pndX9AQFUswP/T8wQ/u7daxRgrwAwtw9Jc85oXcaOM2gL
FG1XWL+OzSN00hzxNNeuSyP7rKTF9vOXEa+bWSRGMF+1dEnsKIKzEBdw6vc4Rksg
SmBD7Um841tBke8ndfXU9ybq5s6+OTfI0OO0t7y0dZ5S3SpGhDoT7H973jkbTR63
cu91XjWlADc=
=2N0Q
-----END PGP SIGNATURE-----