Re: Re: [Users] multiple ipsec.secrets entries
Michael Richardson <[email protected]> Sun, 02 Mar 2003 19:17:52 -0500
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- >>>>> "Andreas" == Andreas Steffen <[email protected]> writes: Andreas> Standard FreeS/WAN explicitly does not allow multiple anomymous Andreas> RSA private keys in ipsec.secrets because it cannot differentiate Andreas> them. This is why the warning >> Pluto[24727]: "roadwarrior-net" 206.26.195.236 #6: Andreas> multiple ipsec.secrets entries with distinct secrets match Andreas> endpoints: Andreas> first secret used Andreas> is generated. Hugh, perhaps we could start marking the keys more explicitely? Andreas> parameter. Since X.509-1.1.6 for freeswan-2.00 alread supports Andreas> both X.509 and OpenPGP certificates, as a thirk class, a link OpenPGP? that sounds exciting! ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[ ] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) Comment: Finger me for keys iQCVAwUBPmKfL4qHRg3pndX9AQFUswP/T8wQ/u7daxRgrwAwtw9Jc85oXcaOM2gL FG1XWL+OzSN00hzxNNeuSyP7rKTF9vOXEa+bWSRGMF+1dEnsKIKzEBdw6vc4Rksg SmBD7Um841tBke8ndfXU9ybq5s6+OTfI0OO0t7y0dZ5S3SpGhDoT7H973jkbTR63 cu91XjWlADc= =2N0Q -----END PGP SIGNATURE-----