Re-6: VPN not working ...
| Newsgroups | gmane.network.freeswan.user |
|---|---|
| Message-ID | <[email protected]> |
Hi, Now I have entered the private key files into the ipsec.secrets file and they are loaded on ipsec startup. Ipsec verify now tells me Checking for RSA privte key (/etc/ipsec.secrets) ... [Failed] ipsec showhostkey: No default key in "etc/ipsec.secrets" I also generated the crl. But it's still not working. I'm going insane some day .... Greetings, Kai -------- Original Message -------- Subject: Re-5: [Users] VPN not working ... (09-Aug-2004 10:19) From: [email protected] To: [email protected] > Hi > > At 10:13 09.08.2004, [email protected] wrote: > >Hi, > > > >the ipsec.secrets file has been populated but for some reason it is empty > >now. Maybe I deleted the file for testing purposes. I tested a lot the > >last days. Any idea how I can "rebuild" this file with my RSA 2048 bit > >keys without creating a complete new set? > > You need the private key from your certificate..... see below > > > >There are 3 certificates I generated: > > > >MultinovaCA-cert = root CA (located in /etc/ipsec.d/cacerts/) > >mnvpngw-cert = gateway CA (located in /etc/ipsec.d/private/) > >vpn-key = user certificate (located in /etc/ipsec.d/private/) > > > > >How can I implement the private key for the user in my ipsec.conf? > > You don't, you copy the private key to /etc/ipsec.d/private and reference > it from /etc/ipsec.secrets like > > : RSA aspkey.pem > > and.... btw. install a crl to /etc/ipsec.d/crls > > cheers > Erich > > THINK > Püntenstrasse 39 > 8143 Stallikon > mailto:[email protected] > PGP Fingerprint: BC9A 25BC 3954 3BC8 C024 8D8A B7D4 FF9D 05B8 0A16 > > _______________________________________________ > FreeS/WAN Users mailing list > [email protected] > https://mj2.freeswan.org/cgi-bin/mj_wwwusr > To: [email protected] [email protected] [email protected]