(racoon 819) Re: Windows XP Road Warrior with x509 and/or PSK
Roland Dirlewanger <[email protected]> Thu, 21 Oct 2004 10:36:01 +0200
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Organization | CNRS- Delegation Aquitaine et Poitou-Charentes, Bordeaux, France |
| Message-ID | <[email protected]> |
David Herselman wrote: >2. I next tried getting x509 certificates to work with the Windows XP >roaming machine. I've followed several documents on how to create the >relevant certificates but none of them show the required steps in how one >gets Windows XP to 'bind' the certificate to the required VPN connection... >Windows XP doesn't even attempt the connection out as it can not locate the >right certificate. > >I found some reference to a 'mini-HOWTO with Windows XP using certificates' >but the domain doesn't exist anymore... Would someone possibly still have >this document lying around? Broken link: >http://www.fatcanary.com.au/docs/xp_freebsd_cert_ipsec.txt > > Jacco De Leeuw wrote a very good step by step guide for installing and configuring FreeSwan with L2TP/IPsec clients. The part concerning the clients is not tighted to any ISAKMP or IPsec implementation. It contains a chapter named "Importing certificates (Windows 2000/XP)" in the following page : http://www.jacco2.dds.nl/networking/win2000xp-freeswan.html >Problem is that both the host and the client machine are on Dynamic IPs so I >can not simply use the local security policy to activate the certificate on >the IPSec link based on the IP filter... > > Your racoon.conf has "generate_policy on" in phase 1. On a server with a fixed address, this generates the correct policy, so there's no need to bother with setting the policy in any other script. IMHO, it should also work in your case. Roland. -- Roland Dirlewanger CNRS - Delegation Aquitaine et Poitou-Charentes Esplanade des Arts et Metiers 33402 TALENCE CEDEX Mel : [email protected], Tel : 05.57.35.58.52, Fax : 05.57.35.58.01