(racoon 871) Re: x509 certificates problems

YAMASHITA Yutaka <[email protected]> Fri, 17 Dec 2004 02:51:34 +0900
Newsgroups gmane.network.ipv6.kame.racoon
Message-ID <[email protected]>
Hi,

It is because of DN lengths mismatch.
the ID of the certificate the peer sent is different from the DN of
your local certificate.
The simple fix is just to remove "peers_cetificate" in racoon.conf.



On Tue, 14 Dec 2004 16:45:20 +0100
Morgan <[email protected]> wrote:

> 
> Hi,
> 
> I try to make a tunnel between two FreeBSD 5.3 computers using x509 
> certificates with a CA.
> 
> The main message is :
> 2004-12-14 16:00:18: ERROR: oakley.c:1640:oakley_check_certid(): Invalid ID
> length in phase 1.
> 
> I've created many certificates without any change.
> 
> On the web, I don't find answer to this problem.
> 
> Do you have a solution, or an idea ?
> 
> Regards.
> 
> Morgan
> 
> -- 
> 
> Un pas vers les logiciels libres
> http://www.fsf-europe.org/
> http://www.gnu.org/
> 


-- 
-----------------------------
   - YAMASHITA Yutaka -    
 Keio Univ. ICS. Teraoka Lab 
 [email protected]
-----------------------------