(racoon 871) Re: x509 certificates problems
YAMASHITA Yutaka <[email protected]> Fri, 17 Dec 2004 02:51:34 +0900
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Message-ID | <[email protected]> |
Hi, It is because of DN lengths mismatch. the ID of the certificate the peer sent is different from the DN of your local certificate. The simple fix is just to remove "peers_cetificate" in racoon.conf. On Tue, 14 Dec 2004 16:45:20 +0100 Morgan <[email protected]> wrote: > > Hi, > > I try to make a tunnel between two FreeBSD 5.3 computers using x509 > certificates with a CA. > > The main message is : > 2004-12-14 16:00:18: ERROR: oakley.c:1640:oakley_check_certid(): Invalid ID > length in phase 1. > > I've created many certificates without any change. > > On the web, I don't find answer to this problem. > > Do you have a solution, or an idea ? > > Regards. > > Morgan > > -- > > Un pas vers les logiciels libres > http://www.fsf-europe.org/ > http://www.gnu.org/ > -- ----------------------------- - YAMASHITA Yutaka - Keio Univ. ICS. Teraoka Lab [email protected] -----------------------------