Hello!

Short version:

How do I turn a single .P12 file that works fine with SSH Sentinel into the
files that Bering/SuperFreeS/Wan 1.99 expect to work with?  I believe that
these would be cacert.pem, crl.pem and x509cert.der, though maybe another
collection of files will work as well.

Long version:

I am trying to establish a VPN between my Bering box and a remote firewall.
This is to replace and expand on the functionality I have with a Windows
2000 computer running SSH Sentinel.

My biggest problem right now is how to set up Bering to accept the
certificates.  With SSH Sentinel, I have been given a single .p12 file.
With that, SSH Sentinel has everything that it needs to make the VPN work.

This is not true, it seems, of Bering.  According to the Bering User's
Guide (Chapter 15:  http://leaf.sourceforge.net/doc/guide/buipsec.html),
there are three files I need:

      cacert.pem (in /etc/ipsec.d/cacerts)
      crl.pem (in /etc/ipsec.d/crls)
      x509cert.der (in /etc)

The Bering install guide assumes you are in full control of the connection,
are generating your own keys, etc.  It doesn't explain at all what it's
doing.  Most importantly, it does not define which of these pieces each of
these files are.  I have tried to find out what each of these are supposed
to be (public key?  Private key?  Both?  My key-pair? The remote end's?
The CA's?) but I have met with very limited success.

Could someone assist me in breaking down this .P12 file into the pieces I
need to feed into Bering to make this VPN work?


Thank you very much for reading my lengthy e-mail.  I would be very
grateful for any help you could give me.

Tim Massey



-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to