Re: GSSAPI and racoon

2017-03-08 Thread Victor Sudakov
Victor Sudakov wrote: > Victor Sudakov wrote: > > > > Is anyone running GSSAPI+IKE (racoon)? > > I'm still struggling with racoon in GSSAPI mode. racoon says > > 2017-03-08 13:01:59: [192.168.3.38] ERROR: failed to get valid proposal. > 2017-03-08 13:01:59: [192.168.3.38] ERROR: failed to pre-pr

Re: GSSAPI and racoon

2017-03-07 Thread Victor Sudakov
Victor Sudakov wrote: > > Is anyone running GSSAPI+IKE (racoon)? I'm still struggling with racoon in GSSAPI mode. racoon says 2017-03-08 13:01:59: [192.168.3.38] ERROR: failed to get valid proposal. 2017-03-08 13:01:59: [192.168.3.38] ERROR: failed to pre-process ph1 packet (side: 1, status 1).

Re: GSSAPI and racoon

2017-03-04 Thread Victor Sudakov
Victor Sudakov wrote: > > Is anyone running GSSAPI+IKE (racoon)? > > I have a Heimdal realm with a dozen FreeBSD hosts in it. I use GSSAPI > for ssh access, also for CVS and SVN authentication. So I thought it > would be a good idea to use Kerberos for IPSec as well, but the > documentation is sc

GSSAPI and racoon

2017-03-03 Thread Victor Sudakov
Dear Colleagues, Is anyone running GSSAPI+IKE (racoon)? I have a Heimdal realm with a dozen FreeBSD hosts in it. I use GSSAPI for ssh access, also for CVS and SVN authentication. So I thought it would be a good idea to use Kerberos for IPSec as well, but the documentation is scarce, in fact only