Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-15 Thread Tom Robinson
On 16/11/15 11:05, Tom Robinson wrote: > On 15/11/15 01:50, Tom Robinson wrote: >> On 14/11/15 22:58, Tuomo Soini wrote: >>> On Sat, 14 Nov 2015 21:56:54 +1100 >>> Tom Robinson wrote: >>> >>> My apologies, I should have said earlier. We're running libreswan-3.9-1 on CentOS 5. >>> >>> Tha

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-15 Thread Tom Robinson
On 15/11/15 01:50, Tom Robinson wrote: > On 14/11/15 22:58, Tuomo Soini wrote: >> On Sat, 14 Nov 2015 21:56:54 +1100 >> Tom Robinson wrote: >> >> >>> My apologies, I should have said earlier. We're running >>> libreswan-3.9-1 on CentOS 5. >> >> That is all too old version. It doesn't have any supp

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-15 Thread Paul Wouters
On Sun, 15 Nov 2015, Tom Robinson wrote: My other question was about having both IKEv2 and IPSec/L2TP connection definitions on the same VPN server. Is that possible on 3.13 (or any version)? I noticed with my L2TP connection sometimes responded to the IKEv2 client request. Note that pluto use

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-14 Thread Tom Robinson
On 14/11/15 22:58, Tuomo Soini wrote: > On Sat, 14 Nov 2015 21:56:54 +1100 > Tom Robinson wrote: > > >> My apologies, I should have said earlier. We're running >> libreswan-3.9-1 on CentOS 5. > > That is all too old version. It doesn't have any support for this > config. Upgrade to 3.13 which i

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-14 Thread Tuomo Soini
On Sat, 14 Nov 2015 21:56:54 +1100 Tom Robinson wrote: > My apologies, I should have said earlier. We're running > libreswan-3.9-1 on CentOS 5. That is all too old version. It doesn't have any support for this config. Upgrade to 3.13 which is last version which will work on centos-5. I'd advic

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-14 Thread Tom Robinson
On 14/11/15 01:50, Matt Rogers wrote: > - Original Message - >> From: "Tom Robinson" >> To: swan@lists.libreswan.org >> Sent: Thursday, November 12, 2015 4:24:10 PM >> Subject: Re: [Swan] IKEv2 connection "no RSA public key known for" and &q

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-13 Thread Matt Rogers
- Original Message - > From: "Tom Robinson" > To: swan@lists.libreswan.org > Sent: Thursday, November 12, 2015 4:24:10 PM > Subject: Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA > authentication failed" > >

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-12 Thread Tom Robinson
On 12/11/15 08:20, Tom Robinson wrote: > Hi Matt, > > Thanks for your response. > > On 12/11/15 01:15, Matt Rogers wrote: >> You should set rightid=%fromcert so it will use the received cert subject >> as the ID here. >> > > I've added rightid=%fromcert to the connection but it still fails as fo

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-11 Thread Tom Robinson
Hi Matt, Thanks for your response. On 12/11/15 01:15, Matt Rogers wrote: > You should set rightid=%fromcert so it will use the received cert subject > as the ID here. > I've added rightid=%fromcert to the connection but it still fails as follows: Nov 12 08:15:38 fw2 pluto[26342]: "ikev2-cp"[1]

Re: [Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-11 Thread Matt Rogers
- Original Message - > From: "Tom Robinson" > To: swan@lists.libreswan.org > Sent: Tuesday, November 10, 2015 6:54:39 PM > Subject: [Swan] IKEv2 connection "no RSA public key known for" and "RSA > authentication failed" > > Hi, >

[Swan] IKEv2 connection "no RSA public key known for" and "RSA authentication failed"

2015-11-10 Thread Tom Robinson
Hi, I've had a lot of success with IPSec/L2TP but have faced some issues. Recently I upgraded from an older OpenSWAN to libreswan implementation and found there is support for IKEv2 connections. I decided to give it a go as it looked quite easy to setup. After following the documentation here: