Re: [strongSwan] Charon hangs after failing to delete Rekeyed IPsec SAs

2012-03-23 Thread gowrishankar
Hi Anand, wrt RFC 4306 Page 22: If the two ends have the same lifetime policies, it is possible that both will initiate a rekeying at the same time (which will result in redundant SAs). To reduce the probability of this happening, the timing of rekeying requests SHOULD be jittere

[strongSwan] Upgrade issue

2012-03-23 Thread Peter Sagerson
Hello, I'm attempting to upgrade from strongSwan 4.4.0 to 4.5.2 and I'm seeing a mysterious failure that I haven't been able to puzzle out. The connection config looks like this (DPD and cipher settings omitted for brevity): conn ipsec keyexchange = ikev1 auth = esp authby = xauthrs