[strongSwan] How to retrieve remote certificates

2017-01-22 Thread John Brown
Hi all, We have problems with certificate authentication and see "RSA signature verification failed: Bad signature" during strongswan connection try. We would like to retrieve all remote certificate chain to "manually" check this issue. Is this possible using strongswan (for example by enabling

[strongSwan] DHCP plugin

2017-01-22 Thread Dusan Ilic
Hello, I have a problem with the DHCP plugin. I have Strongswan and DNSmasq on the same host (my Linux gateway) and would like to issue IP adress from local LAN to remote access users, however, I cant get it working. In the logging I can see Strongswan sending DHCP Discover, and DNSmasq

[strongSwan] DHCP plugin

2017-01-22 Thread Dusan Ilic
Hello, I have a problem with the DHCP plugin. I have Strongswan and DNSmasq on the same host (my Linux gateway) and would like to issue IP adress from local LAN to remote access users, however, I cant get it working. In the logging I can see Strongswan sending DHCP Discover, and DNSmasq

Re: [strongSwan] DHCP plugin

2017-01-22 Thread Noel Kuntze
On 23.01.2017 01:46, Dusan Ilic wrote: > Thanks, I have already read it and configured according to those instructions > but without any success. > > To me it seems to be the issue that the DHCP server is sending the offer to > its own IP, because Strongswan is also using that IP. Well, make

Re: [strongSwan] DHCP plugin

2017-01-22 Thread Dusan Ilic
Hi, Thanks, I have already read it and configured according to those instructions but without any success. To me it seems to be the issue that the DHCP server is sending the offer to its own IP, because Strongswan is also using that IP. Noel Kuntze skrev >On 22.01.2017 22:33, Dusan

Re: [strongSwan] strongSwan fails to configure IPv6 source routes

2017-01-22 Thread Noel Kuntze
On 20.01.2017 16:31, Andrej Podzimek wrote: > Also, I think that the IPv6 address should be configured as /48 or /64, not > /128, but even that shouldn't prevent the road warrior from pinging (at > least) itself. Plus the road warrior should be able to ping other machines > from

Re: [strongSwan] DHCP plugin

2017-01-22 Thread Noel Kuntze
On 22.01.2017 22:33, Dusan Ilic wrote: > dhcp { > > # Always use the configured server address. > force_server_address = yes > > # Derive user-defined MAC address from hash of IKE identity. > # identity_lease = yes > > # Interface name the plugin uses for address

[strongSwan] DHCP plugin

2017-01-22 Thread Dusan Ilic
Hello, I have a problem with the DHCP plugin. I have Strongswan and DNSmasq on the same host (my Linux gateway) and would like to issue IP adress from local LAN to remote access users, however, I cant get it working. In the logging I can see Strongswan sending DHCP Discover, and DNSmasq

[strongSwan] UCI configuration

2017-01-22 Thread Nicola Feltrin
Hi all, I’m running strongswan on an OpenWRT router as a server for some roadwarriors. The configuration works, but has been implemented through the standard strongswan configuration files (/etc/strongswan.conf, /etc/ipsec.conf, /etc/ipsec.secrets, /etc/ipsec.d). I would like to move to a