Re: [strongSwan] How to retrieve remote certificates

2017-02-16 Thread Noel Kuntze
Hello John, > In the meantime my experiments has shown that the problem was not associated > with certificates at all. This message about bad signature was a result of > missing some strongswan basic plugins (so it was an unexpected strongswan > installation problem!), all the certificates

Re: [strongSwan] activating manually configured VPNs with NetworkManager?

2017-02-16 Thread Noel Kuntze
Hello Daniel, That is not possible and currently there's no alternative. On 16.02.2017 15:09, Daniel Pocock wrote: > > Looking at the documentation about the NetworkManager plugin[1], it can > only configure a subset of possible road-warrior configurations through > the GUI > > If somebody has

Re: [strongSwan] IKEv2 : Tunnel gets established even when local cert startDate is invalid

2017-02-16 Thread Tobias Brunner
Hi Sriram, > "ipsec listcerts" says that the above (device)cert is not yet valid. > Still tunnel gets established properly. strongSwan does use seemingly invalid certificates for its own authentication, but won't accept invalid remote certificates. So if the server certificate was also only

[strongSwan] IKEv2 : Tunnel gets established even when local cert startDate is invalid

2017-02-16 Thread Sriram
Hi, In one our of linux devices which is the vpn client, the date is not set properly because of gps issue. [root@0005B9xx /]# date Wed Feb 8 05:56:43 UTC 2017 0005B9xx.airvana.com i.e this DNS name represents the linux device certificate . [root@0005B9xx /]# ipsec listcerts List

[strongSwan] activating manually configured VPNs with NetworkManager?

2017-02-16 Thread Daniel Pocock
Looking at the documentation about the NetworkManager plugin[1], it can only configure a subset of possible road-warrior configurations through the GUI If somebody has their own mechanism in place to deploy ipsec.conf files to users, is it possible for the NetworkManager plugin to be used to

Re: [strongSwan] IKEv2 retransmission of Android app

2017-02-16 Thread Tobias Brunner
> > But how can I control this on Android? Is it hardcoded somewhere? If > > yes, can somebody help me and point me to the right direction? > > See [1] or [2]. > > Where is [1] or [2]? :) Odd, I distinctly remember pasting the links into an email. Anyway, here they are: [1]

Re: [strongSwan] IKEv2 retransmission of Android app

2017-02-16 Thread Piotr Soróbka
Hi Piotr, > But how can I control this on Android? Is it hardcoded somewhere? If > yes, can somebody help me and point me to the right direction? See [1] or [2]. Where is [1] or [2]? :) > I'm trying to use OTP to authenticate IKEv2. So far, so good, but the > main issue is to maintain the

Re: [strongSwan] How to retrieve remote certificates

2017-02-16 Thread John Brown
Hi Tobias, Sorry for delay, I didn't notice your message. In the meantime my experiments has shown that the problem was not associated with certificates at all. This message about bad signature was a result of missing some strongswan basic plugins (so it was an unexpected strongswan installation