Re: [strongSwan] peer cert verification: X509: temporary cert import operation failed

2018-02-16 Thread Thomas Jarosch
Hi, On Thursday, 15 February 2018 17:37:24 CET Thomas Jarosch wrote: > Feb 15 17:20:11.324390: "companyserver" #1: Peer ID is ID_DER_ASN1_DN: > 'CN=firewall.company.com, O=Company, OU=HQ' Feb 15 17:20:11.324416: | > checking for CERT payloads > Feb 15 17:20:11.324426: | found at last one CERT payl

Re: [strongSwan] received TS_UNACCEPTABLE notify, no CHILD_SA built

2018-02-16 Thread Jafar Al-Gharaibeh
On 2/16/2018 3:39 AM, Sujoy wrote: The config file is same but then also it failed by saying "unable to install inbound and outbound IPsec SA (SAD) in kernel failed to establish CHILD_SA, keeping IKE_SA". It is failing with the error "IPsec SA: unsupported mode". That means transport (US