Re: [strongSwan] Let's Encrypt CA Expiry & related StrongSWAN trouble

2021-10-06 Thread Philip Veale
On Wed, 6 Oct 2021 at 17:24, Simon Deziel wrote: > On 2021-10-06 12:22 p.m., Simon Deziel wrote: > > On 2021-10-06 12:08 p.m., Philip Veale wrote: > >> Oct 6 16:43:55 VPN-Server charon: 00[LIB] opening > >> '/etc/letsencrypt/live/vpn.my-hostname/privkey.pem' fai

Re: [strongSwan] Let's Encrypt CA Expiry & related StrongSWAN trouble

2021-10-06 Thread Philip Veale
why it does not work. On Wed, 6 Oct 2021 at 16:02, Noel Kuntze wrote: > Hi, > >> > Have you tried ipsec stroke rereadsecrets? (Btw, better switch to swanctl) > >> > Kind regards > >> Noel > >> > Am 06.10.21 um 16:54 schrieb Philip Veale: > >

[strongSwan] Let's Encrypt CA Expiry & related StrongSWAN trouble

2021-10-06 Thread Philip Veale
So about a week about, one of the CAs in the chain Let'sEncrypt use (DST Root CA X3) expired. This shouldn't have been a problem for most clients, as it was cross signed with a CA that had not expired (ISRG Root X1) which most modern clients and devices should trust, though some older ones may not