Re: [strongSwan] setting up a mac os x client

2014-12-10 Thread Cindy Moore
(Ah, I finally see that the "options above" means the "Autoconf options above"...) Biting the bullet and compiling, since *both* options I'd really like to check out have to be enabled at compilation time. After running ./configure --prefix=/usr --sysconfdir=/etc --enable-xauth-pam --enable-xa

Re: [strongSwan] setting up a mac os x client

2014-12-10 Thread Cindy Moore
Oh, thanks for the hint on the xauth-noauth workaround. I don't want to use username/passwords unless I hook it into our ldap, but recompiling everything with the xauth-pam configuration enabled isn't high on my list. One question about compiling it, on the https://wiki.strongswan.org/projects/st

Re: [strongSwan] setting up a mac os x client

2014-12-10 Thread Martin Willi
Hi Cindy, > I've been reading through this [AppleIKEv2Profile] and particularly > the Certificate section. Assuming I have a 10.10 and above, is this > what I need to do to setup a vpn client?? Unfortunately, despite some other information floating around, OS X 10.10 does not support IKEv2 and th

[strongSwan] setting up a mac os x client

2014-12-09 Thread Cindy Moore
I'm trying to set up a mac os x client to use a certificate based authentication. I've created root and host (and client, w/private key) certificates with ipsec pki, then created p12 packages and successfully loaded them into the keychain on the mac I'm using. On the server side (ubuntu 14.04) of