[strongSwan] Connection continuously going up and down

ABULIUS, MUGUR (MUGUR) mugur.abulius at alcatel-lucent.com
Thu Dec 29 18:39:47 CET 2011


Hello,
The ALPHA connection continuously goes up and down if '/etc/ipsec.d/cacerts' contains 2 certificates
that are the same. In this test the CAs hierarchy has only one level (the anchor is the certificate of the
signing CA of the local system). The local system (initiator of IKE connection) is a Linux system.
We know that is unusual to have 2 files containing the same certificate in 'cacerts' but this may happen
for our application in the field. Is the strongSwan behavior normal or there is a bug?
conn ALPHA
        left=172.21.11.21
        right=172.21.11.181
        leftsubnet=172.21.10.21/32
        rightsubnet=0.0.0.0/0,0::0/0
        leftauth=pubkey
        rightauth=pubkey
        leftcert=0_clcert.der
        rightca="O=Company, CN=CMS"
        rightid="O=*, CN=*"
        auto=start

Best Regards
Mugur


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20111229/2f8db1e2/attachment.html>


More information about the Users mailing list