[strongSwan] strongswan pki command error

Andreas Steffen andreas.steffen at strongswan.org
Thu Nov 10 14:58:55 CET 2011


Hi Anand,

If I execute the same commands then the ca cert generation works.

- Verify if openssl rsa -inform der -in caKey.der -noout -text works

Regards

Andreas

On 10.11.2011 14:49, anand rao wrote:
> Hi,
>
>   I am using strongswan 4.3.6
>
> I have tried generate certificates using strongswan PKI gen tool to generate RSA certificate.
> I am getting below errors.
>
> root at evm1gw:/etc/cert# ipsec pki --gen>  caKey.der
> root at evm1gw:/etc/cert#
> root at evm1gw:/etc/cert# ipsec pki --self --in caKey.der --dn "C=IN,O=strongSwan, CN=strongSwan CA" --ca>  caCert.der
> file coded in unknown format, discarded
> building CRED_PRIVATE_KEY - RSA failed, tried 6 builders
> parsing private key failed
>
> I have used the default load so all the plugins are loaded. Please help.
>
> Thanks,
> Anand

======================================================================
Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4489 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20111110/d6f91ba2/attachment.bin>


More information about the Users mailing list