[strongSwan] Strongswan+RADIUS secret code problem?

T Z ttzforj at hotmail.com
Fri Oct 28 18:09:10 CEST 2011


Hi Martin,

I've imported the CA certificate (right?) but it doesn't help. I generated the certificate using the instruction here:
http://wiki.strongswan.org/projects/strongswan/wiki/IOS_%28Apple%29
where it says "the serverAuth flag is not required for authentication with an iOS client, but will allow both iOS and 
Windows 7 clients to authenticate using the same server certificate.".

> Subject: Re: [strongSwan] Strongswan+RADIUS secret code problem?
> From: martin at strongswan.org
> To: ttzforj at hotmail.com
> CC: users at lists.strongswan.org
> Date: Fri, 28 Oct 2011 17:56:35 +0200
> 
> Hi,
> 
> > Testing with Windows 7 IKEv2 client, it prompts "Error 13801: IKE
> > authentication credentials are unacceptable."
> 
> > 10[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH EAP/REQ/MD5 ]
> 
> Looks to me like the client does not accept the certificate it gets from
> the gateway. Does it have the properties outlined at [1]? Did you import
> the certificate or the CA in the Windows machine certificate store?
> 
> Regards
> Martin
> 
> [1]http://wiki.strongswan.org/projects/strongswan/wiki/Win7CertReq
> 
> 
> 
 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20111028/4cb1b32d/attachment.html>


More information about the Users mailing list