[strongSwan] [Strongswan] Authentication based on X.509 using DN identification has failed and getting errors

Tobias Brunner tobias at strongswan.org
Thu Oct 4 14:03:21 CEST 2012


Hi,

> Oct  1 14:42:26 localhost charon: 13[ENC] parsed IKE_AUTH request 1 [
> IDi CERT CERTREQ AUTH SA TSi TSr ]
> ...
> Oct  1 14:42:26 localhost charon: 13[CFG] looking for peer configs
> matching 35.0.0.2[%any]...35.0.0.1[]

Your client seemed have sent an empty IDi payload (seen as [] above),
which will not match with the config where you configured

> conn site-site
>     ...
>     rightid="C=CH, O=strongswan, CN=iss"
>     ...

What did you configure on the client?

Regards,
Tobias




More information about the Users mailing list