[strongSwan] Error using pki in StrongSwan 5.1.0

Gregg Hughes ghughes at iscinternational.com
Fri Aug 9 23:41:23 CEST 2013

Good afternoon, all!


I'm retesting Strongswan 5.1 in a virtual environment and have managed to
overcome most obstacles until this one.  Following the directions on
generating a simple CA structure using ipsec pki, I got as far as generating
a new host certificate and got the error "CA certificate misses CA
basicConstraint."  I did the googling thing and found some older postings
(over a year ago) with a couple of patches that don't apply to my version.  


I don't see any way to insert this into the ipsec pki process to add that
constraint condition back to the CA.


Is this a bug or am I missing a part of the process?


Thanks in advance!





Gregg Hughes

IT Administrator


414.721.0301 phone

262.313.3106 fax





-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20130809/ed581c49/attachment.html>

More information about the Users mailing list