Awesome thanks for that.  I believe I was having an issue with some
intermediary firewalls / nat  devices dropping my oversized packets
due to the size of the rsa certs.  Hopefully preloading them will fix

Out of interest how does  the strongswan daemon know which cert
corresponds to which client? Is  the client just sending the subject
of it's certificate and then the  daemon uses that to choose a
corresponding client cert?
On 2/10/2014 at 3:37 PM, "Martin Willi"  wrote:Pete,

> I've copied them to the /etc/ipsec.d/certs directory and restarted
> daemon but "ipsec listcerts" still only lists the certificates that
> have a private key for.

Certificates from the cert directory do not get loaded automatically.
The directory merely holds the certificates you can directly reference
with left/rightcert. This is a little different from the swanctl x509
directory [1], for which all contained certificates get loaded

If you have a large bunch of client certificates to handle, you
don't want a conn entry in ipsec.conf for each. Usually you issue all
the certificates from a CA to avoid handling all the client
separately, and just install the CA to cacerts.


