PS: To clarify the CA story: There is a self-signed root certificate, an intermediate "IPsec" certificate signed by the root cert, and a client cert for each peer signed by the IPsec cert. Of course the whole chain has been loaded on the iphone. Regards Harri