[strongSwan] Separate files for crt and key

Noel Kuntze noel.kuntze+strongswan-users-ml at thermi.consulting
Fri Jan 26 16:44:19 CET 2018


Hi,

The pretense - that charon loads the cert and key from the same file - is wrong. charon takes the path to the key from ipsec.secrets.

Kind regards

Noel

On 26.01.2018 15:01, Marc Roos wrote:
> Is it possible to specify separate files for the crt and key? Something 
> like
>
> 	leftcert=moonCert.crt
>       leftkey=moonCert.key ???
>
>
>
>
> conn rw-eap
> 	left=192.168.0.1
> 	leftsubnet=10.1.0.0/16
> 	leftid=@moon.strongswan.org
> 	leftcert=moonCert.pem
> 	leftauth=pubkey
> 	leftfirewall=yes
> 	rightid=*@strongswan.org
> 	rightauth=eap-md5
> 	rightsendcert=never
> 	right=%any
> 	auto=add

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20180126/1287d63d/attachment.sig>


More information about the Users mailing list