Hi list,

We are trying to establish IPSEC dynamic tunnel between 2 Zos lpars.
We created the Policy Agent, IKED and also the ipsec_policy.
Everything should be working.

We have defined in each LPAR:
1. Self signed CA
2. The IKE deamon certificate signed by the local CA
3. Connected both certificates to a  RING own by
    the IKED UserId
4. Define the CA in the iked condiguration file...

When we try to TELNET between the 2 lpars
we can see in IKED sysout that negotioation is started
but then it failes with this MSG:

EZD1037I The IKE daemon has no matching certificate entry
for the specified LocalSecurityEndpoint identity ( 172.31.20.65 )
and certificate authority
( CN=IKED Test SYSD_SYSC,O=Bankomat SYSD,C=IL )

Where 172.31.20.65  is the local security end point (the lpar which we are
trying to telnet from...)
and CN=IKED Test SYSD_SYSC,O=Bankomat SYSD,C=IL is the CA
we have defined in the Second lpar (the TELNET server).

We have tried everything we tought about but still
it's not working?

Any ideas? Whatare we missing?

Thanks in advanced.

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to