https://bugs.kde.org/show_bug.cgi?id=526170

            Bug ID: 526170
           Summary: plasma fails to add proper VPN IKEv2/IPsec using
                    Strongswan with  certificate + key
    Classification: Applications
           Product: systemsettings
      Version First 6.7.5
       Reported In:
          Platform: Other
                OS: Linux
            Status: REPORTED
          Severity: normal
          Priority: NOR
         Component: kcm_networkmanagement
          Assignee: [email protected]
          Reporter: [email protected]
                CC: [email protected]
  Target Milestone: ---

DESCRIPTION
When you want to create or modify IKEv2/IPsec vpn connection with cert+key
authentication plasma produces malformed .nmconnection file

related with https://bugs.kde.org/show_bug.cgi?id=443495 +
https://bugs.kde.org/show_bug.cgi?id=429639 but broader

STEPS TO REPRODUCE
1. create or modify previously working connection
2. try to connect


OBSERVED RESULT
It fails as decribed in the troublshooting
https://bugzilla.opensuse.org/show_bug.cgi?id=1282536
connection file in /etc/NetworkManager/system-connections/
contains method=key even though i select certificate in the combobox

EXPECTED RESULT
The file should contain minumum those to work:

it lacks :
local-identity= (it's not even added in the created file, also in plasma no way
to specify it making the whole stronswan useless in plasma)
method=cert (plasma puts =key)
password-flags=1 (not added by plasma without it it does not work at all)

Also in plasma gui there is a window to place password for the key but it is
not used in anyway or at least i have to specify it everytime in order to get
it working. So every time i have to enter the password when i click on
"connect"

The proper way to call nmcli to get strongstwan working with cert+key is
nmcli connection add \
  type vpn \
  con-name "CONNECTION_NAME" \
  ifname "*" \
  vpn-type org.freedesktop.NetworkManager.strongswan \
  ipv4.never-default yes \
  ipv6.never-default yes \
  vpn.data "address = GW_ADDRESS, \
            certificate = GW.crt, \
            encap = no, \
            ipcomp = no, \
            local-identity = YOUR_VPN_IDENTITY, \
            method = cert, \
            password-flags = 1, \
            proposal = no, \
            remote-identity = YOUR_GW_IDENTITY, \
            usercert =VPN_USER.crt, \
            userkey = VPN_USER.key, \
            virtual = yes"

Sometimes modiying the connection deletes user .crt and .key i already have
specified as https://bugs.kde.org/show_bug.cgi?id=429639

SOFTWARE/OS VERSIONS
Operating System (available in the Info Center app, or by running `kinfo` in a
terminal window):
KDE Plasma Version: 6.7.5
KDE Frameworks Version: 
Qt Version: 6.11

ADDITIONAL INFORMATION
Opensuse Slowroll

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to