https://bugs.kde.org/show_bug.cgi?id=526170
Bug ID: 526170
Summary: plasma fails to add proper VPN IKEv2/IPsec using
Strongswan with certificate + key
Classification: Applications
Product: systemsettings
Version First 6.7.5
Reported In:
Platform: Other
OS: Linux
Status: REPORTED
Severity: normal
Priority: NOR
Component: kcm_networkmanagement
Assignee: [email protected]
Reporter: [email protected]
CC: [email protected]
Target Milestone: ---
DESCRIPTION
When you want to create or modify IKEv2/IPsec vpn connection with cert+key
authentication plasma produces malformed .nmconnection file
related with https://bugs.kde.org/show_bug.cgi?id=443495 +
https://bugs.kde.org/show_bug.cgi?id=429639 but broader
STEPS TO REPRODUCE
1. create or modify previously working connection
2. try to connect
OBSERVED RESULT
It fails as decribed in the troublshooting
https://bugzilla.opensuse.org/show_bug.cgi?id=1282536
connection file in /etc/NetworkManager/system-connections/
contains method=key even though i select certificate in the combobox
EXPECTED RESULT
The file should contain minumum those to work:
it lacks :
local-identity= (it's not even added in the created file, also in plasma no way
to specify it making the whole stronswan useless in plasma)
method=cert (plasma puts =key)
password-flags=1 (not added by plasma without it it does not work at all)
Also in plasma gui there is a window to place password for the key but it is
not used in anyway or at least i have to specify it everytime in order to get
it working. So every time i have to enter the password when i click on
"connect"
The proper way to call nmcli to get strongstwan working with cert+key is
nmcli connection add \
type vpn \
con-name "CONNECTION_NAME" \
ifname "*" \
vpn-type org.freedesktop.NetworkManager.strongswan \
ipv4.never-default yes \
ipv6.never-default yes \
vpn.data "address = GW_ADDRESS, \
certificate = GW.crt, \
encap = no, \
ipcomp = no, \
local-identity = YOUR_VPN_IDENTITY, \
method = cert, \
password-flags = 1, \
proposal = no, \
remote-identity = YOUR_GW_IDENTITY, \
usercert =VPN_USER.crt, \
userkey = VPN_USER.key, \
virtual = yes"
Sometimes modiying the connection deletes user .crt and .key i already have
specified as https://bugs.kde.org/show_bug.cgi?id=429639
SOFTWARE/OS VERSIONS
Operating System (available in the Info Center app, or by running `kinfo` in a
terminal window):
KDE Plasma Version: 6.7.5
KDE Frameworks Version:
Qt Version: 6.11
ADDITIONAL INFORMATION
Opensuse Slowroll
--
You are receiving this mail because:
You are watching all bug changes.