Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-16 Thread Tim Stewart
Matt, Matthew Ernisse writes: > I have not tried ECDSA, however I've had iOS and macOS devices > running with iked since it came into OpenBSD using certificate auth > with RSA 2048 certs and a RSA 4096 CA. > > I just recently wrote a blog post on it, it includes a general overview > of how I

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-06 Thread Michael Lam
Hi, I don't have GRE and all clients are iOS devices on the same policy. The symptom is like when the 2nd client connects, the IPSec flow that is shown via ipsecctl -sa indicates that the 2nd flow, due to the fact that it is assigned an IP address in the same subnet of the first one (due to the

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-05 Thread Scott Bonds
On 04/05, Michael Lam wrote: Are you able to have 2 clients connected at the same time? When I tried that (I am using mschap) whenever the 2nd client connects the 1st one's traffic will not go through anymore (it stays connected but no traffic can go through). I've noticed that, if my 2 ikedv2

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-05 Thread Matthew Ernisse
On Fri, Apr 05, 2019 at 01:45:19PM +, Michael Lam said unto me: > > Are you able to have 2 clients connected at the same time? When I tried > that (I am using mschap) whenever the 2nd client connects the 1st one's > traffic will not go through anymore (it stays connected but no traffic > can

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-05 Thread Michael Lam
Are you able to have 2 clients connected at the same time? When I tried that (I am using mschap) whenever the 2nd client connects the 1st one's traffic will not go through anymore (it stays connected but no traffic can go through). I raised this a month ago but seems to have no response. Still

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-05 Thread Matthew Ernisse
I have not tried ECDSA, however I've had iOS and macOS devices running with iked since it came into OpenBSD using certificate auth with RSA 2048 certs and a RSA 4096 CA. I just recently wrote a blog post on it, it includes a general overview of how I did it and a fragment of my .mobileconfig and

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-04 Thread Tim Stewart
Hi Ted, On 6/2/18 12:26 PM, Theodore Wynnychenko wrote: Hello Last year (before about 3/27/2017 when "Add support for RFC4754 (ECDSA) and RFC7427 authentication" diff was committed to current), I had set up and had been able to connect iOS devices (iphone/ipad) to OpenBSD's iked, and have

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2018-06-03 Thread J Vans
> Hello > > Last year (before about 3/27/2017 when "Add support for RFC4754 (ECDSA) and > RFC7427 authentication" diff was committed to current), I had set up and had > been able to connect iOS devices (iphone/ipad) to OpenBSD's iked, and have ikev2 > VPN's happen, almost as if by, magic. > >

Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2018-06-02 Thread Theodore Wynnychenko
Hello Last year (before about 3/27/2017 when "Add support for RFC4754 (ECDSA) and RFC7427 authentication" diff was committed to current), I had set up and had been able to connect iOS devices (iphone/ipad) to OpenBSD's iked, and have ikev2 VPN's happen, almost as if by, magic. Authentication was