Re: iked x509 negotiation problem with BlackBerry OS 10.3.1

2015-07-07 Thread Denis Lapshin
Having patched ikev2_pld.c to accept emty certreq still have no connection from BlackBerry smartphone. Please give some ideas what can be wrong? On 04.07.2015 11:24, Denis Lapshin wrote: Index: ikev2_pld.c === RCS file: /cvs/src/s

Re: iked x509 negotiation problem with BlackBerry OS 10.3.1

2015-07-04 Thread Denis Lapshin
Stuart, I've just added patch you've provided. The error about "cert request" disappeared but the connection freezes. The phone has been set to "Automatically determine algorithm". Does it affect or should I set the same algorithm on both ends? ikev2_pld_payloads: decrypted payload CERTREQ

Re: iked x509 negotiation problem with BlackBerry OS 10.3.1

2015-07-03 Thread Stuart Henderson
On 2015-07-03, Stuart Henderson wrote: > On 2015-07-02, Denis Lapshin wrote: >> ikev2_pld_payloads: decrypted payload CERTREQ nextpayload CP critical >> 0x00 length 5 >> ikev2_pld_certreq: type X509_CERT signatures length 0 >> ikev2_pld_certreq: invalid certificate request >> ikev2_resp_recv: fa

Re: iked x509 negotiation problem with BlackBerry OS 10.3.1

2015-07-03 Thread Stuart Henderson
On 2015-07-02, Denis Lapshin wrote: > ikev2_pld_payloads: decrypted payload CERTREQ nextpayload CP critical > 0x00 length 5 > ikev2_pld_certreq: type X509_CERT signatures length 0 > ikev2_pld_certreq: invalid certificate request > ikev2_resp_recv: failed to parse message iked doesn't accept an e

Re: iked x509 negotiation problem with BlackBerry OS 10.3.1

2015-07-02 Thread Denis Lapshin
Can it be MTU problem? On 02.07.2015 11:51, Denis Lapshin wrote: Hi, Have working setup with OpenIKEd and Win7 machine in part of IPsec link negotiating by using IKEv2 and MSCHAP-v2. Using certificate and 2048 key in *.P12 form. 10.0.20.0/24 is local network 10.0.10.0/24 is IPsec network DNS

iked x509 negotiation problem with BlackBerry OS 10.3.1

2015-07-02 Thread Denis Lapshin
Hi, Have working setup with OpenIKEd and Win7 machine in part of IPsec link negotiating by using IKEv2 and MSCHAP-v2. Using certificate and 2048 key in *.P12 form. 10.0.20.0/24 is local network 10.0.10.0/24 is IPsec network DNS server is 10.0.20.1 /etc/iked.conf is: ikev2 "winauth" passive e