Re: ikectl ca and subjectAltName for IKEv2 VPNs

2021-03-08 Thread Stuart Henderson
On 2021-03-04, David Newman wrote: > On 3/4/21 12:29 AM, Stuart Henderson wrote: > >> On 2021-03-04, David Newman wrote: >>> Apparently Apple iOS and iPadOS VPN clients now require a subjectAltName >>> in the client cert, not just the CN, to set up IKEv2 VPN tunnels.* The >>> subjectAltName can

Re: ikectl ca and subjectAltName for IKEv2 VPNs

2021-03-04 Thread David Newman
On 3/4/21 12:29 AM, Stuart Henderson wrote: > On 2021-03-04, David Newman wrote: >> Apparently Apple iOS and iPadOS VPN clients now require a subjectAltName >> in the client cert, not just the CN, to set up IKEv2 VPN tunnels.* The >> subjectAltName can be the same as the CN; it just has to be

Re: ikectl ca and subjectAltName for IKEv2 VPNs

2021-03-04 Thread Stuart Henderson
On 2021-03-04, David Newman wrote: > Apparently Apple iOS and iPadOS VPN clients now require a subjectAltName > in the client cert, not just the CN, to set up IKEv2 VPN tunnels.* The > subjectAltName can be the same as the CN; it just has to be present. Most IKE software has always needed this.

ikectl ca and subjectAltName for IKEv2 VPNs

2021-03-03 Thread David Newman
Apparently Apple iOS and iPadOS VPN clients now require a subjectAltName in the client cert, not just the CN, to set up IKEv2 VPN tunnels.* The subjectAltName can be the same as the CN; it just has to be present. Questions about this: 1. Does the 'ikectl ca certificate create' command support