Re: [strongSwan] Logging

2010-11-30 Thread Martin Willi
Hi Francois, - I haven't been able to use stdout or stderr to print anything Be aware that ipsec starter forks the daemon by default, so you won't see what the daemon logs. Invoke with --nofork to see logs to stdout/stderr. - When I'm using a real file to log, the content is written only

Re: [strongSwan] certificate status is not available

2010-11-30 Thread Andreas Steffen
Hello Laurence, as I wrote to Bijan, I would need the certificate for closer inspection of the DER encoding of the distingushed name. Regards Andreas On 11/30/2010 08:56 AM, Groebl, Laurence (Laurence) wrote: Hello Andreas, thanks for the reply. we fixed the issue of the missing '.' (full

Re: [strongSwan] certificate status is not available

2010-11-30 Thread Farivar Tanha, Bijan (Bijan)
Hello Andreas, thanks for the reply. We set strictcrlpolicy to no, it's working. Thanks for your support, Best regards, Laurence Bijan Bijan Farivar Tanha Dept. MS/E

Re: [strongSwan] [RFC][PATCH] set negotiated traffic selectors in SAs for transport mode

2010-11-30 Thread Tobias Brunner
Hi Richard, Hi Tobias, was this ever included in strongswan. We are failing this test while undergoing USGv6 certification testing and would like to be able to have a fix. No, it has not yet been applied. The patch still fixes this particular test case, so you may try applying it. But

Re: [strongSwan] Fail on loading secrets (ECDSA)

2010-11-30 Thread Andreas Steffen
Hello Bill, what does restarting mean? Does charon crash? (what it shouldn't) If you give the key in PEM format then it is normal that it is automatically converted to DER format first. Regards Andreas On 11/30/2010 09:55 PM, William Greene wrote: Hello, The charon daemon keeps restarting

[strongSwan] Logging

2010-11-30 Thread Francois Bard
Hi Martin, Thanks for your answer ! I should have upgraded first thing instead of being lazy and using the ubuntu package... Well it's working like a charm now. I think it would be great if these info were added to the wiki page, it would make it perfect. Regards Francois

[strongSwan] About multi-tunnel support

2010-11-30 Thread David Deng
Hi Andreas, Hi All, Wheter Strongswan can support mult-tunnel? In order to make clear this question, I did some test and found that: 1) It seems that Strongswan can support scenario Multi-IKESA, one ESP SA per IKE SA; 2) but I am not sure whether Strongswan can support scenario one-IKESA,