Re: [strongSwan] Strongswan does not removes CA Certificate from its internal objects (RAM) even after removing the certificate from cacerts directory or ca section.

2015-05-14 Thread Sajal Malhotra
Hi Martin, Is it possible to share patch details that we can apply over v5.2? I need changes that will re/unload CA certificates referenced in ipsec.conf ca sections via "ipsec update" command. Using the link you shared I am not able to identify how to get to the changed files of the 6 patches th

Re: [strongSwan] Strongswan does not removes CA Certificate from its internal objects (RAM) even after removing the certificate from cacerts directory or ca section.

2015-05-13 Thread Sajal Malhotra
Thanks Martin for a quick reply. I was looking at link for patches that you shared however could not identify which 6 patches include the fix as there are many patches available on this link: http://git.strongswan.org/?p=strongswan.git;a=shortlog BR Sajal On May 13, 2015 3:17 PM, "Martin Wil

Re: [strongSwan] Strongswan does not removes CA Certificate from its internal objects (RAM) even after removing the certificate from cacerts directory or ca section.

2015-05-13 Thread Martin Willi
Hi, > ca section1 > cacert=/usr/local/etc/ipsec.d/cacerts/CA.pem > 6. After removing this and executing "ipsec update" we expect that the > SA will not get established as the end which does not have root CA of > peer will reject the IKE_AUTH. All CA certificates placed under the cacerts

[strongSwan] Strongswan does not removes CA Certificate from its internal objects (RAM) even after removing the certificate from cacerts directory or ca section.

2015-05-13 Thread Sajal Malhotra
Hi, We are using Strongswan 4.2 and 5.2 version of stack in our Lab and we have following setup: Linux Box 1(v4.2)<->Linux Box 2(v5.2) Here is what we are trying: 1. Both Sides are using Device Certificates signed by different Root CA. 2. On both Devices we have provided both the root CA ce