Re: [strongSwan] how to send/request the intermediate CAs?

2018-03-05 Thread Tobias Brunner
Hi Harald, > Even if Strongswan ignores the additional certs, is it possible that > some crypto implementation *used* by Strongswan does not, but reads > all certificates found in the cert files (in /etc/ipsec.d)? Only the pem plugin reads PEM encoded files, and it only parses one credential per

Re: [strongSwan] how to send/request the intermediate CAs?

2018-03-02 Thread Harald Dunkel
Hi Tobias, On 02/23/18 14:25, Tobias Brunner wrote: > Hi Harri, > >> I had hoped that putting the whole chain into /etc/ipsec.d/certs/mycert.pem >> would help, but apparently it doesn't. > > strongSwan reads only the first certificate from PEM encoded files. So > put them in separate files. >

Re: [strongSwan] how to send/request the intermediate CAs?

2018-02-27 Thread Tobias Brunner
Hi Harald, > I had hoped that putting the whole chain into > /etc/ipsec.d/certs/mycert.pem > would help, but apparently it doesn't. strongSwan reads only the first certificate from PEM encoded files. So put them in separate files. >>> >>> This is unusual, is it?

Re: [strongSwan] how to send/request the intermediate CAs?

2018-02-27 Thread Harald Dunkel
Hi Tobias, On 02/26/18 09:28, Tobias Brunner wrote: Hi Harri, I had hoped that putting the whole chain into /etc/ipsec.d/certs/mycert.pem would help, but apparently it doesn't. strongSwan reads only the first certificate from PEM encoded files. So put them in separate files. This is

Re: [strongSwan] how to send/request the intermediate CAs?

2018-02-26 Thread Tobias Brunner
Hi Harri, >>> I had hoped that putting the whole chain into /etc/ipsec.d/certs/mycert.pem >>> would help, but apparently it doesn't. >> >> strongSwan reads only the first certificate from PEM encoded files. So >> put them in separate files. >> > > This is unusual, is it? What is? > If I do,

Re: [strongSwan] how to send/request the intermediate CAs?

2018-02-24 Thread Harald Dunkel
Hi Tobias, On 02/23/18 14:25, Tobias Brunner wrote: > Hi Harri, > >> I had hoped that putting the whole chain into /etc/ipsec.d/certs/mycert.pem >> would help, but apparently it doesn't. > > strongSwan reads only the first certificate from PEM encoded files. So > put them in separate files. >

Re: [strongSwan] how to send/request the intermediate CAs?

2018-02-23 Thread Tobias Brunner
Hi Harri, > I had hoped that putting the whole chain into /etc/ipsec.d/certs/mycert.pem > would help, but apparently it doesn't. strongSwan reads only the first certificate from PEM encoded files. So put them in separate files. Regards, Tobias