[Swan-dev] can add connection require a private key?
paul at nohats.ca
Mon Sep 21 02:16:29 UTC 2020
On Sun, 20 Sep 2020, Andrew Cagney wrote:
> - if orient() tries to load a cert and fails, should the connection be tossed or left unoriented?
It's too late than isn't it? The connection is already loaded before
orient() can be called on it.
> First, it looks like message generated by "ipsec whack --label 'SAwest-east leftrsasigkey' --keyid
> "@west" --pubkeyrsa ..." should trigger an attempt to load the corresponding private key (but ignore
> failure). Both of these:
> were relying on *.secrets triggering an attempt to load the private key.
> and this leads to a potential refinement:
> - "add" triggers a lazy attempt at loading the private key - this already happens with certificates (it
> warns when the private key is missing)
> - orient() can then check that the public / private key is available
More information about the Swan-dev