[Swan] Unknown RSA Key

Phil Daws uxbod at splatnix.net
Tue Dec 16 22:18:25 EET 2014


Hello:

am new to libreswan and attempting to set up an IPSEC tunnel between two subnets.  The issue am facing is that when I bring up the connection I see:

"network1" #28: no RSA public key known for 'CN=fwl01.bbb'

yet if I check the NSS database the certificate is there and the CN is correct.  This is how my connection looks:

conn network1
        left=XXX.XXX.XXX.XXX
        leftid="CN=fwl01.aaa"
        leftsourceip=XXX.XXX.XXX.XXX
        leftrsasigkey=%cert
        leftcert="fwl01-aaa"
        leftnexthop=XXX.XXX.XXX.XXX
        right=XXX.XXX.XXX.XXX
        rightid="CN=fwl01.bbb"
        rightsourceip=XXX.XXX.XXX.XXX
        rightrsasigkey=%cert
        rightnexthop=XXX.XXX.XXX.XXX
        rekey=no
        esp="aes-sha1"
        ike="aes-sha1"
        auto=add

What may I be missing please ? Thanks, Phil



More information about the Swan mailing list