[Swan] LIBRESWAN -- pluto not running

Madhan Raj madhanrajrm at gmail.com
Wed Feb 6 11:07:58 UTC 2019


Hi all,

I am an active libreswan user. just need to know when will i get this below
error:

Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: FIPS Product: YES
Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: FIPS Kernel: YES
Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: FIPS Mode: YES
Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: NSS DB directory:
sql:/etc/ipsec.d
Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: Initializing NSS
Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: Opening NSS database
"sql:/etc/ipsec.d" read-only
Feb  6 16:12:08 CuCM-216 authpriv 4 pluto: NSS Password from file
"/usr/local/platform/.security/ipsec/nsspassword" for token "NSS FIPS 140-2
Certificate DB" with length 8 passed to NSS
Feb  6 16:12:09 CuCM-216 authpriv 4 pluto: authentication of "NSS FIPS
140-2 Certificate DB" failed
Feb  6 16:12:09 CuCM-216 authpriv 4 pluto: FATAL: NSS initialization failure
Feb  6 16:12:09 CuCM-216 authpriv 7 pluto: | pluto_sd: executing action
action: stopping(6), status 6
Feb  6 16:12:09 CuCM-216 authpriv 7 pluto: | certs and keys locked by
'free_preshared_secrets'
Feb  6 16:12:09 CuCM-216 authpriv 7 pluto: | certs and keys unlocked by
'free_preshard_secrets'
Feb  6 16:12:09 CuCM-216 authpriv 7 pluto: | crl fetch request list locked
by 'free_crl_fetch'
Feb  6 16:12:09 CuCM-216 authpriv 7 pluto: | crl fetch request list
unlocked by 'free_crl_fetch'
Feb  6 16:12:09 CuCM-216 authpriv 4 pluto: leak detective found no leaks
Feb  6 16:12:09 CuCM-216 authpriv 7 pluto: | pluto_sd: executing action
action: exit(1), status 6

i am using my custom nssdb location.
NOTE: In my "/usr/local/platform/.security/ipsec/nsspassword"  file it has
the proper value as "NSS FIPS 140-2 Certificate DB: <mypwd>"

Thanks,
Madhan.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.libreswan.org/pipermail/swan/attachments/20190206/29b1213d/attachment.html>


More information about the Swan mailing list