[Swan] How to use libreswan with racoon certifcates

MARSON Ismenia ismenia.marson-ext at sagemcom.com
Thu Nov 14 10:10:10 UTC 2019


Hi Paul,

Thank you for your response.
I did:
#openssl pkcs12 -export -inkey key.pkey -in key.cer -out key.p12
#ipsec import key.p12
#service ipsec restart

it'sound good but when I capture the traffic with wireshark, i didn't see encrypted traffic to a server who has racoon and ipsec tools.

I would like to have encrypted ESP traffic.

Thank you for your help.



On 11/13/19 3:17 PM, Paul Wouters wrote:
[EXTERNAL]-Real sender is: paul at nohats.ca<mailto:paul at nohats.ca>
________________________________


On Nov 13, 2019, at 08:50, MARSON Ismenia <ismenia.marson-ext at sagemcom.com<mailto:ismenia.marson-ext at sagemcom.com>> wrote:

Hello swan community,

I hope that you could help me or if you can give me some advice.
I used ubuntu 16 and i used ipsec-tools and racoon. I create racoon
certs in /etc/racoon/certs. I have two certs, a .cer  and a .pkey files.
Now, i want to use debian 10 and i see that ipsec-tools and racoon are
not supported on this new OS.
I installed libreswan, and i want to keep using my old racoon certificates.

https://libreswan.org/wiki/HOWTO:_Using_NSS_with_libreswan#Importing_third-party_files_into_NSS<https://urldefense.proofpoint.com/v2/url?u=https-3A__libreswan.org_wiki_HOWTO-3A-5FUsing-5FNSS-5Fwith-5Flibreswan-23Importing-5Fthird-2Dparty-5Ffiles-5Finto-5FNSS&d=DwMFaQ&c=3H3w9x2bmP2ldeACwfvarQ&r=0BVB9TyGPZePigFrF4jmZM_n8wfytXi94C0DPCz9ltY&m=IFjVaa4sYz7D3bhwUFHEDZ3LT7zGJ5hqERDPjNc2MmM&s=iiw1IIB36cyzM3KX_qGG6T5epWIfwpV9JgB7YvUgAHM&e=>

Create a pkcs#12 file from the cert/cacert and key, and run: ipsec import file.p12

Paul

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Ce courriel et les documents qui lui sont joints sont, sauf mention contraire, présumés de nature confidentielle et destinées à l'usage exclusif du ou des destinataire(s) mentionné(s). Si vous n'êtes pas le ou les destinataire(s), vous êtes informé(e) que toute divulgation, reproduction, distribution, toute autre diffusion ou utilisation de cette communication ou de tout ou partie de ces informations est strictement interdite, sauf accord préalable de l’expéditeur. Si ce message vous a été transmis par erreur, merci d’immédiatement en informer l'expéditeur et supprimer de votre système informatique ce courriel ainsi que tous les documents qui y sont attachés. En vous remerciant de votre coopération.

This email and any attached documents are, unless otherwise stated, presumed to be confidential and intended for the exclusive use of the recipient(s) mentioned. If you are not the recipient(s), you are informed that any disclosure, reproduction, distribution, any other dissemination or use of this communication or all or part of this information is strictly prohibited, unless agreed beforehand by the sender. If you have received this e-mail in error, please immediately advise the sender and delete this e-mail and all the attached documents from your computer system. Thanking you for your cooperation.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.libreswan.org/pipermail/swan/attachments/20191114/cd058f19/attachment.html>


More information about the Swan mailing list