[Swan] Libreswan 4.6: connection IKEv2 win10 to Linux freezes soon after Android device connects

Paul Wouters paul at nohats.ca
Fri Jan 14 23:01:57 EET 2022


On Fri, 14 Jan 2022, Mirsad Goran Todorovac wrote:

> 1. FYI, I can confirm that my Android 11 Samsung Galaxy A22 5G & Tab S6 Lite 
> devices connected successfully over IKEv2, together with Win10 laptop, all at 
> the same time (two over the same NAT and one over 4G ISP).

good :)

> 2. I would like to test the interoperability of ECDSA certs with IKEv2, Win 
> 10, Android and maybe even iOS devices when I get some for testing ... also a 
> Linux desktop client comes to mind ... but I miss the reference material and 
> Google is not revealing much ...

It works the same as RSA certs if every aspect other than generating the
certificates with the other algorithm, and perhaps ensuring the authby=
is using "ecdsa" (although the default should already include that and
you should be able to omit it)

> Thank for the help with certs. :-)

You can look at our python code for generating CAs, certs et all that
generates a bunch of different (normal and very weird) things:

https://raw.githubusercontent.com/libreswan/libreswan/main/testing/x509/dist_certs.py

Paul


More information about the Swan mailing list