<div dir="ltr">Hi Swan users, <div><br></div><div>My libreswan version is libreswan-3.25-9.1.el7.x86_64 </div><div><br></div><div>and my public key has the below XU and EXU extensions currently </div><div><br></div><div> X509v3 Key Usage:<br> Digital Signature, Key Encipherment, Data Encipherment, Certificate Sign<br> X509v3 Extended Key Usage:<br> TLS Web Server Authentication, TLS Web Client Authentication, IPSec End System<br> X509v3 Subject Key Identifier:<br> EF:D1:D4:57:4F:A1:4A:61:0F:DE:FB:27:AA:63:74:BC:94:ED:A1:18<br> X509v3 Basic Constraints: critical<br> CA:TRUE, pathlen:0<br></div><div><br></div><div>So i wan't to know does libreswan really need the
Key Encipherment & IPSec End System XKU to bring up the IKE connection ?</div><div><br></div><div>It would be great if I can get the recommended XU and EXU in the public key to bring up an ipsec connection up and running. </div><div><br></div><div>Thanks,</div><div>Madhan</div></div>