Tuesday, July 23, 2019

Re: [iked] differentiating policies by dstid

Hello Tobias,
thanks a lot, that solved the question for me (at least on the server :) ).

Using ASN1 ids iked detects the matching policy. However, it then uses RFC7427 for auth (SIG), but the Windows 10 clients use RSA_SIG. This causes a mismatch and the connection can't be established. (Yet, Windows 10 is lacking support for aforementioned RFC).

So, I have to find another way, but thank you very much.

Best regards,

Alex

No comments:

Post a Comment