Justement c'est celle que j'ai choisi. J'étais déjà tombé il y a quelques temps sur le thread suivant dont tu étais l'initiateur.
http://forums.fr.ixus.net/viewtopic.php?p=144424&highlight=#144424
Je l'ai retrouvé cette AM. Je galère un peu.
J'ai généré les certif des deux côtés comme indiqué. Tout a fonctionné et je ne pense pas avoir fait d'erreur. Par contre quand je relance dans
Contrôle et statut de la connexion : le statut reste sur fermé.
J'ai la chose suivante dans les logs :
18:53:34 pluto[8467] loaded private key file '/var/ipcop/certs/hostkey.pem' (887 bytes)
18:53:34 pluto[8467] loading secrets from "/etc/ipsec.secrets"
18:53:34 pluto[8467] forgetting secrets
18:39:41 ipsec__plutorun ...could not start conn "homegrome"
18:39:41 ipsec__plutorun 021 no connection named "homegrome"
18:39:41 ipsec__plutorun ...could not route conn "homegrome"
18:39:40 ipsec__plutorun 021 no connection named "homegrome"
18:39:40 pluto[8467] loaded private key file '/var/ipcop/certs/hostkey.pem' (887 bytes)
18:39:40 pluto[8467] loading secrets from "/etc/ipsec.secrets"
18:39:40 pluto[8467] adding interface ipsec0/eth1 82.65.6.110:4500
18:39:40 pluto[8467] adding interface ipsec0/eth1 82.65.6.110
18:39:40 pluto[8467] listening for IKE messages
18:39:40 ipsec__plutorun ...could not add conn "homegrome"
18:39:40 ipsec__plutorun: whack error "homegrome" does not look numeric and name lookup failed "lns-vlq-44-poi-82-252-140-237.adsl.proxad.net"
18:39:39 pluto[8467] OpenPGP certificate file '/etc/pgpcert.pgp' not found
18:39:39 pluto[8467] loaded crl file 'cacrl.pem' (573 bytes)
18:39:39 pluto[8467] Changing to directory '/etc/ipsec.d/crls'
18:39:39 pluto[8467] loaded cacert file 'cacert.pem' (1294 bytes)
18:39:39 pluto[8467] error in X.509 certificate
18:39:39 pluto[8467] loaded cacert file 'cakey.pem' (1679 bytes)
18:39:39 pluto[8467] loaded cacert file 'cilccert.pem' (1253 bytes)
18:39:39 pluto[8467] Changing to directory '/etc/ipsec.d/cacerts'
18:39:39 pluto[8467] ike_alg_register_enc(): Activating OAKLEY_SSH_PRIVATE_65289: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_enc(): Activating OAKLEY_TWOFISH_CBC: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_hash(): Activating OAKLEY_SHA2_512: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_hash(): Activating OAKLEY_SHA2_256: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_enc(): Activating OAKLEY_SERPENT_CBC: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_enc(): Activating OAKLEY_CAST_CBC: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_enc(): Activating OAKLEY_BLOWFISH_CBC: Ok (ret=0)
18:39:39 pluto[8467] ike_alg_register_enc(): Activating OAKLEY_AES_CBC: Ok (ret=0)
18:39:39 pluto[8467] including NAT-Traversal patch (Version 0.6)
18:39:39 pluto[8467] including X.509 patch with traffic selectors (Version 0.9.42)
18:39:39 pluto[8467] Starting Pluto (Openswan Version 1.0.7)
18:39:38 ipsec_setup ...Openswan IPsec started
18:39:38 ipsec__plutorun Starting Pluto subsystem...
est ce que tu aurais une petite idée ?
merci d'avance.
grome
L'important n'est pas de construire seul une montagne, mais d'apporter à l'édifice humain sa contribution, ne serait ce qu'un caillou. St Exupéry