From owner-freebsd-security Thu Jun 20 23:28:19 2002 Delivered-To: freebsd-security@freebsd.org Received: from sccrmhc03.attbi.com (sccrmhc03.attbi.com [204.127.202.63]) by hub.freebsd.org (Postfix) with ESMTP id C2B8B37B407 for ; Thu, 20 Jun 2002 23:28:12 -0700 (PDT) Received: from blossom.cjclark.org ([12.234.91.48]) by sccrmhc03.attbi.com (InterMail vM.4.01.03.27 201-229-121-127-20010626) with ESMTP id <20020621062812.SBFF20219.sccrmhc03.attbi.com@blossom.cjclark.org> for ; Fri, 21 Jun 2002 06:28:12 +0000 Received: from blossom.cjclark.org (localhost. [127.0.0.1]) by blossom.cjclark.org (8.12.3/8.12.3) with ESMTP id g5L6SAJK029539 for ; Thu, 20 Jun 2002 23:28:11 -0700 (PDT) (envelope-from cjc@blossom.cjclark.org) Received: (from cjc@localhost) by blossom.cjclark.org (8.12.3/8.12.3/Submit) id g5L6SA8A029538 for security@freebsd.org; Thu, 20 Jun 2002 23:28:10 -0700 (PDT) Date: Tue, 18 Jun 2002 13:05:47 -0700 From: "Crist J. Clark" To: security@freebsd.org Subject: Configuring sainfo in racoon(8) Message-ID: <20020618130547.A11688@blossom.cjclark.org> Reply-To: cjclark@alum.mit.edu Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5.1i X-URL: http://people.freebsd.org/~cjc/ Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org I am trying to get some ESP tunnels going. I am using racoon(8) to handle the IKE to negotiate the SAs. I am having a problem right from the start. My racoon.conf(5) looks something like, remote 192.168.100.1 { ... my_identifier user_fqdn "cjc@mydomain.org"; peer_identifier user_fqdn "cjc@mydomain.org"; ... } sainfo user_fqdn "cjc@mydomain.org" user_fqdn "cjc@mydomain.org" { ... } I have my SPD set, # setkey -c <