[Openswan Users] Pluto failures

Lewis Shobbrook lshobbrook at fasttrack.net.au
Fri Apr 16 22:09:18 CEST 2004


Hi All,

Upgrading to OpenSwan 2.11 on a Debian unstable running 2.6-4 native
stack.  I've noted that the ipsec.secrets fails to load.
Ipsec_verify idicates...
for RSA private key (/etc/ipsec.secrets)                       [FAILED]
showhostkey: no default key in "/etc/ipsec.secrets"

Ipsec.secrets has an RSA key listed as follows (worked previously)

: RSA my.key "mypasswd"

Pluto fails with the following...

ipsec__plutorun: /usr/local/lib/ipsec/_plutorun: line 1:  8388
Segmentation fault  /usr/local/libexec/ipsec/pluto --nofork
--secretsfile /etc/ipsec.secrets --ipsecdir /etc/ipsec.d --uniqueids
--nat_traversal    
ipsec__plutorun: whack: is Pluto running?  connect() for
"/var/run/pluto.ctl" failed (111 Connection refused)
ipsec__plutorun: ...could not add conn "roadwarrior"
ipsec__plutorun: whack: is Pluto running?  connect() for
"/var/run/pluto.ctl" failed (111 Connection refused)
ipsec__plutorun: !pluto failure!:  exited with error status 139 (signal
11)
fireone ipsec__plutorun: restarting IPsec after pause...

I have a what is as far as I can acertain and identical setup which
works, the only difference being the RSA key.  On the working system the
RSA key was installed during STD deb post install configuration and
doesn't use a password to access the key, on the broken system where the
key fails to load, the key was created using openssl (Key had been
operational for quite a while prior to upgrade).

Anyone come across this sort of thing before?

Cheers,

Lewis 


More information about the Users mailing list