[Openswan Users] seems ok but receive 678 error

Paul Wouters paul at xelerance.com
Wed May 18 15:38:01 CEST 2005


On Wed, 18 May 2005, Luca Ballerini wrote:

> CLIENTIP #20: Main mode peer ID is ID_DER_ASN1_DN: 'C=IT, ST=Marche,
> L=Montegranaro, O=MarcoCannella, CN=MarcoCannella,
> E=info at marcocannella.it'
> May 18 11:38:04 SERVERNAME pluto[23206]: "roadwarrior-l2tp"[21]
> CLIENTIP #20: end certificate with identical subject and issuer not
> accepted
> May 18 11:38:04 SERVERNAME pluto[23206]: "roadwarrior-l2tp"[21]
> CLIENTIP #20: X.509 certificate rejected

You created a certificate with the same CN= as the CA. This is rejected.

All CN's have to be unique. It is recomended to always include the string "CA"
or "Certificate Authority" in the CA's CN=

Paul


More information about the Users mailing list