[Openswan Users] One cert, multiple connections?

Paul Wouters paul at xelerance.com
Fri Jul 22 10:53:30 EDT 2011


On Fri, 22 Jul 2011, Richard Pickett wrote:

> Using x.509 for client auth, does the server permit multiple connections
> from different computers (with different IPs) all using the same client
> cert?

       uniqueids

        whether  a particular participant ID should be kept unique, with
        any new (automatically keyed) connection using an ID from a dif-
        ferent  IP address deemed to replace all old ones using that ID.
        Acceptable values are yes (the default) and no. Participant  IDs
        normally  are  unique, so a new (automatically-keyed) connection
        using the same ID is almost invariably intended  to  replace  an
        old one.

However, it is not wise to do so....

Paul


More information about the Users mailing list