Project

General

Profile

Actions

Feature #4234

open
PB

allow for strict user <> cn validation of mobile ipsec users when using rsa+xauth

Feature #4234: allow for strict user <> cn validation of mobile ipsec users when using rsa+xauth

Added by Pi Ba over 11 years ago. Updated over 9 years ago.

Status:
Assigned
Priority:
Low
Assignee:
-
Category:
IPsec
Target version:
Start date:
01/18/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:

Description

Allow for strict user <> cn validation of mobile ipsec users when using rsa+xauth
It seems the gui setting is missing, but the background code is already in place to allow this.

RB Updated by Renato Botelho over 11 years ago Actions #1

  • Target version changed from 2.2 to 2.2.1

Push it to 2.2.1

CB Updated by Chris Buechler over 11 years ago Actions #2

  • Target version changed from 2.2.1 to 2.2.2

CB Updated by Chris Buechler over 11 years ago Actions #3

  • Target version changed from 2.2.2 to 2.2.3

CB Updated by Chris Buechler over 11 years ago Actions #4

  • Target version changed from 2.2.3 to 2.3

JT Updated by Jim Thompson almost 11 years ago Actions #5

  • Assignee set to Matthew Smith

JT Updated by Jim Thompson over 10 years ago Actions #6

  • Assignee changed from Matthew Smith to Marc Dye

JT Updated by Jim Thompson over 10 years ago Actions #7

  • Status changed from New to Assigned

MS Updated by Matthew Smith over 10 years ago Actions #8

  • Target version changed from 2.3 to Future

The backend code that exists in /etc/inc/ipsec.auth-user.php is not actually something that can be used. It looks like that code is very closely modeled after code in the openvpn.auth-user.php script. OpenVPN passes the common name in as an environment variable when it calls an auth script. Strongswan doesn't do this so the code won't work.

RB Updated by Renato Botelho over 9 years ago Actions #9

  • Assignee deleted (Marc Dye)
Actions

Also available in: Atom