Project

General

Profile

Bug #4794

Handling of ASN1.DN values for RSA IPsec during upgrades from previous versions

Added by Jorge Albarenque about 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Normal
Category:
Upgrade
Target version:
Start date:
06/27/2015
Due date:
% Done:

100%

Estimated time:
Affected Version:
2.2.x
Affected Architecture:

Description

The certificate CNs are interpreted differently by raccoon and strongSwan, for example:

raccoon:
C=US, ST=Whatever, L=Springfield, O=Springfield Power Plant/emailAddress=, CN=springfield.powerplant.com

strongSwan:
"C=US, ST=Whatever, L=Springfield, O=Springfield Power Plant, E=, CN=springfield.powerplant.com"

So on upgrades from v2.1.x and before, some regex needs to be done on the ASN1DN field.

Also, the value needs to be surrounded in quotes, but be careful because if the identity prefix is provided, the prefix must be included within the quotes, eg: rightid = "asn1dn:#whateverhexvalue..."
This will depend on how the identity type prefixes are handled (related to bug 4792 )

Associated revisions

Revision e4b7410b (diff)
Added by Renato Botelho about 4 years ago

Fix #4794:

- Add a upgrade code to fix asn1dn string format to match strongSwan needs
- Bump config version to 11.8

Revision faaab088 (diff)
Added by Renato Botelho about 4 years ago

Fix #4794:

- Add a upgrade code to fix asn1dn string format to match strongSwan needs
- Bump config version to 11.8

History

#1 Updated by Tobias Brunner about 4 years ago

As I've recently explained on an Ubuntu bug report related to pfSense just adding identity type prefixes is not correct and will most likely not result in the intended result.

#2 Updated by Jim Thompson about 4 years ago

  • Assignee set to Renato Botelho

#3 Updated by Chris Buechler about 4 years ago

  • Status changed from New to Confirmed

Should be fine to s/\/emailAddress/, E/ on asn1dn when doing config upgrade from 2.1.5

#4 Updated by Renato Botelho about 4 years ago

  • Status changed from Confirmed to Feedback
  • % Done changed from 0 to 100

#6 Updated by Chris Buechler about 4 years ago

  • Status changed from Feedback to Resolved

works

Also available in: Atom PDF