Project

General

Profile

Actions

Bug #4825

closed

Mobile client IPsec config omits peer identifier

Added by Moritz Bechler over 9 years ago. Updated almost 8 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
IPsec
Target version:
Start date:
07/10/2015
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.2.x
Affected Architecture:

Description

The strongswan connection config generated for a mobile client association does not include the configured peer identifier (pattern). Therefor when using certificate authentication all certificates issued by the configured CA will be accepted instead of only the certificates matching the pattern.

Marking private as this might have severe security implications in some setups.

Actions

Also available in: Atom PDF