Markus P. Beckhaus
2018-06-13 09:49:29 UTC
Hi,
I am trying to use ipsec_scepclient against a 2-tiered AD CS with ECDSA setup but this fails with the following error message:
EC public key encryption not implemented
encrypting symmetric key failed
Obviosly this tells me exactly, why it isnât working, but on the other side we have strongswan running VPN tunnels on the same box with ECDSA certificates from abovementioned CA, so basically ECDSA modules are present and loaded.
So I am asking myself, if the scepclient does not utilize the same module architecture as the charon deamon.
My question is, if scepclient definitely does not support EC or if I can tweak my configuration in any way to add EC support to scepclient.
Best Regards
Markus
I am trying to use ipsec_scepclient against a 2-tiered AD CS with ECDSA setup but this fails with the following error message:
EC public key encryption not implemented
encrypting symmetric key failed
Obviosly this tells me exactly, why it isnât working, but on the other side we have strongswan running VPN tunnels on the same box with ECDSA certificates from abovementioned CA, so basically ECDSA modules are present and loaded.
So I am asking myself, if the scepclient does not utilize the same module architecture as the charon deamon.
My question is, if scepclient definitely does not support EC or if I can tweak my configuration in any way to add EC support to scepclient.
Best Regards
Markus