Re: [Fed-Talk] OS X, L2TP/IPsec, and Cisco VPN3000s
Re: [Fed-Talk] OS X, L2TP/IPsec, and Cisco VPN3000s
- Subject: Re: [Fed-Talk] OS X, L2TP/IPsec, and Cisco VPN3000s
- From: Mark D Miller <email@hidden>
- Date: Thu, 02 Feb 2006 16:37:45 -0500
- Thread-topic: [Fed-Talk] OS X, L2TP/IPsec, and Cisco VPN3000s
But only if you have a service account!
> From: <email@hidden>
> Reply-To: <email@hidden>
> Date: Thu, 2 Feb 2006 12:03:18 -0800 (PST)
> To: <email@hidden>
> Subject: Fed-talk Digest, Vol 3, Issue 27
>
> Date: Thu, 2 Feb 2006 10:25:25 -0500
> From: Joel Esler <email@hidden>
> Subject: Re: [Fed-Talk] OS X, L2TP/IPsec, and Cisco VPN3000s
> To: Timothy J Miller <email@hidden>
> Cc: Fedtalk List <email@hidden>
> Message-ID: <email@hidden>
> Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
>
> I use the Cisco VPN Client for OSX. It's downloadable via Cisco's
> website.
>
> Joel
>
>
> On Feb 1, 2006, at 9:23 AM, Timothy J Miller wrote:
>
>> Has anyone had any success getting OS X 10.4.x L2TP/IPsec to
>> negotiate an SA with a Cisco VPN3000 concentrator with certificate
>> authenticated IPsec? I've gotten to the point where main mode is
>> complete (as far as the concentrator is concerned), but OS X
>> terminates the nascent SA because (it says) the certificate
>> identity is invalid.
>>
>> As far as I can tell, the only IPsec certificate profile
>> requirements OS X is supposed to have to IPsec peer certificates is
>> the FQDN in the subjectAlternativeName. Which I have. But for the
>> life of me I can't get it to work.
>>
>> Pointers?
>>
>> -- Tim _______________________________________________
>> Do not post admin requests to the list. They will be ignored.
>> Fed-talk mailing list (email@hidden)
>> Help/Unsubscribe/Update your Subscription:
>>
>> This email sent to email@hidden
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden