1
mirror of https://git.dn42.dev/wiki/wiki.git synced 2025-03-13 09:04:27 +01:00

Updated RacoonExample (markdown)

This commit is contained in:
dn42 wiki 2015-02-22 10:32:13 +00:00
parent 7c0e727303
commit d30842f07e
2 changed files with 36 additions and 3 deletions

View File

@ -1 +1 @@
[![dn42](/dn42.png)](/)
[![dn42](/dn42.png)](/)

View File

@ -1,2 +1,35 @@
# IPsec with public key authentication on Racoon
## Coming soon
The keys are generated with plainrsa-gen.
```
Usage: plainrsa-gen [options]
-b bits Generate <bits> long RSA key (default=1024)
-e pubexp Public exponent to use (default=0x3)
-f filename Filename to store the key to (default=stdout)
-i filename Input source for format conversion
-h Help
```
I'd probably go with 4096 bits.
in your racoon.conf:
```
path certificate "/etc/racoon/keys";
listen {
isakmp 192.168.255.1[500];
}
remote 192.168.255.2 {
exchange_mode main;
certificate_type plain_rsa "local.priv.key";
peers_certfile plain_rsa "remote.pub.key";
proposal {
authentication_method rsasig;
lifetime time 8 hour;
encryption_algorithm aes256;
hash_algorithm sha256;
dh_group modp1024;
}
}
```