Subject: racoon and psk.txt
To: None <tech-net@netbsd.org>
From: Jan Schaumann <jschauma@netmeister.org>
List: tech-net
Date: 01/07/2003 18:02:16
Hi,

Is it just me or did racoon break recently?
I rebuilt -current yesterday, and after the reboot it does not seem to
read the psk.txt file any more:

# grep psk /etc/racoon/racoon.conf
path pre_shared_key "/etc/racoon/psk.txt" ;
# ls -la /etc/racoon/psk.txt
-rw-------  1 root  wheel  3464 Jan  7 17:54 /etc/racoon/psk.txt
# ls -lu /etc/racoon/*  
-rw-------  1 root  wheel  3464 Jan  7 17:55 /etc/racoon/psk.txt
-rw-r--r--  1 root  wheel  2061 Jan  7 17:56 /etc/racoon/racoon.conf
# date
Tue Jan  7 17:57:40 EST 2003
# /etc/rc.d/racoon restart
starting local daemons:.
starting local daemons:.
racoon not running? (check /var/run/racoon.pid).
starting local daemons:.
Starting racoon.
# ls -lu /etc/racoon/*
-rw-------  1 root  wheel  3464 Jan  7 17:55 /etc/racoon/psk.txt
-rw-r--r--  1 root  wheel  2061 Jan  7 17:57 /etc/racoon/racoon.conf
# 

Now without the PSKs, of course ipsec is not working properly:
racoon: ERROR: isakmp.c:490: can't start the quick mode, there is no ISAKMP-SA
/netbsd: IPv4 ESP input: no key association found for spi

Anybody with a clue?

-Jan

-- 
"Life," said Marvin, "don't talk to me about life."