Subject: racoon and psk.txt
To: None <tech-net@netbsd.org>
From: Jan Schaumann <jschauma@netmeister.org>
List: tech-net
Date: 01/07/2003 18:02:16
Hi,
Is it just me or did racoon break recently?
I rebuilt -current yesterday, and after the reboot it does not seem to
read the psk.txt file any more:
# grep psk /etc/racoon/racoon.conf
path pre_shared_key "/etc/racoon/psk.txt" ;
# ls -la /etc/racoon/psk.txt
-rw------- 1 root wheel 3464 Jan 7 17:54 /etc/racoon/psk.txt
# ls -lu /etc/racoon/*
-rw------- 1 root wheel 3464 Jan 7 17:55 /etc/racoon/psk.txt
-rw-r--r-- 1 root wheel 2061 Jan 7 17:56 /etc/racoon/racoon.conf
# date
Tue Jan 7 17:57:40 EST 2003
# /etc/rc.d/racoon restart
starting local daemons:.
starting local daemons:.
racoon not running? (check /var/run/racoon.pid).
starting local daemons:.
Starting racoon.
# ls -lu /etc/racoon/*
-rw------- 1 root wheel 3464 Jan 7 17:55 /etc/racoon/psk.txt
-rw-r--r-- 1 root wheel 2061 Jan 7 17:57 /etc/racoon/racoon.conf
#
Now without the PSKs, of course ipsec is not working properly:
racoon: ERROR: isakmp.c:490: can't start the quick mode, there is no ISAKMP-SA
/netbsd: IPv4 ESP input: no key association found for spi
Anybody with a clue?
-Jan
--
"Life," said Marvin, "don't talk to me about life."