Your problem is that this is not a CA certificate, it's the servers certificate.
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Sep 9 2021
Sep 8 2021
Can you share your CAs public cert for testing?
A new ISO 1.4-rolling-202109081242 is currently build - you may check in 30 minutes and try if this works for you - it did in my example config.
That would only work if accept_local will be added as proper CLI node on the tunnel interface, or use set system sysctl parameter net.ipv4.conf.default.accept_local value '1'
Sep 7 2021
@absolutesantaja this is definately a bug in the 1.2.9 op-mode commands
Can you please share a version of your anonymized client configuration?
Same happens to other op-mode commands:
please refer to the PKI documentation at https://docs.vyos.io/en/latest/configuration/pki/index.html or https://blog.vyos.io/pki-and-ipsec-ikev2-remote-access-vpn about how the PKI feature is used.
I tested it on ESXi
Sep 6 2021
Works as designed. Note that the MACSec interface will only change its state to u/u after a successful key-exchange.
Does it work if you grand the capabilities to the openvpn group in /etc/security/capability.conf?