If the NM gateway certificate has the CA constraint set, we use the gateway address...
authorMartin Willi <martin@strongswan.org>
Fri, 15 May 2009 14:35:14 +0000 (16:35 +0200)
committerMartin Willi <martin@strongswan.org>
Fri, 15 May 2009 14:35:14 +0000 (16:35 +0200)
commit0ed6b7a7d73d8e1b9a7f83bd16b9bd6688130d86
treee6ddd3eaee410c80db379beb97c035d7a9f1cfe2
parentd4b403e2f31587a012a2b7b3f93dc45ddfbe4846
If the NM gateway certificate has the CA constraint set, we use the gateway address as its identity.

To allow the same certificate deployment for Windows 7 and NetworkManager clients,
the NM plugin now accepts CA certificates. To prevent any certificate holder
to act as a gateway, we bind the identity to the entered gateway address. The
gateways certificate therefore must contain the IP/DNS of the gateway
as subjectAltName.
src/charon/plugins/nm/gnome/properties/nm-strongswan-dialog.glade
src/charon/plugins/nm/nm_service.c