From 7c52c3f35cdbdff58443b994f2f33d13b4d81f57 Mon Sep 17 00:00:00 2001 From: Rene Mayrhofer Date: Tue, 23 Jun 2009 11:35:38 +0000 Subject: Updated to new upstream version. --- testing/tests/ikev2/two-certs/description.txt | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) (limited to 'testing/tests/ikev2/two-certs/description.txt') diff --git a/testing/tests/ikev2/two-certs/description.txt b/testing/tests/ikev2/two-certs/description.txt index 46ca8fec1..94ffaa487 100644 --- a/testing/tests/ikev2/two-certs/description.txt +++ b/testing/tests/ikev2/two-certs/description.txt @@ -1,6 +1,7 @@ -The roadwarriors carol and dave set up a connection each -to gateway moon. The authentication is based on X.509 certificates. -Gateway moon has already loaded a revoked certificate for carol -and a self-signed certificate for dave locally but gets actual certificates -as CERT payloads from both peers. The RSA signature verification process tries all -candidate peer certificates until it finds a valid one with a matching public key. +The roadwarrior carol possesses two different X.509 certificates plus +matching RSA private keys. With the first certificate carol authenticates +a tunnel connection to gateway moon in order to reach client alice +and presents the second certificate in order to reach client venus using +the identity carol@strongswan.org for both IKE security associations. +Therefore the RSA signature verification process on moon tries all +candidate peer certificates until it finds the correct RSA public key. -- cgit v1.2.3