Discussion:
Followup: ikev2 fails with iOS after 3/23/2017 diff - any ideas?
Theodore Wynnychenko
2017-07-05 15:29:54 UTC
Permalink
Hello

I hope that I am not being too annoying, but I don't have the knowledge or skill
to explore this issue on my own.

I originally sent a message to misc@ and then bugs@ in early June.

In summary, after the "Add support for RFC4754 (ECDSA) and RFC7427
authentication" diff was committed (on 3/27/2017, I believe) I am unable to
establish an ikev2 VPN from an iOS device. Those connections fail with:

ikev2_ike_auth_recv: unexpected auth method RSA_SIG, was expecting SIG
ikev2_resp_recv: failed to send auth response

My initial, more detailed explanation is at
https://marc.info/?l=openbsd-bugs&m=149706080419488&w=2.

I have updated current twice since then, but the iked problem with iOS persists.
For now, reverting to the "2017/03/23 05:29:48" patchset 394 allows iOS to work
with OBSD.

I would be happy to help with this if can. Please let me know if I can help in
any way.

Thanks once again.
Ted

Loading...