Can you please share your entire config and what to type to reproduce it? Happy to have a look later on.
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Sep 10 2021
Can you please retrst with the latest 1.4? the was a bug related to route-maps in bgpd
Setting this to resolved as implementation is almost complete. Please file individual tasks for bugs so we can properly track them in the 1.3 release cycle.
Sep 9 2021
Will be fixed in tomorrows rolling - thanks for reporting this.
cpo@LR1.wue3:~$ generate pki wireguard key-pair file test Private key: QG039BeDoy2MXKxQwFRhYYea7B50crYvZ1RUn+N0c3A= Public key: iXVG4GSHc0O7NHgX47DhhNO/WWSTZS83/eF2z4GHYSE= File written to /config/auth/test_public.key File written to /config/auth/test_private.key
Your problem is that this is not a CA certificate, it's the servers certificate.
Sep 8 2021
Can you share your CAs public cert for testing?
A new ISO 1.4-rolling-202109081242 is currently build - you may check in 30 minutes and try if this works for you - it did in my example config.
That would only work if accept_local will be added as proper CLI node on the tunnel interface, or use set system sysctl parameter net.ipv4.conf.default.accept_local value '1'
Sep 7 2021
@absolutesantaja this is definately a bug in the 1.2.9 op-mode commands
Can you please share a version of your anonymized client configuration?
Same happens to other op-mode commands:
please refer to the PKI documentation at https://docs.vyos.io/en/latest/configuration/pki/index.html or https://blog.vyos.io/pki-and-ipsec-ikev2-remote-access-vpn about how the PKI feature is used.
I tested it on ESXi
Sep 6 2021
Works as designed. Note that the MACSec interface will only change its state to u/u after a successful key-exchange.
Does it work if you grand the capabilities to the openvpn group in /etc/security/capability.conf?