Cert based IPsec initialization fails with AUTHENTICATION_FAILED
Applies to
- ONTAP 9
- IPSec
- Libreswan
- Strongswan
Issue
- When attempting to initialize IPsec, an
AUTHENTICATION_FAILED
is seen on the initiators side. - The following is seen on the responder's side:
18[CFG] no issuer certificate found for "CN=rhelhost1, C=US, ST=California, O=AMER-NAS"
18[CFG] issuer is "C=US, ST=California, L=Wichita, O=NeatApp, CN=wronghost.hendricm.com"
18[IKE] no trusted RSA public key found for 'CN=rhelhost1, C=US, ST=California, O=AMER-NAS' in vserver 5