<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Configuring an IPsec tunnel between Openswan and Windows 2000/XP with x509</title>
	<atom:link href="http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/</link>
	<description>All geek, most of the time</description>
	<lastBuildDate>Wed, 08 Feb 2012 15:03:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Simon Tang</title>
		<link>http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/comment-page-1/#comment-312396</link>
		<dc:creator>Simon Tang</dc:creator>
		<pubDate>Wed, 11 May 2011 01:53:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.natecarlson.com/?p=303#comment-312396</guid>
		<description>Hi,I encountered a problem using your method. the following is the problem:
when I use the the following command: openssl pkcs12 -export -in winhost.example.com.pem -inkey winhost.example.com.key -certfile demoCA/cacert.pem -out winhost.example.com.p12, it said unable to load private key.
How can I solve the problem? Please help me, Thank you very much!</description>
		<content:encoded><![CDATA[<p>Hi,I encountered a problem using your method. the following is the problem:<br />
when I use the the following command: openssl pkcs12 -export -in winhost.example.com.pem -inkey winhost.example.com.key -certfile demoCA/cacert.pem -out winhost.example.com.p12, it said unable to load private key.<br />
How can I solve the problem? Please help me, Thank you very much!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ocii</title>
		<link>http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/comment-page-1/#comment-312222</link>
		<dc:creator>ocii</dc:creator>
		<pubDate>Thu, 09 Dec 2010 13:59:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.natecarlson.com/?p=303#comment-312222</guid>
		<description>Hi, i had the same error

what i did wrong: 

i renamed newreq.pem to host.example.com.key

but when i renamed newkey.pem to host.example.com.key

everything works fine

thx for this great tutorial</description>
		<content:encoded><![CDATA[<p>Hi, i had the same error</p>
<p>what i did wrong: </p>
<p>i renamed newreq.pem to host.example.com.key</p>
<p>but when i renamed newkey.pem to host.example.com.key</p>
<p>everything works fine</p>
<p>thx for this great tutorial</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chap</title>
		<link>http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/comment-page-1/#comment-312175</link>
		<dc:creator>Chap</dc:creator>
		<pubDate>Fri, 22 Oct 2010 11:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.natecarlson.com/?p=303#comment-312175</guid>
		<description>Hi, i got the same Error as Gab. What can I do?</description>
		<content:encoded><![CDATA[<p>Hi, i got the same Error as Gab. What can I do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gab</title>
		<link>http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/comment-page-1/#comment-312105</link>
		<dc:creator>Gab</dc:creator>
		<pubDate>Tue, 31 Aug 2010 23:00:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.natecarlson.com/?p=303#comment-312105</guid>
		<description>I&#039;ve followed all steps and something is wrong with:

openssl pkcs12 -export -in winhost.example.com.pem -inkey winhost.example.com.key -certfile 

I got the message: &quot; unable to load private key &quot;

seems that I have to use the file : demoCA/private/cakey.pem ?

Thanks in advanced
gab</description>
		<content:encoded><![CDATA[<p>I&#8217;ve followed all steps and something is wrong with:</p>
<p>openssl pkcs12 -export -in winhost.example.com.pem -inkey winhost.example.com.key -certfile </p>
<p>I got the message: &#8221; unable to load private key &#8221;</p>
<p>seems that I have to use the file : demoCA/private/cakey.pem ?</p>
<p>Thanks in advanced<br />
gab</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sean</title>
		<link>http://www.natecarlson.com/2007/07/30/configuring-an-ipsec-tunnel-between-openswan-and-windows-2000-xp/comment-page-1/#comment-312066</link>
		<dc:creator>sean</dc:creator>
		<pubDate>Fri, 20 Aug 2010 09:00:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.natecarlson.com/?p=303#comment-312066</guid>
		<description>just an aside, while doing this, i kept hitting this error during the last part of Step 4 under &quot;setting up your certificate authority&quot;
# openssl ca -gencrl -out crl.pem
Using configuration from /usr/lib/ssl/openssl.cnf
Enter pass phrase for ./demoCA/private/cakey.pem:
./demoCA/crlnumber: No such file or directory
error while loading CRL number
11493:error:02001002:system library:fopen:No such file or directory:bss_file.c:352:fopen(&#039;./demoCA/crlnumber&#039;,&#039;r&#039;)
11493:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:354:

googling it i found this

https://lists.strongswan.org/pipermail/users/2006-February/001286.html

I have had the same problem today. I resolved it by commenting out the following line in my /etc/ssl/openssl.cnf:
	crlnumber  = $dir/crlnumber  # the current crl number
The line is followed by a comment, that makes me think this is okay:
	# must be commented out to leave a V1 CRL


which worked for me too.  just FYI for anybody else following this guide.</description>
		<content:encoded><![CDATA[<p>just an aside, while doing this, i kept hitting this error during the last part of Step 4 under &#8220;setting up your certificate authority&#8221;<br />
# openssl ca -gencrl -out crl.pem<br />
Using configuration from /usr/lib/ssl/openssl.cnf<br />
Enter pass phrase for ./demoCA/private/cakey.pem:<br />
./demoCA/crlnumber: No such file or directory<br />
error while loading CRL number<br />
11493:error:02001002:system library:fopen:No such file or directory:bss_file.c:352:fopen(&#8216;./demoCA/crlnumber&#8217;,'r&#8217;)<br />
11493:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:354:</p>
<p>googling it i found this</p>
<p><a href="https://lists.strongswan.org/pipermail/users/2006-February/001286.html" rel="nofollow">https://lists.strongswan.org/pipermail/users/2006-February/001286.html</a></p>
<p>I have had the same problem today. I resolved it by commenting out the following line in my /etc/ssl/openssl.cnf:<br />
	crlnumber  = $dir/crlnumber  # the current crl number<br />
The line is followed by a comment, that makes me think this is okay:<br />
	# must be commented out to leave a V1 CRL</p>
<p>which worked for me too.  just FYI for anybody else following this guide.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

