This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

PKI Errror.

Hi guys,

I'm getting this error :

2009-07-07 11:20:09  IPSec: Start building connection
2009-07-07 11:20:09  Ike: phase1:name(REF_JfcNUgbean) - outgoing connect request - main mode.
2009-07-07 11:20:09  Ike: XMIT_MSG1_MAIN - REF_JfcNUgbean
2009-07-07 11:20:09  Ike: RECV_MSG2_MAIN - REF_JfcNUgbean
2009-07-07 11:20:09  Ike: IKE phase I: Setting LifeTime to 7800 seconds
2009-07-07 11:20:09  Ike: Turning on XAUTH mode - REF_JfcNUgbean
2009-07-07 11:20:09  IPSec: Final Tunnel EndPoint is:024.122.020.089
2009-07-07 11:20:09  Ike: IkeSa negotiated with the following properties -
2009-07-07 11:20:09    Authentication=XAUTH_INIT_RSA,Encryption=AES,Hash=MD5,DHGroup=5,KeyLen=256
2009-07-07 11:20:09  Ike: REF_JfcNUgbean ->Support for NAT-T version - 9
2009-07-07 11:20:09  Ike: XMIT_MSG3_MAIN - REF_JfcNUgbean
2009-07-07 11:20:09  Ike: RECV_MSG4_MAIN - REF_JfcNUgbean
2009-07-07 11:20:09  Ike: Turning on NATD mode - REF_JfcNUgbean - 1
2009-07-07 11:20:09  ERROR - 4036: IKE(phase1)- PKI ERROR: -  Client Error: No User Certificate loaded .
2009-07-07 11:20:09  Ike: phase1:name(REF_JfcNUgbean) - error - PKI ERROR: -  Client Error: No User Certificate loaded .
2009-07-07 11:20:09  IPSec: Disconnected from REF_JfcNUgbean on channel 1.


Any idea?

Thanks
Nicolas


This thread was automatically locked due to age.
  • I think I got this error once when my cert was inconsistent with my hostname.  I'd changed the hostname of the Astaro and generated a new signing CA.  I don't remember if it was my personal cert or the Local X509 Cert that was out of phase with everything else.

    Cheers - Bob