From 123fdf700a03825946dd227d43935cad49e01da6 Mon Sep 17 00:00:00 2001 From: Andreas Steffen Date: Sat, 6 Jun 2009 16:23:42 +0200 Subject: updated documentation on leftsendcert --- README | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'README') diff --git a/README b/README index 8e82e59f8..101e4838c 100644 --- a/README +++ b/README @@ -1505,12 +1505,16 @@ any certificates to the other end via the IKE Main Mode protocol. Especially if self-signed certificates are used which wouldn't be accepted any way by the other side. In these cases it is recommended to add - leftsendcert=never + leftsendcert=never to the connection definition[s] in order to avoid the sending of the host's own certificate. The default value is - leftsendcert=always. + leftsendcert=ifasked + +If a peer does not send a certificate request then use the setting + + leftsendcert=always If a peer certificate contains a subjectAltName extension, then an alternative rightid type can be used, as the example "conn sun" shows. If no rightid -- cgit v1.2.3