Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Using ACME acquired certificate 05[IKE] <con-mobile|7> no private key found for "***************"

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 364 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lolipoplo
      last edited by lolipoplo

      Hello,

      I have certificate aquired via ACME package. I encounter the issue with "no private key found for"
      I see the ipsec config has leftcert=/var/etc/ipsec/ipsec.d/certs/cert-1.crt
      which is identical to a .cer file in /tmp/acme/<cert name>/<fqdn>/

      the certificate uses pubkey: ECDSA 384 bits
      not sure if this is a problem

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It is probably due to it being ECDSA. There are several areas that don't properly support ECDSA certs on 2.4.x, but should work on 2.5.0.

        ACME certs do work in general for mobile IPsec, I have setup and tested that before.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        L 1 Reply Last reply Reply Quote 0
        • L
          lolipoplo @jimp
          last edited by

          @jimp I verified it. I change it to a RSA 2048 cert, it successfully loaded cert and I can establish conn

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.