Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Cannot use installed certificate for IPSec VPN connection

I've been issued with a certificate for a VPN connection to a SecureSwan server, which should in principle work with the native iOS VPN client.


I have successfully installed this certificate on my iPhone via two different routes: either as a configuration profile through my Mac, as well as by emailing it to myself as an attachment (after using OpenSSL to convert the plain-text .pem file to a binary .der one). Both, as expected create entries under Profiles on my iPhone - one being a profile containing the certificate, the other being the "bare" certificate. All the details come up fine. (N.B. Additionally, the certificate installed with the profile is marked as "Trusted", since this is carried over from the Keychain.app on my Mac).


However, once I create the IPSec VPN connection I appear unable to use the certificate with it. I tick "Use Certificate" in the configuration options and when I go into the "Certificate" menu, the certificate does not appear there. The only option I am given is the iPhone Configurator Signature certificate, which is obviously not what I want.


Therefore my question: What do I need to do in order to use this certificate with the iOS VPN client? What are the VPN client's requirements with respect to a certificate?


Also, from what I can tell the certificate I have been issued matches the requirements laid out in https://wiki.strongswan.org/projects/strongswan/wiki/IOS_(Apple), though that may be irrelevant since I can't even get to the point of asking iOS to use it.


I've not been able to find any details on this via a fair bit of googling. I hope I'm posting in roughly the right place. Any light anyone can shed on this would be appreciated!

Svet

iPhone 5s, iOS 8.2

Posted on Mar 29, 2015 2:39 AM

Reply
1 reply

Cannot use installed certificate for IPSec VPN connection

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.