The CA commands below create a short-lived test CA. Use your organization’s CA for production certificates. The responder certificate must contain the public key that matches the CryptoHub-resident private key.
Create the responder key
The output lists a private key with
Usage: sign and a public key with Usage: verify. Both objects must have the same ID.Export the public object
Run
sudo openssl pkey -pubin -inform DER -in /root/strongswan-certs/responder-public.der -noout. The command must succeed.Issue the certificates
Both verification commands report
certificate trusted, lifetimes valid.initiator-key.pem, initiator-cert.pem, and ca-cert.pem to the initiator over an encrypted channel.
