Re: iked(8): support for intermediate CAs and multiple CERT payloads

2022-05-19 Thread Loïc Revest
()Hello Stuart, Thanks for giving it also a try - I was the one bothering Tobias earlier today with this use case of a Windows 10 (21H2) client trying to connect to an iked server whose CA certificate wasn't self-signed, but signed by a root CA. > For Windows this works provided that ISRG Root X1

Re: iked(8): support for intermediate CAs and multiple CERT payloads

2022-05-19 Thread Stuart Henderson
> > I haven't tested Windows yet, I'll try to locate a machine to test with > > at the weekend. > > > > The certificate arrangement is a little awkward to work with typical > > ACME infrastructure used with standard TLS servers: > > > > For a standard server the root certificate would not normall

Re: iked(8): support for intermediate CAs and multiple CERT payloads

2022-05-19 Thread Tobias Heider
On Fri, May 14, 2021 at 09:23:02PM +0100, Stuart Henderson wrote: > On 2021/05/14 21:14, Tobias Heider wrote: > > On Thu, May 13, 2021 at 02:39:37PM +0900, Katsuhiro Ueno wrote: > > > Hi, > > > > > > I would be happy if iked(8) supports intermediate CAs and sends the > > > entire certificate chain

hidmt: default to clickpad unless report says otherwise

2022-05-19 Thread joshua stein
Most Windows Precision Touchpad-style touchpads will be clickpads, with no-button "pressure pad" style devices being the outlier. Make clickpad the default unless the report says otherwise. This fixes the Framework laptop which has a PixArt touchpad with a weird HID descriptor report which put