android: Always send the client certificate

In scenarios where the server accepts client certificates from dozens or
even hundreds of CAs it might be necessary to omit certificate request
payloads from the IKE_SA_INIT response to avoid fragmentation.

As it is rarely the case in road-warrior scenarios that the server
already has the client certificate installed it should not be a problem
to always send it.
This commit is contained in:
Tobias Brunner
2018-02-08 12:15:36 +01:00
parent c7263577b3
commit 6bafa2d346
@@ -739,7 +739,7 @@ static job_requeue_t initiate(private_android_service_t *this)
ike_sa_t *ike_sa;
auth_cfg_t *auth;
peer_cfg_create_t peer = {
.cert_policy = CERT_SEND_IF_ASKED,
.cert_policy = CERT_ALWAYS_SEND,
.unique = UNIQUE_REPLACE,
.rekey_time = 36000, /* 10h */
.jitter_time = 600, /* 10min */