Why does it matter if you have any other configs? Because charon tries to reload secrets after dropping privs. If it fails, it still works. If it succeeds in reading *some* secrets though (like if you make your secrets file owned by ipsec), then it drops the NM secrets.
-
-
Show this thread
-
The fix is chown root:root /etc/ipsec.secrets; chmod 600 /etc/ipsec.secrets and just let charon keep failing at re-reading *all* secrets, not just NetworkManager's, so it doesn't drop those keys on the floor. I'm sure this breaks some other use case though ¯\_(ツ)_/¯
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.