When using old (<3.0.20) GnuTLS, try looking in some other places for the system CA file. Don't just assume the Fedora location. Also try harder to find PKCS#11 keys if the token doesn't admit to their existence before login, but it *does* admit to the existence of the corresponding certificate. ftp://ftp.infradead.org/pub/openconnect/openconnect-4.06.tar.gz ftp://ftp.infradead.org/pub/openconnect/openconnect-4.06.tar.gz.asc David Woodhouse (4): Handle PKCS#11 tokens which don't list keys before login Improve error reporting for vpnc-script Fix strict-aliasing warning with DTLS local port handling Tag version 4.06 Mike Miller (1): Check for system CA certificate file for GnuTLS -- dwmw2 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 6171 bytes Desc: not available URL: <http://lists.infradead.org/pipermail/openconnect-devel/attachments/20120723/e0f81ed0/attachment.bin>