isakmpd with x509 certificates and sub ca?


I would like to know if anyone here ever succeded to connect the
native Win2k IPsec client with an OpenBSD's IPsec gateway
using isakmpd.
IKE Authentication via Passphrase or X509v3 certificates work 
both fine.

But if we try to use a certification chain, which means
we have a Root certification authority, which signs a Subordinate
certification authority, which signes the client and gateway
certificates, the authentication fails.

Something like INVALID_ID_INFORMATION ... 
(I could provide more logs, if someon is interested in it)

Something like this:

Any hints or help would be really appreciated.

thanks in advance

