From 774a362e87feab25f1be16fbca08269ddc7121a4 Mon Sep 17 00:00:00 2001 From: Rene Mayrhofer Date: Thu, 12 Apr 2007 20:41:31 +0000 Subject: Major new upstream release, just ran svn-upgrade for now (and wrote some debian/changelong entries). --- testing/tests/ikev1/multi-level-ca-ldap/description.txt | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 testing/tests/ikev1/multi-level-ca-ldap/description.txt (limited to 'testing/tests/ikev1/multi-level-ca-ldap/description.txt') diff --git a/testing/tests/ikev1/multi-level-ca-ldap/description.txt b/testing/tests/ikev1/multi-level-ca-ldap/description.txt new file mode 100644 index 000000000..18fb88840 --- /dev/null +++ b/testing/tests/ikev1/multi-level-ca-ldap/description.txt @@ -0,0 +1,11 @@ +The VPN gateway moon controls the access to the hosts alice and +venus by means of two different Intermediate CAs. Access to +alice is granted to users presenting a certificate issued by the Research CA +whereas venus can only be reached with a certificate issued by the +Sales CA. The roadwarriors carol and dave have certificates from +the Research CA and Sales CA, respectively. Therefore carol can access +alice and dave can reach venus. +

+By setting strictcrlpolicy=yes the CRLs from the strongSwan, Research and +Sales CAs must be fetched from the LDAP server winnetou first, before the +connection setups can be successfully completed. -- cgit v1.2.3