From b0d8ed94fe9e74afb49fdf5f11e4add29879c65c Mon Sep 17 00:00:00 2001 From: Rene Mayrhofer Date: Thu, 12 Apr 2007 20:30:08 +0000 Subject: [svn-upgrade] Integrating new upstream version, strongswan (4.1.1) --- testing/tests/ikev2/ocsp-revoked/description.txt | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 testing/tests/ikev2/ocsp-revoked/description.txt (limited to 'testing/tests/ikev2/ocsp-revoked/description.txt') diff --git a/testing/tests/ikev2/ocsp-revoked/description.txt b/testing/tests/ikev2/ocsp-revoked/description.txt new file mode 100644 index 000000000..73d072549 --- /dev/null +++ b/testing/tests/ikev2/ocsp-revoked/description.txt @@ -0,0 +1,9 @@ +By setting strictcrlpolicy=yes, a strict CRL policy is enforced on +both roadwarrior carol and gateway moon. The online certificate status +is checked via the OCSP server winnetou which possesses an OCSP signer certificate +issued by the strongSwan CA. This certificate contains an OCSPSigning +extended key usage flag. A strongswan ca section in ipsec.conf defines an +OCSP URI pointing to winnetou. +

+carol tries to initiate an IPsec connection to moon but fails +because carol's certificate has been revoked. -- cgit v1.2.3