By setting cachecrls=yes in ipsec.conf, a copy of the CRL fetched
via http from the web server winnetou is saved locally in the
directory /etc/ipsec.d/crls on both the roadwarrior carol
and the gateway moon when the IPsec connection is set up. The
subjectKeyIdentifier of the issuing CA plus the suffix .crl
is used as a unique filename for the cached CRL.