description.txt 489 B

1234567
  1. This scenario is based on <a href="../ocsp-signer-cert">ikev2/ocsp-signer-cert</a>
  2. and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fetching
  3. by adding an ocspuri1 in <b>moon</b>'s strongswan ca section on which no OCSP
  4. server is listening and an ocspuri2 that cannot be resolved by <b>DNS</b>.
  5. Since the certificate status is <b>unknown</b> the connection setup is aborted by
  6. <b>moon</b> with an <b>AUTHORIZATION_FAILED</b> notification sent to <b>carol</b>.