description.txt 365 B

12345
  1. By setting <b>strictcrlpolicy=yes</b> a <b>strict CRL policy</b> is enforced on
  2. both roadwarrior <b>carol</b> and gateway <b>moon</b>. When <b>carol</b> initiates
  3. an IPsec connection to <b>moon</b>, both VPN endpoints find a cached CRL in
  4. their <b>/etc/ipsec.d/crls/</b> directories which allows them to immediately verify
  5. the certificate received from their peer.