description.txt 407 B

123456
  1. By setting <b>cachecrls=yes</b> in ipsec.conf, a copy of the CRL fetched
  2. via http from the web server <b>winnetou</b> is saved locally in the
  3. directory <b>/etc/ipsec.d/crls</b> on both the roadwarrior <b>carol</b>
  4. and the gateway <b>moon</b> when the IPsec connection is set up. The
  5. <b>subjectKeyIdentifier</b> of the issuing CA plus the suffix <b>.crl</b>
  6. is used as a unique filename for the cached CRL.