[strongSwan] [strongSwan IKEv2] Issue in CA certificate updates

Sajal Malhotra sajalmalhotra at gmail.com
Thu Jun 3 14:07:45 CEST 2010

Hi Martin,

Thanks for the clarification. If not possible to trigger the flush
externally, then when does that stack flush these certificates

On Thu, Jun 3, 2010 at 1:58 PM, Martin Willi <martin at strongswan.org> wrote:

> Hi,
> > This is incorrect as the Certificate of peer is signed by previous CA
> > certificate, which has been deleted in step 4 above.
> The certificate is probably still in the cache, and therefore accepted.
> There is currently no way to flush the cache externally, you'll have to
> restart the daemon.
> Regards
> Martin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20100603/c043d2c4/attachment.html>

More information about the Users mailing list