[strongSwan] Help, charon: 03[CFG] issuer of fetched CRL does not match CRL issuer
jacky.he at gmail.com
Thu Jul 28 13:49:20 CEST 2011
Thank you, Tobias.
That is some part of my openssl.cnf, but I use your suggestion to uncomment this line in my openssl.cnf, everything is ok now.
# crl_extensions = crl_ext
Thank you again.
From: Tobias Brunner [mailto:tobias at strongswan.org]
Sent: Thursday, July 28, 2011 6:53 PM
Cc: Users at lists.strongswan.org
Subject: Re: [strongSwan] Help, charon: 03[CFG] issuer of fetched CRL does not match CRL issuer
Is that your complete openssl.cnf? Because the crl_ext section has to
actually be referenced in your CA section.
[ ca ]
default_ca = my_ca
[ my_ca ]
dir = /dir/to/ca
# ... other options (see 'man ca')
crl_extensions = crl_ext
__________ Information from ESET NOD32 Antivirus, version of virus signature database 6330 (20110727) __________
The message was checked by ESET NOD32 Antivirus.
More information about the Users