[strongSwan] charon and CRL loading

Tobias Brunner tobias at strongswan.org
Thu May 9 09:58:43 CEST 2019


Hi Anthony,

> ? does charon reload the CRL during ( re-authentication and re-connection )

Not if a valid CRL is still stored in the in-memory cache (which can be
cleared via `ipsec purgecrls` or `swanctl --flush-certs -t x509_crl`).

> If new CRL’s arrive, ? will charon use them during ( re-authentication
> and re-connection ).

Arrive how?

Regards,
Tobias


More information about the Users mailing list