By setting strictcrlpolicy=yes, a strict CRL policy is enforced on both roadwarrior carol and gateway moon. The online certificate status is checked via the OCSP server winnetou which possesses an OCSP signer certificate issued by the strongSwan CA. This certificate contains an OCSPSigning extended key usage flag. A strongswan ca section in ipsec.conf defines an OCSP URI pointing to winnetou.

carol tries to initiate an IPsec connection to moon but fails because carol's certificate has been revoked.