File:  [ELWIX - Embedded LightWeight unIX -] / embedaddon / strongswan / testing / tests / ikev2 / ocsp-timeouts-unknown / description.txt
Revision 1.1.1.1 (vendor branch): download - view: text, annotated - select for diffs - revision graph
Wed Jun 3 09:46:47 2020 UTC (5 years, 4 months ago) by misho
Branches: strongswan, MAIN
CVS tags: v5_9_2p0, v5_8_4p7, HEAD
Strongswan

This scenario is based on <a href="../ocsp-signer-cert">ikev2/ocsp-signer-cert</a>
and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fetching
by adding an ocspuri1 in <b>moon</b>'s strongswan ca section on which no OCSP
server is listening and an ocspuri2 that cannot be resolved by <b>DNS</b>.
Since the certificate status is <b>unknown</b> the connection setup is aborted by
<b>moon</b> with an <b>AUTHORIZATION_FAILED</b> notification sent to <b>carol</b>.


FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>