By setting strictcrlpolicy=yes, a strict CRL policy is enforced on both roadwarrior carol and gateway moon. The online certificate status is checked via the OCSP server winnetou which is sending its self-signed OCSP signer certificate. A strongswan ca section in ipsec.conf defines an OCSP URI pointing to winnetou.

carol cannot successfully initiate an IPsec connection to moon since the self-signed certificate contained in the OCSP response will not be accepted by moon.