This scenario is based on ikev2/ocsp-signer-cert and tests the timeouts of the libcurl library used for http-based OCSP fetching by adding an ocspuri1 in moon's strongswan ca section on which no OCSP server is listening and an ocspuri2 that cannot be resolved by DNS. Since the certificate status is unknown the connection setup is aborted by moon with an AUTHORIZATION_FAILED notification sent to carol.