Just wondering what the current state of CRL handling in LibreSWAN is?

I'm running 3.18, and files in /etc/ipsec.d/crls seem to be detected and imported by "ipsec auto --rereadcrls", but "ipsec auto --listcrls" shows nothing:

> ipsec auto --rereadcrls
> 002   loading crl file 'crl.pem' (1223 bytes)

> ipsec auto --listcrls
> 000
> 000 List of CRLs:

Attempts to import a CRL file into the NSS database using crlutil fail with "crlutil: unable to import CRL: SEC_ERROR_CRL_INVALID: New CRL has an invalid format."

Nels Lindquist
----
<[email protected]>
_______________________________________________
Swan mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan

Reply via email to