Hi Martin,

Thanks for the clarification. If not possible to trigger the flush
externally, then when does that stack flush these certificates
automatically.

Regards
Sajal
On Thu, Jun 3, 2010 at 1:58 PM, Martin Willi <[email protected]> wrote:

> Hi,
>
> > This is incorrect as the Certificate of peer is signed by previous CA
> > certificate, which has been deleted in step 4 above.
>
> The certificate is probably still in the cache, and therefore accepted.
> There is currently no way to flush the cache externally, you'll have to
> restart the daemon.
>
> Regards
> Martin
>
>
_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users

Reply via email to