> Hi Martin,
>
> Thanks for the explanations.
>
> I don't see an authorityKeyIdentifier in my CRL, but my openssl.cnf
> contains :
>
> [ crl_ext ]
> authorityKeyIdentifier = keyid:always,issuer:always
I found the problem. I was missing the 'crl_extensions = crl_ext' line
in my openssl.cnf.
It works now.

thanks a lot for your help.

kind regards,
Claude
>
> Isn't this correct ?
>
> kind regards,
> Claude
>
>
>
> _______________________________________________
> Users mailing list
> [email protected]
> https://lists.strongswan.org/mailman/listinfo/users


-- 
Claude Tompers
Ingénieur réseau et système
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la 
Recherche
6, rue Richard Coudenhove-Kalergi
L-1359 Luxembourg

Tel: +352 424409 1
Fax: +352 422473


Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users

Reply via email to