Re: [Swan-dev] dist_certs.py and crl tests

2014-11-28 Thread Paul Wouters 🔓
On Fri, 28 Nov 2014, Matt Rogers wrote: (moved discussion to swan-dev) The intent was that the signature made by the CAcert over the CRL was either not yet valid or expired. This is unrelated to the content of the CRL. The signature being expired? Do you mean a scenario where the CRL is signe

Re: [Swan-dev] shared IKE SA interop bug with cisco

2014-11-28 Thread Matt Rogers
On 11/25, Paul Wouters ? wrote: > > Matt wrote the problem below. I am still confused what exactly is > happening and why we would need his patch for this. I would think > that if we --down tunnelA we should notice the phase1 is still used > by tunnelB and leave/move it around instead? > The use