Re: [strongSwan] revoke certification with out "ipsec restart"

2017-09-07 Thread Nimo
Hi Tobias, >> I don't want to use "ipsec restart" because other IPsec sessions are >> disconnected. >> How can I make enabled the revocation without disconnecting other's >> IPsec session ? > > You used the same crlNumber for your second CRL. So it didn't replace > the CRL that you loaded before

Re: [strongSwan] revoke certification with out "ipsec restart"

2017-09-07 Thread Tobias Brunner
Hi Nimo, > I don't want to use "ipsec restart" because other IPsec sessions are > disconnected. > How can I make enabled the revocation without disconnecting other's > IPsec session ? You used the same crlNumber for your second CRL. So it didn't replace the CRL that you loaded before (this is

[strongSwan] revoke certification with out "ipsec restart"

2017-09-06 Thread Nimo
Hi, I'm trying to revoke Windows machine certificate. But it fails as below. Could please someone help me ? I made two machine certificate for Win-A, Win-B. Windows is windows7 and I setup it based on https://wiki.strongswan.org/projects/strongswan/wiki/Win7Certs. strongSwan is 5.5.3 and