delay OCSP response by 5 seconds

This commit is contained in:
Andreas Steffen
2007-03-20 04:35:16 +00:00
parent e59bd409ab
commit f9a73bee9c
2 changed files with 19 additions and 1 deletions
@@ -3,4 +3,8 @@ and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fe
by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by
<b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no
OCSP server is listening. Thanks to timeouts the connection can nevertheless
be established successfully.
be established successfully by contacting a valid OCSP URI contained in
<b>carol</b>'s certificate.
<p>
As an additional test the OCSP response is delayed by 5 seconds in order to check
the correct handling of retransmitted IKE_AUTH messages.
@@ -0,0 +1,14 @@
#!/bin/bash
cd /etc/openssl
echo "Content-type: application/ocsp-response"
echo ""
# simulate a delayed response
sleep 5
/usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \
-rkey ocspKey.pem -rsigner ocspCert.pem \
-nmin 5 \
-reqin /dev/stdin -respout /dev/stdout