delay OCSP response by 5 seconds
This commit is contained in:
@@ -3,4 +3,8 @@ and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fe
|
||||
by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by
|
||||
<b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no
|
||||
OCSP server is listening. Thanks to timeouts the connection can nevertheless
|
||||
be established successfully.
|
||||
be established successfully by contacting a valid OCSP URI contained in
|
||||
<b>carol</b>'s certificate.
|
||||
<p>
|
||||
As an additional test the OCSP response is delayed by 5 seconds in order to check
|
||||
the correct handling of retransmitted IKE_AUTH messages.
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
#!/bin/bash
|
||||
|
||||
cd /etc/openssl
|
||||
|
||||
echo "Content-type: application/ocsp-response"
|
||||
echo ""
|
||||
|
||||
# simulate a delayed response
|
||||
sleep 5
|
||||
|
||||
/usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \
|
||||
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||
-nmin 5 \
|
||||
-reqin /dev/stdin -respout /dev/stdout
|
||||
Reference in New Issue
Block a user