delay OCSP response by 5 seconds
This commit is contained in:
@@ -3,4 +3,8 @@ and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fe
|
|||||||
by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by
|
by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by
|
||||||
<b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no
|
<b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no
|
||||||
OCSP server is listening. Thanks to timeouts the connection can nevertheless
|
OCSP server is listening. Thanks to timeouts the connection can nevertheless
|
||||||
be established successfully.
|
be established successfully by contacting a valid OCSP URI contained in
|
||||||
|
<b>carol</b>'s certificate.
|
||||||
|
<p>
|
||||||
|
As an additional test the OCSP response is delayed by 5 seconds in order to check
|
||||||
|
the correct handling of retransmitted IKE_AUTH messages.
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
cd /etc/openssl
|
||||||
|
|
||||||
|
echo "Content-type: application/ocsp-response"
|
||||||
|
echo ""
|
||||||
|
|
||||||
|
# simulate a delayed response
|
||||||
|
sleep 5
|
||||||
|
|
||||||
|
/usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \
|
||||||
|
-rkey ocspKey.pem -rsigner ocspCert.pem \
|
||||||
|
-nmin 5 \
|
||||||
|
-reqin /dev/stdin -respout /dev/stdout
|
||||||
Reference in New Issue
Block a user