delay OCSP response by 5 seconds

This commit is contained in:
Andreas Steffen
2007-03-20 04:35:16 +00:00
parent e59bd409ab
commit f9a73bee9c
2 changed files with 19 additions and 1 deletions
@@ -3,4 +3,8 @@ and tests the timeouts of the <b>libcurl</b> library used for http-based OCSP fe
by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by by adding an ocspuri2 in <b>moon</b>'s strongswan ca section that cannot be resolved by
<b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no <b>DNS</b> and an ocspuri2 in <b>carol</b>'s strongswan ca section on which no
OCSP server is listening. Thanks to timeouts the connection can nevertheless OCSP server is listening. Thanks to timeouts the connection can nevertheless
be established successfully. be established successfully by contacting a valid OCSP URI contained in
<b>carol</b>'s certificate.
<p>
As an additional test the OCSP response is delayed by 5 seconds in order to check
the correct handling of retransmitted IKE_AUTH messages.
@@ -0,0 +1,14 @@
#!/bin/bash
cd /etc/openssl
echo "Content-type: application/ocsp-response"
echo ""
# simulate a delayed response
sleep 5
/usr/bin/openssl ocsp -index index.txt -CA strongswanCert.pem \
-rkey ocspKey.pem -rsigner ocspCert.pem \
-nmin 5 \
-reqin /dev/stdin -respout /dev/stdout