Re: [Users] Next CRL update was expected...

From: Andreas Steffen (andreas.steffen_at_strongsec.net)
Date: Sat Nov 30 2002 - 00:21:00 CET


This warning means that the nextUpdate field in your CRL was set
to Oct 05 13:16:54 and that this date has passed. If the
parameter strictcrlpolicy is *not* set to yes then this warning
does not have any consequences. With strictcrlpolicy=yes, the
IPsec connections would come to a stand-still.

Generate a new CRL put it intp /etc/ipsec.d/crls and execute

ipsec auto --rereadcrls

and the warning will disappear.

Regards

Andreas

J.J.Gallardo wrote:
> Hi : I would like to know what's mean this messages in my log:
>
> Nov 29 10:44:56 vpn-gw Pluto[548]: "central-cli1" #5940: Next CRL update
> was expected on Oct 05 13:16:54 UTC 2002
> Nov 29 10:44:56 vpn-gw Pluto[548]: "central-cli1" #5940: Next CRL update
> was expected on Oct 05 13:16:54 UTC 2002
> Nov 29 10:44:56 vpn-gw Pluto[548]: "central-cli1" #5940: ISAKMP SA
> established
>

-- 
======================================================================
Andreas Steffen                 e-mail: andreas.steffen_at_strongsec.com
strongSec GmbH                  phone:  +41 76 340 25 56
Alter Zürichweg 20              home:   http://www.strongsec.com
CH-8952 Schlieren (Switzerland)
==========================================[strong internet security]==
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users


This archive was generated by hypermail 2.1.5 : Sun Dec 01 2002 - 05:20:58 CET