[Openswan Users] multiple root CA

Laurent Jouannic laurent.jouannic at cbsa.fr
Mon Oct 3 19:56:39 CEST 2005


Hi to the forum,

Well, I'm still using freeswan with x509 path and I send my question to this forum, because freeswan one is obsolete.

My problem is the following:

My root CA will be soon obsolete and I want to know if it's possible to use multiple (in fact 2)  root CA in /etc/ipsec.d/cacerts/,  during a certain time (needed for the transition).

Is it possible?

If yes, I should have 2 crl.pem in /etc/ipsec.d/clrs/. 1 crl per cacert.
How   (freeswan/open)swan would link a clr to a cacert?

help welcomed. 
thanks.

Laurent.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20051003/1f97e9a0/attachment-0001.htm


More information about the Users mailing list