Hide Forgot
Description of problem: Currently. libreswan does not fetch CRLs defined oin intermediate CA certificates. It should fetch CRLs from EE, subCA and rootCA CRLdistributionpoints Support for will be added upstream to libreswan-3.19
this work was completed in upstream 3.19 and will come in via the rebase
Paul, by any chance - is this tested upstream?
unfortunately, I don't see a test case for it. It requires extending our test certificates.
Verified SanityOnly. This should be tested in the future, unfortunately our testing PKI tools do not support intermediate CA at the time being.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2101