Description of problem: Causes a "no capable fetcher found error" when using CA certs which contain CRL URIs with strictcrlpolicy enabled. This is an important part of Version-Release number of selected component (if applicable): Using v5, not sure if this affects v4.x. How reproducible: Set up an x509 ipsec tunnel using certs signed with CA with a Enter Bug: Fedora EPEL url and turn on strictcrlpolicy Actual results: /var/log/messages: Apr 15 15:15:58 swan1 charon: 13[LIB] unable to fetch from http://ca.domain.co.uk/crl/domain.crl, no capable fetcher found You cannot then bring the tunnel up as this violates the CRL policy Expected results: CRL to be downloaded and tunnel up. Additional info:
Feel free to try 5.1.1-3 build: http://koji.fedoraproject.org/koji/packageinfo?packageID=13302