By setting revocation = strict a strict CRL policy is enforced on
both roadwarrior carol and gateway moon. Thus when carol initiates
the connection and only an expired CRL cache file in /etc/swanctl/x509crl is
available, an ldap fetch to get the CRL from the LDAP server winnetou is
successfully started and the IKE authentication completes. The new CRL is again
cached locally as a file in /etc/swanctl/x509crl due to the cache_crls = yes
option in /etc/strongswan.conf.