By setting revocation = strict, a strict CRL policy is enforced on both roadwarrior carol and gateway moon. The online certificate status is checked via the OCSP server winnetou which possesses a self-signed OCSP signer certificate that must be imported locally by the peers into the /etc/swanctl/x509ocsp/ directory. A strongswan authorities section in swanctl.conf defines an OCSP URI pointing to winnetou.

carol can successfully initiate an IPsec connection to moon since the status of both certificates is good.