ipsec.conf: ca Reference » History » Version 5
Tobias Brunner, 18.04.2008 13:54
certuribase added
1 | 1 | Martin Willi | = ca <name> = |
---|---|---|---|
2 | 1 | Martin Willi | |
3 | 3 | Martin Willi | * ''also = ''<section name> |
4 | 4 | Martin Willi | includes ca section <name>. |
5 | 2 | Martin Willi | |
6 | 3 | Martin Willi | * ''auto = '''ignore'''|add'' |
7 | 1 | Martin Willi | |
8 | 3 | Martin Willi | * ''cacert = ''<path> |
9 | 4 | Martin Willi | defines a path to the CA certificate either relative to ''/etc/ipsec.d/cacerts'' or as an absolute path. |
10 | 1 | Martin Willi | |
11 | 3 | Martin Willi | * ''crluri = ''<uri> |
12 | 4 | Martin Willi | defines a CRL distribution point (ldap, http, or file URI). |
13 | 1 | Martin Willi | |
14 | 3 | Martin Willi | * ''crluri1 = ''<uri> |
15 | 3 | Martin Willi | synonym for ''crluri''. |
16 | 1 | Martin Willi | |
17 | 3 | Martin Willi | * ''crluri2 = ''<uri> |
18 | 4 | Martin Willi | defines an alternative CRL distribution point (ldap, http, or file URI). |
19 | 1 | Martin Willi | |
20 | 3 | Martin Willi | * ''ldaphost = ''<hostname> |
21 | 4 | Martin Willi | defines an ldap host. Currently used by IKEv1 only. |
22 | 1 | Martin Willi | |
23 | 3 | Martin Willi | * ''ocspuri = ''<uri> |
24 | 4 | Martin Willi | defines an OCSP URI. |
25 | 1 | Martin Willi | |
26 | 3 | Martin Willi | * ''ocspuri1 = ''<uri> |
27 | 3 | Martin Willi | synonym for ''ocspuri''. |
28 | 1 | Martin Willi | |
29 | 3 | Martin Willi | * ''ocspuri2 = ''<uri> |
30 | 4 | Martin Willi | defines an alternative OCSP URI. Currently used by IKEv2 only. |
31 | 5 | Tobias Brunner | |
32 | 5 | Tobias Brunner | * ''certuribase = ''<uri> |
33 | 5 | Tobias Brunner | defines the base URI for the Hash and URL feature supported by IKEv2. |
34 | 5 | Tobias Brunner | Instead of exchanging complete certificates, IKEv2 allows to send an URI |
35 | 5 | Tobias Brunner | that resolves to the DER encoded certificate. The certificate URIs are built |
36 | 5 | Tobias Brunner | by appending the SHA1 hash of the DER encoded certificates to this base URI. |