Project

General

Profile

ipsec.conf: ca Reference » History » Version 5

Tobias Brunner, 18.04.2008 13:54
certuribase added

1 1 Martin Willi
= ca <name> =
2 1 Martin Willi
3 3 Martin Willi
 * ''also = ''<section name>
4 4 Martin Willi
     includes ca section <name>.
5 2 Martin Willi
6 3 Martin Willi
 * ''auto = '''ignore'''|add''
7 1 Martin Willi
8 3 Martin Willi
 * ''cacert = ''<path>
9 4 Martin Willi
     defines a path to the CA certificate either relative to ''/etc/ipsec.d/cacerts'' or as an absolute path.
10 1 Martin Willi
11 3 Martin Willi
 * ''crluri = ''<uri>
12 4 Martin Willi
     defines a CRL distribution point (ldap, http, or file URI).
13 1 Martin Willi
14 3 Martin Willi
 * ''crluri1 = ''<uri>
15 3 Martin Willi
     synonym for ''crluri''.
16 1 Martin Willi
17 3 Martin Willi
 * ''crluri2 = ''<uri>
18 4 Martin Willi
     defines an alternative CRL distribution point (ldap, http, or file URI).
19 1 Martin Willi
20 3 Martin Willi
 * ''ldaphost = ''<hostname>
21 4 Martin Willi
     defines an ldap host. Currently used by IKEv1 only.
22 1 Martin Willi
23 3 Martin Willi
 * ''ocspuri = ''<uri>
24 4 Martin Willi
     defines an OCSP URI.
25 1 Martin Willi
26 3 Martin Willi
 * ''ocspuri1 = ''<uri>
27 3 Martin Willi
     synonym for ''ocspuri''.
28 1 Martin Willi
29 3 Martin Willi
 * ''ocspuri2 = ''<uri>
30 4 Martin Willi
     defines an alternative OCSP URI. Currently used by IKEv2 only.
31 5 Tobias Brunner
32 5 Tobias Brunner
 * ''certuribase = ''<uri>
33 5 Tobias Brunner
     defines the base URI for the Hash and URL feature supported by IKEv2.
34 5 Tobias Brunner
     Instead of exchanging complete certificates, IKEv2 allows to send an URI
35 5 Tobias Brunner
     that resolves to the DER encoded certificate. The certificate URIs are built
36 5 Tobias Brunner
     by appending the SHA1 hash of the DER encoded certificates to this base URI.