Summary
CRLs generated using the VyOS PKI subsystem do not include standard X.509 extensions (e.g., Authority Key Identifier, CRL Number). As a result, strongSwan cannot properly validate certificate revocation status during IKE authentication.
Steps to reproduce
- Generate a CA on VyOS:
run generate pki ca install <ca-name>
- Generate and sign certificates using that CA:
run generate pki certificate sign <ca-name> install <cert-A> run generate pki certificate sign <ca-name> install <cert-B>
- Revoke one certificate:
set pki certificate <cert-B> revoke
- Generate and install the CRL:
run generate pki crl <ca-name> install commit
- Configure IPsec site-to-site VPN using certificate authentication (referencing the CA and certificates)
- Check tunnel establishment — even though <cert-B> is revoked, the tunnel authentication still succeeds
Observed behavior
router-A charon[1234]: checking certificate status of "CN=<cert-B>" router-A charon[1234]: certificate status is not available router-A charon[1234]: authentication of 'CN=<cert-B>' with RSA_EMSA_PKCS1_SHA2_256 successful
This indicates that strongSwan is unable to verify certificate status using the CRL.
CRL inspection
openssl crl -text -noout -in /etc/swanctl/x509crl/<file>.pem
Output does not contain extensions:
Certificate Revocation List (CRL):
Version 2 (0x1)
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=<ca-name>
Last Update: <timestamp>
Next Update: <timestamp>
Revoked Certificates:
...Example of CRL with required extensions:
Certificate Revocation List (CRL):
Version 2 (0x1)
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=<ca-name>
Last Update: <timestamp>
Next Update: <timestamp>
CRL extensions:
X509v3 Authority Key Identifier:
<key-id>
X509v3 CRL Number:
1
Revoked Certificates:
...Expected behavior (CRL with proper extensions)
router-A charon[1234]: checking certificate status of "CN=<cert-B>" router-A charon[1234]: using trusted certificate "CN=<ca-name>" router-A charon[1234]: crl correctly signed by "CN=<ca-name>" router-A charon[1234]: crl is valid: until Apr 28 00:28:05 2026 router-A charon[1234]: certificate was revoked on Apr 13 00:28:05 UTC 2026 router-A charon[1234]: generating IKE_AUTH response [ AUTH_FAILED ]
Conclusion
CRL generation in VyOS PKI lacks required X.509 extensions, preventing strongSwan from properly validating certificate revocation status.