This test except that with a CRL policy set to strict, and no available CRL, the connection fails. See also 06,11,12,13 This time, multiple valid and invalid CRL's are available. It is unknown what the behaviour will be (or should be) East does not have north's certificate cached. East will send a CR to north. East also doesn't have a specific policy for north, but rather, will accept anything that is signed by a specific CA. North will transmit its certificate to east via nic. North's certificate is issued by a CA east accepts (cacerts/ca.crt), and so should be accepted.