By setting strictcrlpolicy=yes a strict CRL policy is enforced on both roadwarrior carol and gateway moon. Thus when carol initiates the connection and no current revocation information is available, the Main Mode negotiation fails but an OCSP request issued to the OCSP server winnetou. When the second Main Mode trial comes around the OCSP response will be available but because the certificate presented by carol has been revoked, the IKE negotatiation will fail..