By setting cachecrls=yes in ipsec.conf, a copy of the CRL fetched via http from the web server winnetou is saved locally in the directory /etc/ipsec.d/crls on both the roadwarrior carol and the gateway moon when the IPsec connection is set up. The subjectKeyIdentifier of the issuing CA plus the suffix .crl is used as a unique filename for the cached CRL.