$ cd /etc/ipsec.d/ $ ipsec pki --signcrl --reason key-compromise \ --cacert cacerts/strongswanCert.pem \ --cakey private/strongswanKey.pem \ --cert certs/AlexanderCert.pem \ --outform pem > crls/crl.pem