Forum Discussion
2 Way SSL implementation
Kevin, 2way ssl working like your config. Thank you. Please help me to configure automatic update for crl file in F5 version 13.
- Kevin_StewartNov 20, 2017
Employee
Gicu,
There is no auto-update function for CRLs. Most admins will create an external monitor or periodic iCall script to update the CRLs. It's also worth noting that, if at all possible, OCSP and OCSP stapling are superior methods for certificate revocation.
- Gicu_337843Nov 28, 2017
Nimbostratus
Kevin sorry for my disturb. Pls help me if you know. I have tried below command of tmsh shell and working: modify sys file ssl-crl ROOT_OMDEXT_CA.crl source-path https://dl.dropboxusercontent.com/u/xxxxxx/CA_XCA_Root.crl
I have tried the same command of icall script but not working: create script omdcrl { app-service none definition { tmsh::modify sys file ssl-crl XCA_CRL.crl source-path https://dl.dropboxusercontent.com/u/xxxxxx/CA_XCA_Root.crl } description none events none }
if I change source-path as file:/shared/tmp/CA_XCA_Root.crl it is working
- Kevin_StewartDec 06, 2017
Employee
It may just be that you can't retrieve it from a dropbox link. I just tested with a generic Apache server and it worked fine.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
