Forum Discussion
Kevin_Stewart
Aug 26, 2015Employee
In short, no. When you select "No Server" as the Server Connection option in the CRLDP AAA, it'll follow the HTTP CRLDP URL in the client certificate. The other Server Connection options are for LDAP-based CRLDPs. If you're willing to host the CRLs locally (on some local web server), you could force the real URLs to resolve locally with Hosts entries. Otherwise you'd have to try to rewrite the CRLDP field in the X509 before it got to this agent. It is definitely possible but not trivial.