Forum Discussion
APM CRLDP
Hello,
I'm configuring APM CRLDP for HTTP CRL retrieval and have a few questions about it. When you select pool or direct the base DN field must be populated. Does this mean that HTTP method is not applicable when you enter a destination IP? i.e. you cannot manually define CRL destinations and must use the ones contained in the client cert. If this is correct how does the APM handle multiple CRL destination URLs in the certs, timeouts and such?
thankyou
Hello,
When you specify a destination, it's for ldap only. In latest versions you have a third option. When checked APM will look in the crldp field of your certificate
- Yann_Desmarest_Nacreous
Hello,
When you specify a destination, it's for ldap only. In latest versions you have a third option. When checked APM will look in the crldp field of your certificate
- Yann_Desmarest_NacreousOf course, if the crldp field in your cert is invalid or non existent. You have a problem. To workaround this, you can define a crl in the clientssl profile and update it using cron and tmsh
- chris100_263517Nimbostratusif I understand - for HTTP CRL you must use cert CRL field when using CRLDP
- Yann_Desmarest_NacreousYou should use an CRLDP AAA object and select the option No Server. This way, the bigip APM will use the crldp field in the client certificate. You have to add a CRLDP block in your VPE
Hello,
When you specify a destination, it's for ldap only. In latest versions you have a third option. When checked APM will look in the crldp field of your certificate
- Of course, if the crldp field in your cert is invalid or non existent. You have a problem. To workaround this, you can define a crl in the clientssl profile and update it using cron and tmsh
- chris100_263517Nimbostratusif I understand - for HTTP CRL you must use cert CRL field when using CRLDP
- You should use an CRLDP AAA object and select the option No Server. This way, the bigip APM will use the crldp field in the client certificate. You have to add a CRLDP block in your VPE
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com