Forum Discussion
Hille_de_Graaf_
Nimbostratus
Oct 24, 2007bypass a CRL with an invalid date
Hi,
We are using client certificates and a CRL (Certificate Revocation List) to check wether the client certificate is revocated.
Every night we are loading a new CRL from our provider ...
David_Holmes_9
Nov 09, 2007Historic F5 Account
Hello Hille,
I tested your rule with an expired CRL and for me anyway, it DOES allow the traffic through. I see the following three messages:
"Found CRL is expired -- revoking all certificates until current CRL is available."
Rule crltest : ClientSSL_Client handshake status: CRL has expired
Rule crltest : CRL date is not valid, but you may continue
I also tested your rule with a revoked certificate and it redirects to "certerror.htm"
Do you not see the "you may continue" message when you run your rule?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
