It means that the CRLDP function does not currently support HTTP-based CRL fetching, only LDAP. The number indicates the support ID assigned to track the request.
I’m looking for a bit of guidance on how to setup a CRLDP AAA server to use HTTP as I just can’t seem to get it right. We are running 11.4.1 HF3 and I have the following options configured for the CRLDP server:
Hey Peter did you actually get CRLDP AAA working on HTTP in APM v11.4.1 HF3? When I try to define the CRLDP server (as Direct + HTTP for example) it simply ignores the Server details and changes the type to “no server”. I have a client cert inspection stage in policy which is working fine, but the following CRLDP Auth seems to do nothing. On the wire there are no HTTP requests being sent to the CRL host and I can still log in with a revoked certificate. I searched for this ID325296 in the release notes, but cannot find anything concrete to say HTTP is now supported for CRLDP AAA on APM thanks
Ok, so it does work and the behaviour of it resorting to “no server” seems to be OK. If you tweak the cache & update timeouts whilst looking on the wire, you do indeed see the HTTP fetch of the CRL from the CDRLP server. Happy Days