Welcome! Log In Create A New Profile

Advanced

Efficient CRL checking at Nginx

December 15, 2014 02:48PM
Hi,
I want to check the validity of a client certificate against CRL. So, I have defined in nginx.cong as follows

listen 80;
listen 443 ssl;
server_name localhost;
ssl_certificate serverCert.pem;
ssl_certificate_key serverKey.key;
ssl_client_certificate RootCA.pem;
ssl_verify_client on;
ssl_verify_depth 2;
ssl_crl CrlFile.pem;

If I write my nginx.conf as follows, It works fine. My application is expected to process a huge number of requests everyday and for each time(request) client certificate validity is checked against CrlFile.pem (specified at ssl_crl). 1. Does it effect servers response time because each time it has to open and read CrlFile.pem?.
My CrlFile.pem will be updated once a day as per my requirement. So, 2. Is there any caching mechanism performed by Nginx to cache CrlFile.pem because It has a new copy only once a day?.
3. Could you please help me in figuring out the best practice for validating client certificate against CRL.

Regards,
Sandeep
Subject Author Posted

Efficient CRL checking at Nginx

sandeepkolla99 December 15, 2014 02:48PM

Re: Efficient CRL checking at Nginx

Maxim Dounin December 15, 2014 03:30PM

Re: Efficient CRL checking at Nginx

sandeepkolla99 December 16, 2014 12:51PM

Re: Efficient CRL checking at Nginx

Maxim Dounin December 17, 2014 10:48AM

Re: Efficient CRL checking at Nginx

sandeepkolla99 December 17, 2014 11:18AM

Re: Efficient CRL checking at Nginx

alweiss March 07, 2017 08:18AM

Re: Efficient CRL checking at Nginx

Maxim Dounin March 07, 2017 08:38AM

Re: Efficient CRL checking at Nginx

alweiss March 07, 2017 09:01AM

Re: Efficient CRL checking at Nginx

alweiss June 18, 2019 11:19AM

Re: Efficient CRL checking at Nginx

Francesco Giacomini June 19, 2019 09:02AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 173
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 500 on July 15, 2024
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready