Welcome! Log In Create A New Profile

Advanced

NGINX not checking OCSP for revoked certificates

Zeal Vora
October 13, 2016 05:38AM
Hi

We've implemented basic Certificate Based Authentication for Nginx.

However whenever the certificate is revoked, Nginx still allows the client
( with revoked certificate ) to access the website.

I verified manually with openssl with OCSP URI and OCSP seems to be working
properly. Nginx doesn't seem to be forwarding request to OCSP before
allowing client.

I tried to specify the ssl_crl but as soon as I put it, all the clients
starts to receive 400 Bad Request.

Here is my sample relevant Nginx Config :-


### SSL cert files ###

ssl_client_certificate /test/ca.crt;
ssl_verify_client optional;

ssl_crl /prod-adcs/latest.pem;
ssl_verify_depth 2;


Is there something that I'm missing here ?


Any help will be appreciated.
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

NGINX not checking OCSP for revoked certificates

Zeal Vora October 13, 2016 05:38AM

Re: NGINX not checking OCSP for revoked certificates

Maxim Dounin October 13, 2016 08:58AM

Re: NGINX not checking OCSP for revoked certificates

Zeal Vora October 14, 2016 01:50AM

Re: NGINX not checking OCSP for revoked certificates

alexsamad October 14, 2016 04:52AM

Re: NGINX not checking OCSP for revoked certificates

Zeal Vora October 14, 2016 06:04AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 291
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready