Welcome! Log In Create A New Profile

Advanced

Re: ssl_crl 3:unable to get certificate CRL

Maxim Dounin
November 01, 2011 06:18PM
Hello!

On Tue, Nov 01, 2011 at 09:34:03PM +0200, Алексей Бобок wrote:

> Приветствую.
> Имею аналогичную проблему как здесь
> http://forum.nginx.org/read.php?21,6417,175050
>
> server {
> ...
> ssl on;
> ssl_certificate /usr/local/etc/nginx/certs/api.srv.biz.crt;
> ssl_certificate_key /usr/local/etc/nginx/certs/api.srv.biz.key;
>
> ssl_session_timeout 5m;
> ssl_session_cache shared:SSL:10m;
> ssl_protocols TLSv1;
> ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP;
> ssl_prefer_server_ciphers on;
> ssl_verify_client on;
> ssl_client_certificate /usr/local/etc/nginx/certs/capem.crt;
>
> ...
> }
>
> все работало.
>
> После того, как включил в секции http{
> ssl_crl /usr/local/etc/nginx/certs/crl.pem;
> }
>
> стало выдавать:
>
> 400 Bad Request
> The SSL certificate error
> nginx/1.0.3
>
> а в логе:
> 2011/11/01 21:27:02 [info] 1287#0: *1741 client SSL certificate verify
> error: (3:unable to get certificate CRL) while reading client request
> headers, client: 89.*.*.99, server: api.srv.biz, request: "GET /
> HTTP/1.1", host: "api.srv.biz"
>
> CRL список, указанный в пользовательском сертификате - доступен. Он же
> подгружается самой опцией ssl_crl.
> внутри файла такое:
> st1# openssl crl -text -in /usr/local/etc/nginx/certs/crl.pem
> Certificate Revocation List (CRL):
> Version 2 (0x1)
> Signature Algorithm: sha256WithRSAEncryption
> Issuer: /C=UA/CN=ca.srv.biz

Возвращённая ошибка предполагает, что не найден crl для одного из
сертификатов в цепочке. Клиентский сертификат выдан
"/C=UA/CN=ca.srv.biz", а тот в свою очередь - self-signed?

Maxim Dounin

_______________________________________________
nginx-ru mailing list
nginx-ru@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-ru
Subject Author Posted

ssl_crl 3:unable to get certificate CRL

Алексей Бобок November 01, 2011 04:12PM

Re: ssl_crl 3:unable to get certificate CRL

Maxim Dounin November 01, 2011 06:18PM

Re: ssl_crl 3:unable to get certificate CRL

showjumper November 02, 2011 10:16AM

Re: ssl_crl 3:unable to get certificate CRL

showjumper November 08, 2011 08:44AM

Re: ssl_crl 3:unable to get certificate CRL

showjumper November 08, 2011 08:52AM

Re: ssl_crl 3:unable to get certificate CRL

Maximus43 November 07, 2011 03:15PM

Re: ssl_crl 3:unable to get certificate CRL

Maximus43 November 08, 2011 03:42PM

Re: ssl_crl 3:unable to get certificate CRL

Forst February 05, 2015 03:52PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 305
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready