<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 10pt;
font-family:Tahoma
}
--></style>
</head>
<body class='hmmessage'>
Thanks Rob, OCSP and mod_revocator is working now fine in my tests! <br>Great to see the mod_nss code base is more bug free and with more features than current mod_ssl implementation<br><br>Luis<br><br>> Date: Tue, 7 Sep 2010 15:20:31 -0400<br>> From: rcritten@redhat.com<br>> To: luisneves@hotmail.com<br>> CC: ttormo@indenova.com; mod_nss-list@redhat.com<br>> Subject: Re: [Mod_nss-list] Problem configuring Client certificate Authentication<br>> <br>> Luis Neves wrote:<br>> > Thanks!<br>> ><br>> > Im testing in Fedora 11. Great to know the variable work, maybe Ive used<br>> > them in the wrong place. I will test it again only in about 2 weeks as<br>> > Im going to holidays :)<br>> ><br>> > Just another tricky question, how do you will check that your users<br>> > certificates didnt got revogated? (became invalid) You will be using<br>> > certificates issued by an external Certification Authority (CA)?<br>> <br>> There are two ways: OCSP or a CRL. Or three ways I suppose, you can use <br>> both.<br>> <br>> OCSP is an online lookup of the certificate validity. If the client has <br>> an OCSP provider encoded in it then that can be used and you can define <br>> a default OCSP provider in the mod_nss configuration (1.0.6+ IIRC).<br>> <br>> A CRL must be loaded into the mod_nss certificate database (default is <br>> in /etc/httpd/alias). Apache needs to be restarted for the CRL to be <br>> seen. The NSS utility crlutil can be used to update a CRL.<br>> <br>> If you have both enabled and loaded then NSS will first look in the CRL <br>> to see if the certificate is revoked. If not it checks OCSP. This saves <br>> a round-trip.<br>> <br>> An alternative to loading a CRL and restarting Apache is to use another <br>> module, mod_revocator. In this you can define a list of URLs where CRLs <br>> can be found and they are automatically fetched and made available to <br>> NSS without requiring a restart.<br>> <br>> rob<br> </body>
</html>