Re: CRL verification in slapd

Ralf Haferkamp wrote:


As openssl-0.9.7* has some CRL checking capabilities, I am currently working on implementing CRL checking in slapd. Therefor I plan to add the following directives to ldap.conf and slapd.conf:



The possible values of these would be: (reflecting the possibilities, that openssl-0.9.7d currently has)

"no"	do not perform any CRL checks (this would be the default)
"yes"   perform CRL checks
"all"   perform CRL checks for a for whole chain

Any comments or suggestings regarding this?

No suggestions here, it sounds good to me. (Though for some reason I thought CRL checks were only in the 0.9.8 branch. Must be misremembering.)

