Re: CRL with OpenSSL


On Sun, 13 Apr 2014, Emmanuel Dreyfus wrote:
Christian Kratzer <ck-lists@cksoft.de> wrote:

looks for an inexistant ${hash}.r1 file. What should be there?
Propably an update to the crl.  You would have to lookup the openssl
docs to be sure.

I think this is because the CRL Next Update is in the past.  I will
renew the CRL to check that.

yes an expired crl will usually cause validation to fail.

I have experienced this regularly when forettting to update the crl
for ipsec vpn with racoon. Should be the same for openldap.


