Certificate revocation lists
Create a CRL on the ADC appliance
-
Certificates that you have created.
-
Certificates whose CA certificate you own.
Revoke a certificate or create a CRL by using the CLI
create ssl crl <CAcertFile> <CAkeyFile> <indexFile> (-revoke <input_filename> | -genCRL <output_filename>)
create ssl crl Cert-CA-1 Key-CA-1 File-Index-1 -revoke Invalid-1
create ssl crl Cert-CA-1 Key-CA-1 File-Index-1 -genCRL CRL-1
Revoke a certificate or create a CRL by using the GUI
-
Navigate to Traffic Management > SSL and, in the Getting Started group, select CRL Management.
-
Enter the certificate details and, in the Choose Operation list, select Revoke Certificate, or Generate CRL.
Add an existing CRL to the ADC
Add a CRL on the NetScaler by using the CLI
add ssl crl <crlName> <crlPath> [-inform (DER | PEM)]
show ssl crl [<crlName>]
> add ssl crl crl-one /var/netscaler/ssl/CRL-one -inform PEM
Done
> show ssl crl crl-one
Name: crl-one Status: Valid, Days to expiration: 29
CRL Path: /var/netscaler/ssl/CRL-one
Format: PEM CAcert: samplecertkey
Refresh: DISABLED
Version: 1
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=US,ST=California,L=Santa Clara,O=NetScaler Inc.,OU=SSL Acceleration,CN=www.ns.com/emailAddress=support@NetScaler appliance.com
Last_update:Jun 15 10:53:53 2010 GMT
Next_update:Jul 15 10:53:53 2010 GMT
1) Serial Number: 00
Revocation Date:Jun 15 10:51:16 2010 GMT
Done
Add a CRL on the NetScaler by using the GUI
Configure CRL refresh parameters
Configure CRL autorefresh by using the CLI
set ssl crl <crlName> [-refresh ( ENABLED | DISABLED )] [-CAcert <string>] [-server <ip_addr|ipv6_addr|*> | -url <URL>] [-method ( HTTP | LDAP )] [-port <port>] [-baseDN <string>] [-scope ( Base | One )] [-interval <interval>] [-day <positive_integer>] [-time <HH:MM>][-bindDN <string>] {-password } [-binary ( YES | NO )]
show ssl crl [<crlName>]
set CRL crl1 -refresh enabled -method ldap -inform DER -CAcert ca1 -server 10.102.192.192 -port 389 -scope base -baseDN "cn=clnt_rsa4_multicert_der,ou=eng,o=ns,c=in" -time 00:01
set ssl crl crl1 -refresh enabled -method http -cacert ca1 -port 80 -time 00:10 -url http://10.102.192.192/crl/ca1.crl
> sh crl
1) Name: crl1 Status: Valid, Days to expiration: 355
CRL Path: /var/netscaler/ssl/crl1
Format: PEM CAcert: ca1
Refresh: ENABLED Method: HTTP
URL: http://10.102.192.192/crl/ca1.crl Port:80
Refresh Time: 00:10
Last Update: Successful, Date:Tue Jul 6 14:38:13 2010
Done
Configure CRL autorefresh using LDAP or HTTP by using the GUI
-
Navigate to Traffic Management > SSL > CRL.
-
Open a CRL, and select Enable CRL Auto Refresh.
Synchronize CRLs
Synchronize CRL autorefresh by using the CLI
set ssl crl <crlName> [-interval <interval>] [-day <integer>] [-time <HH:MM>]
set ssl crl CRL-1 -refresh ENABLE -interval MONTHLY -days 10 -time 12:00
Synchronize CRL refresh by using the GUI
-
Navigate to Traffic Management > SSL > CRL.
-
Open a CRL, select enable CRL Auto Refresh, and specify the interval.
Perform client authentication by using a certificate revocation list
-
Rule for CRL check
-
Rule for client certificate check
-
State of the CRL configured for the CA certificate
| Rule for CRL Check | Rule for Client Certificate Check | State of the CRL Configured for the CA certificate | Result of a Handshake with a Revoked Certificate |
|---|---|---|---|
| Optional | Optional | Missing | Success |
| Optional | Mandatory | Missing | Success |
| Optional | Mandatory | Present | Failure |
| Mandatory | Optional | Missing | Success |
| Mandatory | Mandatory | Missing | Failure |
| Mandatory | Optional | Present | Success |
| Mandatory | Mandatory | Present | Failure |
| Optional/Mandatory | Optional | Expired | Success |
| Optional/Mandatory | Mandatory | Expired | Failure |
-
The CRL check is optional by default. To change from optional to mandatory or conversely, you must first unbind the certificate from the SSL virtual server, and then bind it again after changing the option.
-
In the output of the
sh ssl vservercommand, OCSP check: optional implies that a CRL check is also optional. The CRL check settings are displayed in the output of thesh ssl vservercommand only if the CRL check is set to mandatory. If the CRL check is set to optional, the CRL check details do not appear.
To configure CRL check by using the CLI
bind ssl vserver <vServerName> -certkeyName <string> [(-CA -crlCheck ( Mandatory | Optional ))]
sh ssl vserver
bind ssl vs v1 -certkeyName ca -CA -crlCheck mandatory
> sh ssl vs v1
Advanced SSL configuration for VServer v1:
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED
Ephemeral RSA: ENABLED Refresh Count: 0
Session Reuse: ENABLED Timeout: 120 seconds
Cipher Redirect: DISABLED
SSLv2 Redirect: DISABLED
ClearText Port: 0
Client Auth: ENABLED Client Cert Required: Mandatory
SSL Redirect: DISABLED
Non FIPS Ciphers: DISABLED
SNI: DISABLED
OCSP Stapling: DISABLED
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
SSLv2: DISABLED SSLv3: ENABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED
Push Encryption Trigger: Always
Send Close-Notify: YES
ECC Curve: P_256, P_384, P_224, P_521
1) CertKey Name: ca CA Certificate CRLCheck: Mandatory CA_Name Sent
1) Cipher Name: DEFAULT
Description: Predefined Cipher Alias
Done
Configure CRL check by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers, and open an SSL virtual server.
-
Click in the Certificates section.
-
Select a certificate and, in the OCSP and CRL Check list, select CRL Mandatory.
Result of a handshake with a revoked or valid certificate
| Rule for CRL check | Rule for client certificate check | State of the CRL configured for the CA certificate | Result of a handshake with a revoked certificate | Result of a handshake with a valid certificate |
|---|---|---|---|---|
| Mandatory | Mandatory | Present | Failure | Success |
| Mandatory | Mandatory | Expired | Failure | Failure |
| Mandatory | Mandatory | Missing | Failure | Failure |
| Mandatory | Mandatory | Undefined | Failure | Failure |
| Optional | Mandatory | Present | Failure | Success |
| Optional | Mandatory | Expired | Success | Success |
| Optional | Mandatory | Missing | Success | Success |
| Optional | Mandatory | Undefined | Success | Success |
| Mandatory | Optional | Present | Success | Success |
| Mandatory | Optional | Expired | Success | Success |
| Mandatory | Optional | Missing | Success | Success |
| Mandatory | Optional | Undefined | Success | Success |
| Optional | Optional | Present | Success | Success |
| Optional | Optional | Expired | Success | Success |
| Optional | Optional | Missing | Success | Success |
| Optional | Optional | Undefined | Success | Success |