Certificate revocation lists
-
CRLs that list the certificates that are revoked or are no longer valid
-
Online Certificate Status Protocol (OSCP), an Internet protocol used for obtaining the revocation status of X.509 certificates
-
CRL Name: The name of the CRL being added on the NetScaler. Maximum 31 characters.
-
CRL File: The name of the CRL file being added on the NetScaler. The NetScaler looks for the CRL file in the /var/netscaler/ssl directory by default. Maximum 63 characters.
-
URL: Maximum 127 characters
-
Base DN: Maximum 127 characters
-
Bind DN: Maximum 127 characters
-
Password: Maximum 31 characters
-
Days: Maximum 31
-
In the configuration utility, on the Configuration tab, expand SSL and then click CRL.
-
In the details pane, click Add.
-
In the Add CRL dialog box, specify the values for the following:
-
CRL Name
-
CRL File
-
Format (optional)
-
CA Certificate (optional)
-
-
Click Create and then click Close. In the CRL details pane, select the CRL that you configured and verify that the settings that appear at the bottom of the screen are correct.
CRL refresh parameters
-
CRL NameThe name of the CRL being refreshed on the NetScaler Gateway.
-
Enable CRL Auto RefreshEnable or disable CRL auto refresh.
-
CA CertificateThe certificate of the CA that has issued the CRL. This CA certificate must be installed on the appliance. The NetScaler can update CRLs only from CAs whose certificates are installed on it.
-
MethodProtocol in which to obtain the CRL refresh from a web server (HTTP) or an LDAP server. Possible Values: HTTP, LDAP. Default: HTTP.
-
ScopeThe extent of the search operation on the LDAP server. If the scope specified is Base, the search is at the same level as the base DN. If the scope specified is One, the search extends to one level below the base DN.
-
Server IPThe IP address of the LDAP server from which the CRL is retrieved. Select IPv6 to use an IPv6 IP address.
-
PortThe port number on which the LDAP or the HTTP server communicates.
-
URLThe URL for the web location from which the CRL is retrieved.
-
Base DNThe base DN used by the LDAP server to search for the CRL attribute. Note: Citrix® recommends using the base DN attribute instead of the Issuer-Name from the CA certificate to search for the CRL in the LDAP server. The Issuer-Name field may not exactly match the LDAP directory structure's DN.
-
Bind DNThe bind DN attribute is used to access the CRL object in the LDAP repository. The bind DN attributes are the administrator credentials for the LDAP server. Configure this parameter to restrict unauthorized access to the LDAP servers.
-
PasswordThe administrator password used to access the CRL object in the LDAP repository. Password is required if the access to the LDAP repository is restricted, that is, anonymous access is not allowed.
-
IntervalThe interval at which the CRL refresh must be carried out. For an instantaneous CRL refresh, specify the interval as NOW. Possible values: MONTHLY, DAILY, WEEKLY, NOW, NONE.
-
DaysThe day on which the CRL refresh must be performed. The option is not available if the interval is set to DAILY.
-
TimeThe exact time in 24-hour format when the CRL refresh must be performed.
-
BinarySet the LDAP-based CRL retrieval mode to binary. Possible values: YES, NO. Default: NO.
-
In the navigation pane, expand SSL and then click CRL.
-
Select the configured CRL for which you want to update refresh parameters and then click Open.
-
Select the Enable CRL Auto Refresh option.
-
In the CRL Auto Refresh Parameters group, specify values for the following parameters: Note: An asterisk (*) indicates a required parameter.
-
Method
-
Binary
-
Scope
-
Server IP
-
Port*
-
URL
-
Base DN*
-
Bind DN
-
Password
-
Interval
-
Days
-
Time
-
-
Click Create. In the CRL pane, select the CRL that you configured and verify that the settings that appear at the bottom of the screen are correct.
Monitor certificate status with OCSP
NetScaler Gateway implementation of OCSP
OCSP request batching
OCSP response caching
Configure OCSP certificate status
To configure OCSP
-
On the Configuration tab, in the navigation pane, expand SSL and then click OCSP Responder.
-
In the details pane, click Add.
-
In Name, type a name for the profile.
-
In URL, type the web address of the OCSP responder.This field is mandatory. The Web address cannot exceed 32 characters.
-
To cache the OCSP responses, click Cache and in Time-out, type the number of minutes that NetScaler Gateway holds the response.
-
Under Request Batching, click Enable.
-
In Batching Delay, specify the time, in milliseconds, allowed for batching a group of OCSP requests.The values can be from 0 through 10000. The default is 1.
-
In Produced At Time Skew, type the amount of time NetScaler Gateway can use when the appliance must check or accept the response.
-
Under Response Verification, select Trust Responses if you want to disable signature checks by the OCSP responder.If you enable Trust Responses, skip Step 8 and Step 9.
-
In Certificate, select the certificate that is used to sign the OCSP responses.If a certificate is not selected, the CA that the OCSP responder is bound to is used to verify responses.
-
In Request Time-out, type the number of milliseconds to wait for an OCSP response.This time includes the Batching Delay time. The values can be from 0 through 120000. The default is 2000.
-
In Signing Certificate, select the certificate and private key used to sign OCSP requests. If you do not specify a certificate and private key, the requests are not signed.
-
To enable the number used once
(nonce) extension, select Nonce. -
To use a client certificate, click Client Certificate Insertion.
-
Click Create and then click Close.