CRLs and Intermediate CAs in Apache

"Rhoden, Barret J. Mr. CN (NGIT) HQ USAREUR/7A CIO G6" <[email protected]>
Newsgroups gmane.comp.apache.mod-ssl.user
Message-ID <673CAD77D9D4C14DB8B949B4A30F39C904883328@CMBL0019HQUS412.EUR.DS.ARMY.MIL>
hi - 

does anyone know if apache checks the CRLs for a revoked intermediate CA
certificate?  

for instance, say i set SSLVerifyDepth to 2 and i have the CRLs for the root
CA, as well as the intermediate CAs.  the client has a client certificate
signed by an intermediate CA.  the client's cert is not on the CRL, but the
intermediate CA has been revoked by the root.  when the ssl module works
it's way up the certificate chain, does it check each cert in the chain
against it's higher's CRL, or is the client certificate the only one checked
for revocation?

thanks in advance.

barret
smime.p7s (application/x-pkcs7-signature, 4.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.