Re: A few questions about revoking keys
Gert Doering <[email protected]>
| Newsgroups | gmane.network.openvpn.user |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Sun, Feb 04, 2024 at 04:32:42PM +0100, Bo Berglund wrote:
> You are right about different use cases, but I wanted to share my panic-stricken
> experience when trying to block an ex-employee with the key revoke method not
> understanding that that system relies on a constant server side refresh and that
> failing that ALL(!!!***) connections to the server would fail, not just the
> revoked one....
Understandable. So, let me second that warning :-) -
"if you use the CRL method, be aware that the CRL has an expiry date,
and MUST BE REFRESHED before that".
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJlv7EIAAoJEB2Cnv7KVigSaW0L+QFpDha3XXok39JiM5nWk50k CU3lONHm6Wbj1fRzlq/8EGnjUlSotXIHrfn8Z+y1WVaNmyNUeXUWM3+U5SBw4Lc4 Zl42xljQVmU3wOggN5TBnf4vVUj+KTIkTbjmrajcP4zQyCXpXNjC3eRZSbIWOFuA fa6DgEAUN9Bp4dFlPfn95XJNOp0hc7YRLxGyVW5lzVl/TqkAsZM6HJnr+8UgjQE3 m2PL498CX6KYTfZcaFBd7t8RVptrc+h9TZMcxWniM8Qh2aneSNOFHWT+Q/I06pq5 xywpEE4gdXkIMnUfxG7R4Jc3ImmOSJre7+uTYBwNaZN2DTm2tBuTm1kiSiDmgmff ZYhbuDxXcLghiyNtUBaYl6E9ROlS+FqpzEKO/tjY1f6eDrf8YhMUMbu49Da3/8Uc wUa/JkoyVZ7EJH9/S/TcmDztb6JiFCpObVm99gsKkNBOuBn3qtYBkn8pZnrp4Ly/ y7Bt3q8GQWro/gNp9fYCdROoKELqMhealK2w4TgDdw== =IjTB -----END PGP SIGNATURE-----