users@glassfish.java.net

Re: Certificate Revocation List (CRL) use in GlassFish v3

From: <glassfish_at_javadesktop.org>
Date: Thu, 14 Oct 2010 09:32:09 PDT

Kumar,
 
> Just to be clear : with my example revocation works as expected, but when you place your keystores and crl file it fails (i.e CRL checking fails to detect a revoked cert).

That is correct.

BTW, I discovered the crl.pem file in your example is outdated. I emailed you directly about that. Do you have a current file?

Also, I noted that your crl.pem file is
Signature Algorithm: md5WithRSAEncryption
and mine is
Signature Algorithm: sha1WithRSAEncryption
would that make any difference?
[Message sent by forum member 'eliscinsky']

http://forums.java.net/jive/thread.jspa?messageID=485219