5 ms·
Why would CRL require web server support?
by Asmod4n 2y ago
Why would CRL require web server support?
- iso8859-1 2y agoSo that admins find out that the certificate they have configured is no longer valid.
- Asmod4n 2y agoYou’d need a monitoring solution for that, your web server won’t just send you a mail when it’s cert got revoked. The client does that for you, by checking back at the CA. No need for any configuration server side.
- mcpherrinm 2y agoFor webservers, our recommendation is that your ACME client queries the ACME Renewal Information endpoint to find out if the certificate needs to be renewed: https://letsencrypt.org/2023/03/23/improving-resliiency-and-reliability-with-ari.html https://letsencrypt.org/2023/03/23/improving-resliiency-and-...
- Arnavion 2y agoDoes ARI also return a suggested window of "right now" if the queried cert is manually revoked in the past? I was actually wondering this a few months ago when I implemented ARI in my ACME client - I also have a pending task to implement revocation checking, and if the ARI check makes that redundant it would be great. (Both the RFC and the LE blog only talk about querying ARI at some time before the CA decides to revoke the cert. My question is about querying ARI at some time after the user has revoked the cert.)
- mcpherrinm 2y agoYes, revoked certs will return "right now".
- Arnavion 2y agoThat's really nice. Thanks.
- eqvinox 2y agoIf your certificate has been revoked and you don't know that (e.g. from a very alarming e-mail), something has seriously gone wrong. In the general case, it'd be yourself requesting the revocation to begin with. But even if it isn't, I'm pretty sure the CA is supposed to tell you expeditiously.
- phasmantistes 2y agoNot all subscribers provide email addresses through which they could be informed of a revocation.
- mcpherrinm 2y agoIdeally your server handles this automatically, which is why Let’s Encrypt is working on extending ACME to help with this case. Some good implementations of ocsp stapling can already automatically get a new certificate if they receive a “revoked” ocsp response. Requiring humans to read their email and be looped in is work I want to avoid needing at all.
- c0balt 2y agoTo verify client and server certificates. For certificate-based auth this is quite important, but it's also nice to, e.g., know that your server cert is not revoked.
- Asmod4n 2y agoYour client does the checking of the server cert, no need for any configuration server side. If you use certs for client auth it’s unlikely it’s used on the web and only in a company setting where you control the PCs, where you could just use something more suited for that case.
- eqvinox 2y agoIt's the client that is supposed to fetch the CRL. The server doesn't care unless it does client certificate authentication (which is incredibly rare due to poor UX.)
- hunter2_ 2y agoA server (nginx / httpd) might very well make outbound HTTPS calls and want to verify the origin's certificate to the fullest extent possible. This is known as a reverse proxy. However, many -- certainly not all -- reverse proxy configurations use origin servers that reside on the same exact network, and therefore don't need TLS connections (or use them with `SSLProxyVerify none` for e.g. self-signed certs to simplify things [0]), but I digress. [0] https://httpd.apache.org/docs/current/mod/mod_ssl.html#sslproxyverify https://httpd.apache.org/docs/current/mod/mod_ssl.html#sslpr...