• False
    • None
    • False
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • RHOAM Sprint 66, RHOAM Sprint 67, RHOAM Sprint 68, RHOAM Sprint 69, RHOAM Sprint 70, RHOAM Sprint 71

      NGINX provides a couple of different ways to validate if client certificates have been revoked.

      The first is through the ssl_crl directive (Certificate Revocation List)
      http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_crl

      The second is through the ssl_ocsp* directives (Online Certificate Status Protocol)
      http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ocsp

      Currently there is no way to configure these in APIcast and ideally these could be configured in the TLS Client Certificate Validation policy

            [THREESCALE-11404] Support Client Certificate revocation in APIcast

            CPaaS Service Account mentioned this issue in merge request !534 of 3scale / Apicast Midstream on branch 3scale-amp-2_upstream_af4eb28a053e3ce7db5eb9cb49b05a66:

            Updated US source to: 5f7cb92 Merge pull request #1503 from tkan145/THREESCALE-11404-crl-and-ocsp

            GitLab CEE Bot added a comment - CPaaS Service Account mentioned this issue in merge request !534 of 3scale / Apicast Midstream on branch 3scale-amp-2_ upstream _af4eb28a053e3ce7db5eb9cb49b05a66 : Updated US source to: 5f7cb92 Merge pull request #1503 from tkan145/ THREESCALE-11404 -crl-and-ocsp

            An Tran added a comment -

            Yes we can do this.

             

            rhn-support-spoole can you please attach the case number?

            An Tran added a comment - Yes we can do this. We can just simply call ffi function from APIcast. https://github.com/3scale/APIcast/blob/master/gateway/src/resty/openssl/x509/store.lua#L15   Openresty supports ocsp out of the box https://github.com/openresty/lua-resty-core/blob/master/lib/ngx/ocsp.md   rhn-support-spoole can you please attach the case number?

              Unassigned Unassigned
              rhn-support-spoole Shannon Poole
              An Tran An Tran
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: