Uploaded image for project: 'Red Hat 3scale API Management'
  1. Red Hat 3scale API Management
  2. THREESCALE-11404

Support Client Certificate revocation in APIcast

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • SaaS, 2.14.3 GA
    • Gateway
    • False
    • None
    • False
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • RHOAM Sprint 66, RHOAM Sprint 67

      NGINX provides a couple of different ways to validate if client certificates have been revoked.

      The first is through the ssl_crl directive (Certificate Revocation List)
      http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_crl

      The second is through the ssl_ocsp* directives (Online Certificate Status Protocol)
      http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ocsp

      Currently there is no way to configure these in APIcast and ideally these could be configured in the TLS Client Certificate Validation policy

              rhn-support-atra An Tran
              rhn-support-spoole Shannon Poole
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: