mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
updated documentation for CRL reload
This commit is contained in:
@@ -1,6 +1,8 @@
|
|||||||
* Version 0.10.9 (unreleased)
|
* Version 0.10.9 (unreleased)
|
||||||
- When compiled with GnuTLS 3.4 automatically sort the certificate list
|
- When compiled with GnuTLS 3.4 automatically sort the certificate list
|
||||||
to be imported.
|
to be imported.
|
||||||
|
- Reload the CRL on during periodic maintaince if its modification time
|
||||||
|
changes.
|
||||||
|
|
||||||
|
|
||||||
* Version 0.10.8 (released 2015-09-04)
|
* Version 0.10.8 (released 2015-09-04)
|
||||||
|
|||||||
+3
-1
@@ -213,7 +213,9 @@ cert-user-oid = 0.9.2342.19200300.100.1.1
|
|||||||
#cert-group-oid = 2.5.4.11
|
#cert-group-oid = 2.5.4.11
|
||||||
|
|
||||||
# The revocation list of the certificates issued by the 'ca-cert' above.
|
# The revocation list of the certificates issued by the 'ca-cert' above.
|
||||||
# See the manual to generate an empty CRL initially.
|
# See the manual to generate an empty CRL initially. The CRL will be reloaded
|
||||||
|
# periodically when ocserv detects a change in the file. To force a reload use
|
||||||
|
# SIGHUP.
|
||||||
#crl = /path/to/crl.pem
|
#crl = /path/to/crl.pem
|
||||||
|
|
||||||
# Uncomment this to enable compression negotiation (LZS, LZ4).
|
# Uncomment this to enable compression negotiation (LZS, LZ4).
|
||||||
|
|||||||
+4
-2
@@ -271,7 +271,9 @@ mobile-dpd = 1800
|
|||||||
try-mtu-discovery = false
|
try-mtu-discovery = false
|
||||||
|
|
||||||
# The revocation list of the certificates issued by the 'ca-cert' above.
|
# The revocation list of the certificates issued by the 'ca-cert' above.
|
||||||
# See the manual to generate an empty CRL initially.
|
# See the manual to generate an empty CRL initially. The CRL will be reloaded
|
||||||
|
# periodically when ocserv detects a change in the file. To force a reload use
|
||||||
|
# SIGHUP.
|
||||||
#crl = /path/to/crl.pem
|
#crl = /path/to/crl.pem
|
||||||
|
|
||||||
# If you have a certificate from a CA that provides an OCSP
|
# If you have a certificate from a CA that provides an OCSP
|
||||||
@@ -819,7 +821,7 @@ $ certtool --generate-crl --load-ca-privkey ca-key.pem \
|
|||||||
--template crl.tmpl --outfile crl.pem
|
--template crl.tmpl --outfile crl.pem
|
||||||
@end example
|
@end example
|
||||||
After that you may want to notify ocserv of the new CRL by using
|
After that you may want to notify ocserv of the new CRL by using
|
||||||
the HUP signal.
|
the HUP signal, or wait for it to reload it.
|
||||||
|
|
||||||
When there are no revoked certificates an empty revocation list
|
When there are no revoked certificates an empty revocation list
|
||||||
should be generated as follows.
|
should be generated as follows.
|
||||||
|
|||||||
Reference in New Issue
Block a user