updated documentation for CRL reload

This commit is contained in:
Nikos Mavrogiannopoulos
2015-09-14 17:59:58 +02:00
parent 090c51cf1f
commit f2caadbe83
3 changed files with 9 additions and 3 deletions
+2
View File
@@ -1,6 +1,8 @@
* Version 0.10.9 (unreleased)
- When compiled with GnuTLS 3.4 automatically sort the certificate list
to be imported.
- Reload the CRL on during periodic maintaince if its modification time
changes.
* Version 0.10.8 (released 2015-09-04)
+3 -1
View File
@@ -213,7 +213,9 @@ cert-user-oid = 0.9.2342.19200300.100.1.1
#cert-group-oid = 2.5.4.11
# The revocation list of the certificates issued by the 'ca-cert' above.
# See the manual to generate an empty CRL initially.
# See the manual to generate an empty CRL initially. The CRL will be reloaded
# periodically when ocserv detects a change in the file. To force a reload use
# SIGHUP.
#crl = /path/to/crl.pem
# Uncomment this to enable compression negotiation (LZS, LZ4).
+4 -2
View File
@@ -271,7 +271,9 @@ mobile-dpd = 1800
try-mtu-discovery = false
# The revocation list of the certificates issued by the 'ca-cert' above.
# See the manual to generate an empty CRL initially.
# See the manual to generate an empty CRL initially. The CRL will be reloaded
# periodically when ocserv detects a change in the file. To force a reload use
# SIGHUP.
#crl = /path/to/crl.pem
# If you have a certificate from a CA that provides an OCSP
@@ -819,7 +821,7 @@ $ certtool --generate-crl --load-ca-privkey ca-key.pem \
--template crl.tmpl --outfile crl.pem
@end example
After that you may want to notify ocserv of the new CRL by using
the HUP signal.
the HUP signal, or wait for it to reload it.
When there are no revoked certificates an empty revocation list
should be generated as follows.