mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
updated documentation for CRL reload
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
* Version 0.10.9 (unreleased)
|
||||
- When compiled with GnuTLS 3.4 automatically sort the certificate list
|
||||
to be imported.
|
||||
- Reload the CRL on during periodic maintaince if its modification time
|
||||
changes.
|
||||
|
||||
|
||||
* Version 0.10.8 (released 2015-09-04)
|
||||
|
||||
+3
-1
@@ -213,7 +213,9 @@ cert-user-oid = 0.9.2342.19200300.100.1.1
|
||||
#cert-group-oid = 2.5.4.11
|
||||
|
||||
# The revocation list of the certificates issued by the 'ca-cert' above.
|
||||
# See the manual to generate an empty CRL initially.
|
||||
# See the manual to generate an empty CRL initially. The CRL will be reloaded
|
||||
# periodically when ocserv detects a change in the file. To force a reload use
|
||||
# SIGHUP.
|
||||
#crl = /path/to/crl.pem
|
||||
|
||||
# Uncomment this to enable compression negotiation (LZS, LZ4).
|
||||
|
||||
+4
-2
@@ -271,7 +271,9 @@ mobile-dpd = 1800
|
||||
try-mtu-discovery = false
|
||||
|
||||
# The revocation list of the certificates issued by the 'ca-cert' above.
|
||||
# See the manual to generate an empty CRL initially.
|
||||
# See the manual to generate an empty CRL initially. The CRL will be reloaded
|
||||
# periodically when ocserv detects a change in the file. To force a reload use
|
||||
# SIGHUP.
|
||||
#crl = /path/to/crl.pem
|
||||
|
||||
# If you have a certificate from a CA that provides an OCSP
|
||||
@@ -819,7 +821,7 @@ $ certtool --generate-crl --load-ca-privkey ca-key.pem \
|
||||
--template crl.tmpl --outfile crl.pem
|
||||
@end example
|
||||
After that you may want to notify ocserv of the new CRL by using
|
||||
the HUP signal.
|
||||
the HUP signal, or wait for it to reload it.
|
||||
|
||||
When there are no revoked certificates an empty revocation list
|
||||
should be generated as follows.
|
||||
|
||||
Reference in New Issue
Block a user