cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
726
Views
0
Helpful
2
Replies

Multiple CRLs

obrigg
Cisco Employee
Cisco Employee

Dear ISE team,

A customer has two CRL servers for redundancy reasons.

Is it possible to direct ISE to two different URLs to download the CRL from?

 

Regards,

Oren.

 

Screen Shot 2019-09-02 at 21.48.43.png

 

1 Accepted Solution

Accepted Solutions

Colby LeMaire
VIP Alumni
VIP Alumni

With OCSP, you can have a primary and secondary.  Not with CRL.  I would recommend using OCSP if at all possible.  It is more efficient and doesn't require ISE to download an entire CRL on an ongoing basis.

View solution in original post

2 Replies 2

Colby LeMaire
VIP Alumni
VIP Alumni

With OCSP, you can have a primary and secondary.  Not with CRL.  I would recommend using OCSP if at all possible.  It is more efficient and doesn't require ISE to download an entire CRL on an ongoing basis.

Arne Bier
VIP
VIP

If you're lucky enough to have a load balancer, then put up a VIP and have the load balancer farm out the CRL download requests to the servers. Perhaps you could even play some tricks with your DNS - use a CNAME that points to both of your servers. That would ensure that in the event of the first A record not responding, the second one would be used.  Works quite well in other use cases where we need to use a single FQDN for a system with multiple backend hosts.