cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1024
Views
0
Helpful
0
Replies

CRL check Question

ahmede1
Level 1
Level 1

According to this document

 

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_pki/configuration/xe-3s/sec-pki-xe-3s-book/sec-cfg-auth-rev-cert.html#GUID-4CED9DF7-D830-4EEA-8389-7D7734AA3614

 

"CAs publish new CRLs periodically or when a certificate for which the CA is responsible has been revoked. By default, a new CRL is downloaded after the currently cached CRL expires. An administrator may also configure the duration for which CRLs are cached in router memory or disable CRL caching completely. The CRL caching configuration applies to all CRLs associated with a trustpoint.

When the CRL expires, the router deletes it from its cache. A new CRL is downloaded when a certificate is presented for verification; however, if a newer version of the CRL that lists the certificate under examination is on the server but the router is still using the CRL in its cache, the router does not know that the certificate has been revoked. The certificate passes the revocation check even though it should have been denied"

 

We want to avoid this situation "if a newer version of the CRL that lists the certificate under examination is on the server but the router is still using the CRL in its cache, the router does not know that the certificate has been revoked. The certificate passes the revocation check even though it should have been denied". We are trying to get Real time check, our servers don't support OCSP.

 

My question is, if I disable the CRL check using "crl-cache none", will that help? Does it have any side effects? Does that overwrite the caching time set by CA?

 

Thank you  

0 Replies 0