CRL validation

irfan sarwar isarwar3334 at gmail.com
Thu Aug 22 16:31:31 EDT 2019


Hi,

How do I ' Validate the certificates used in the assertion using
Certificate Revocation Lists (CRLs), as well as checking expiration'?

I've looked at the documentation here and looking to use the dynamic or
staticpkix engines:
https://wiki.shibboleth.net/confluence/display/SP3/PKIX+and+StaticPKIX+TrustEngines


<TrustEngine type="PKIX"/>
 Setting my TrustEngine to PKIX doesn't seem to do anything with CRL
(looking at the shibd.log  'debug logs')
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190822/2db251f3/attachment.html>


More information about the users mailing list