Displaying 4 results from an estimated 4 matches for "mycrl".
Did you mean:
mycol
2017 Sep 21
2
Revocation with CRL doesn't work for smartcards
...e a smartcard which is revoked in the Certificate Revocation List
(CRL) but I can still login. Seams like the CRL check is not performed. Any
known bug around this?
Server setup:
- Samba 4.4 on Debian as AD DC
- Created domain MYDOM
- smb.conf (extract):
tls enabled = yes
tls crlfile = tls/mycrl.pem (default is to look under private/ folder)
Client setup:
- Windows 7 machine as client
- Joined to the MYDOM domain
- Login ok with both username/password and smartcards
Smart card:
- Principal name test123 at mydom.com (extended attribute)
- Certificate with serial number 0x12ab
CRL:
- In f...
2017 Sep 21
2
Revocation with CRL doesn't work for smartcards
...ill login. Seams like the CRL check is not performed.
> Any
> > known bug around this?
> >
> > Server setup:
> > - Samba 4.4 on Debian as AD DC
> > - Created domain MYDOM
> > - smb.conf (extract):
> > tls enabled = yes
> > tls crlfile = tls/mycrl.pem (default is to look under private/
> folder)
>
> > CRL:
> > - In file system:
> > ..../private/tls/mycrl.pem
> > > mycrl.pem
> > - Contains serial number 0x12ab
>
> The Heimdal code doing the SmartCard stuff doens't know about the
> smb.conf,...
2017 Sep 21
0
Revocation with CRL doesn't work for smartcards
...rformed.
> > Any
> > > known bug around this?
> > >
> > > Server setup:
> > > - Samba 4.4 on Debian as AD DC
> > > - Created domain MYDOM
> > > - smb.conf (extract):
> > > tls enabled = yes
> > > tls crlfile = tls/mycrl.pem (default is to look under private/
> > folder)
> >
> > > CRL:
> > > - In file system:
> > > ..../private/tls/mycrl.pem
> > > > mycrl.pem
> > > - Contains serial number 0x12ab
> >
> > The Heimdal code doing the SmartCard stu...
2017 Sep 22
2
Revocation with CRL doesn't work for smartcards
...t; known bug around this?
> > > >
> > > > Server setup:
> > > > - Samba 4.4 on Debian as AD DC
> > > > - Created domain MYDOM
> > > > - smb.conf (extract):
> > > > tls enabled = yes
> > > > tls crlfile = tls/mycrl.pem (default is to look under private/
> > > folder)
> > >
> > > > CRL:
> > > > - In file system:
> > > > ..../private/tls/mycrl.pem
> > > > > mycrl.pem
> > > > - Contains serial number 0x12ab
> > >
> >...