NextGen Knowledge Center

CRL Revocation Checking

If enabled, Certificate Revocation List (CRL) checking will be done on all local and remote certificates. The issuer of the CRL must be included in your trusted certificates as well in order to verify signatures.

CRL Enabled option on the SSL Settings window

Select the wrench icon to open the CRL Settings window:

CRL Settings window with CRL URI field and Hard Fail option

  • CRL URI: This setting is optional. If specified, this URI will be used in addition to any certificate CRL Distribution Points when checking for revocation. HTTP, File FTP, or LDAP URIs are supported.
  • Hard Fail: When enabled, this connector will depend on the remote CRL provider. If a CRL cannot be downloaded or verified for any reason, all connections will fail revocation checks.