« Return to Thread: X509 Authentication + revoked certificates

Re: X509 Authentication + revoked certificates

by Romain Bourgue :: Rate this Message:

Reply to Author | View in Thread

With cas-server-support-x509, a certificate is indeed treated as valid :
  1- if it matches a trusted issuer dn (subjectDnPattern)...
  2- ...within a specified range of intermediate CAs (maxPathLength),
  3- if it's not expired (and already valid),
  4- if its key usage validate a optionally specified one.

but it doesn't check any CertificateRevocationList (CRL)  (yet?).

If you want this check, the easiest way is to rely on mod_ssl installed on a
apache frontal webserver. The SSLCARevocationPath directive allows you specify a
list of CRLs the certificate will be checked against.

You can also develop your own authentication handler....


Romain

Pavlos Drandakis a écrit :

> Hello all,
>
>  From what I understand, a certificate is treated as valid if current
> time (when checking) is between certificate's creation and expiration
> time. So if a revoked certificate has not expired yet, is considered
> valid and access is granted, when using X509 authentication. Is there
> any way to prevent users from logging into CAS when presenting revoked
> certificates?
>
> Thanks,
>
> Pavlos
>
> (Server Configuration: CAS 3.2.1, Tomcat 6.0.14 with APR support)
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> cas-dev mailing list
> cas-dev@...
> http://tp.its.yale.edu/mailman/listinfo/cas-dev
_______________________________________________
cas-dev mailing list
cas-dev@...
http://tp.its.yale.edu/mailman/listinfo/cas-dev

 « Return to Thread: X509 Authentication + revoked certificates

LightInTheBox - Buy quality products at wholesale price