Re: certificate revocation check for PKINIT in KDC

2017-08-10 Thread tseegerkrb
On 10.08.2017 06:55, Greg Hudson wrote: > On 08/08/2017 02:11 PM, Jim Shi wrote: >> Is there any document how to configure certificate revocation check for >> PKINIT in KDC? > I believe the only documentation we have for this is in the man page for > kdc.conf, which says: > > pkinit_revoke > Spe

Re: certificate revocation check for PKINIT in KDC

2017-08-10 Thread Jim Shi
Greg: I thought ocsp was supported. Good to know it is not. Thorsten: Thanks for the info. Jim > On Aug 10, 2017, at 3:53 AM, tseegerkrb wrote: > > On 10.08.2017 06:55, Greg Hudson wrote: >> On 08/08/2017 02:11 PM, Jim Shi wrote: >>> Is there any document how to configure certificate r

Re: certificate revocation check for PKINIT in KDC

2017-08-10 Thread Robbie Harwood
Jim Shi writes: > Greg: > I thought ocsp was supported. Good to know it is not. We will be clarifying this with the 1.16 release [1]. Thanks, --Robbie 1: https://github.com/krb5/krb5/pull/683/ signature.asc Description: PGP signature Kerberos