Re: OCSP Connector on Tomcat 8.5 not working

2019-07-11 Thread Michael Magnuson
Thanks Mark. I would like to deny access if an unknown response is received. From: Mark Thomas Sent: Thursday, July 11, 2019 12:59 PM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 11/07/2019 17:46, Michael Magnuson wrote

Re: OCSP Connector on Tomcat 8.5 not working

2019-07-11 Thread Michael Magnuson
The OCSP function is working as expected for both "good" and "revoked" responses. However, I find that it also allows "unknown" responses. Is the "unknown" response behavior adjustable? Thanks, Mike ____ From: Michael Magnus

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-28 Thread Michael Magnuson
Thomas Sent: Tuesday, June 25, 2019 12:41 PM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 25/06/2019 20:22, Michael Magnuson wrote: > > > Mark, thanks for the further clarification. With that setup, it prompts for > the smart card PIN and yo

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-25 Thread Michael Magnuson
no OCSP action. From: Mark Thomas Sent: Tuesday, June 25, 2019 11:33 AM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 25/06/2019 19:24, Michael Magnuson wrote: > > > Oh I see. I was trying to use those fields for

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-25 Thread Michael Magnuson
25/06/2019 18:04, Michael Magnuson wrote: > > > Mark, are you defining your server SSL certificate someplace else, other than > within the connector in server.xml? No. > From your example connector config, I'm not seeing it defined. Server key is defined b

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-25 Thread Michael Magnuson
e.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 21/06/2019 17:12, Michael Magnuson wrote: > > > Can I point certificateRevocationListFile= to an empty file so it always > reverts to OCSP? Just don't specify it at all. I've co

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-21 Thread Michael Magnuson
7;t in the CRL. Mark > > > From: Mark Thomas > Sent: Friday, June 21, 2019 8:44 AM > To: users@tomcat.apache.org > Subject: Re: OCSP Connector on Tomcat 8.5 not working > > On 21/06/2019 16:31, Michael Magnuson wrote: >> Hmm. It's st

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-21 Thread Michael Magnuson
Thanks. Is that setup using a CRL instead of OCSP? From: Mark Thomas Sent: Friday, June 21, 2019 8:44 AM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 21/06/2019 16:31, Michael Magnuson wrote: > Hmm. It's s

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-21 Thread Michael Magnuson
Mark Thomas wrote: > On 20/06/2019 18:27, Michael Magnuson wrote: >> Thanks Mark. A couple clarifications on your example first. You don't list >> the clientAuth= attribute. I assume this was a simple oversight. > > It is replaced by certificateVerification="req

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-20 Thread Michael Magnuson
attribute, is the correct syntax "require" or "required"? Thanks, Mike From: Mark Thomas Sent: Thursday, June 20, 2019 10:00 AM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 20/06/2019 17:24, Michael M

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-20 Thread Michael Magnuson
uot; from "want" has no effect either way. Mike From: Mark Thomas Sent: Thursday, June 20, 2019 9:02 AM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working On 20/06/2019 16:19, Michael Magnuson wrote: > Mark, >

Re: OCSP Connector on Tomcat 8.5 not working

2019-06-20 Thread Michael Magnuson
Thomas Sent: Thursday, June 20, 2019 3:33 AM To: users@tomcat.apache.org Subject: Re: OCSP Connector on Tomcat 8.5 not working Tomcat version? Tomcat Native version? Mark On 19/06/2019 23:46, Michael Magnuson wrote: > Hi, > > I'm running Tomcat 8.5 on RHEL 7.6. I'm succes

OCSP Connector on Tomcat 8.5 not working

2019-06-19 Thread Michael Magnuson
Hi, I'm running Tomcat 8.5 on RHEL 7.6. I'm successfully using client certificate validation from the smart card, but I would like to add client-cert OCSP revocation checking. I *think* I've set up the connector correctly in the server.xml file, but although the server starts and operates fin