Thanks Mark. I would like to deny access if an unknown response is received.
From: Mark Thomas
Sent: Thursday, July 11, 2019 12:59 PM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 11/07/2019 17:46, Michael Magnuson wrote
The OCSP function is working as expected for both "good" and "revoked"
responses. However, I find that it also allows "unknown" responses. Is the
"unknown" response behavior adjustable?
Thanks,
Mike
____
From: Michael Magnus
Thomas
Sent: Tuesday, June 25, 2019 12:41 PM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 25/06/2019 20:22, Michael Magnuson wrote:
>
>
> Mark, thanks for the further clarification. With that setup, it prompts for
> the smart card PIN and yo
no OCSP action.
From: Mark Thomas
Sent: Tuesday, June 25, 2019 11:33 AM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 25/06/2019 19:24, Michael Magnuson wrote:
>
>
> Oh I see. I was trying to use those fields for
25/06/2019 18:04, Michael Magnuson wrote:
>
>
> Mark, are you defining your server SSL certificate someplace else, other than
> within the connector in server.xml?
No.
> From your example connector config, I'm not seeing it defined.
Server key is defined b
e.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 21/06/2019 17:12, Michael Magnuson wrote:
>
>
> Can I point certificateRevocationListFile= to an empty file so it always
> reverts to OCSP?
Just don't specify it at all.
I've co
7;t in
the CRL.
Mark
>
>
> From: Mark Thomas
> Sent: Friday, June 21, 2019 8:44 AM
> To: users@tomcat.apache.org
> Subject: Re: OCSP Connector on Tomcat 8.5 not working
>
> On 21/06/2019 16:31, Michael Magnuson wrote:
>> Hmm. It's st
Thanks. Is that setup using a CRL instead of OCSP?
From: Mark Thomas
Sent: Friday, June 21, 2019 8:44 AM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 21/06/2019 16:31, Michael Magnuson wrote:
> Hmm. It's s
Mark Thomas wrote:
> On 20/06/2019 18:27, Michael Magnuson wrote:
>> Thanks Mark. A couple clarifications on your example first. You don't list
>> the clientAuth= attribute. I assume this was a simple oversight.
>
> It is replaced by certificateVerification="req
attribute, is the correct syntax "require" or
"required"?
Thanks,
Mike
From: Mark Thomas
Sent: Thursday, June 20, 2019 10:00 AM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 20/06/2019 17:24, Michael M
uot; from "want" has no effect either way.
Mike
From: Mark Thomas
Sent: Thursday, June 20, 2019 9:02 AM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
On 20/06/2019 16:19, Michael Magnuson wrote:
> Mark,
>
Thomas
Sent: Thursday, June 20, 2019 3:33 AM
To: users@tomcat.apache.org
Subject: Re: OCSP Connector on Tomcat 8.5 not working
Tomcat version?
Tomcat Native version?
Mark
On 19/06/2019 23:46, Michael Magnuson wrote:
> Hi,
>
> I'm running Tomcat 8.5 on RHEL 7.6. I'm succes
Hi,
I'm running Tomcat 8.5 on RHEL 7.6. I'm successfully using client certificate
validation from the smart card, but I would like to add client-cert OCSP
revocation checking. I *think* I've set up the connector correctly in the
server.xml file, but although the server starts and operates fin
13 matches
Mail list logo