Changes in the way gateway processes Certificate Revocation List (CRL) when cache expires

Document ID : KB000107093
Last Modified Date : 19/07/2018
Show Technical Document Details
Question:
What are the Changes in the way gateway processes Certificate Revocation List (CRL) when cache expires
Answer:
 From 9.2 CR10 and 9.3 CR04 onwards, a new cluster wide property (CWP) is going to be introduced. pkix.crl.invalidateCrlCacheOnNextUpdate will by default be set to false so that existing gateway users are not affected.
 
 When pkix.crl.invalidateCrlCacheOnNextUpdate is set to true, the gateway will invalidate the CRL on next update.
 
 The log messages in the ssg logs have also been enhanced to include extra log if the CRL is beyond the validity period.
logger.severe("CRL [URL] is beyond validity period, hence no longer used for revocation prior to the CertPathValidatorException
 
 See following for full list of CWP’s for certificate validation.
https://docops.ca.com/ca-api-gateway/9-3/en/reference/gateway-cluster-properties/certificate-validation-cluster-properties/