Enabling CRL Verification

IMPORTANT  Certificate Revocation and CDP Monitoring is a feature that must be enabled when you install Trust Protection Platform in the Venafi Configuration Console. This module is disabled by default if you are upgrading from a version of Trust Protection Platform prior to 19.2. You will need to enable it manually on at least one engine if you want to do revocation checking and CDP monitoring.

When you enable this module on multiple engines, all must have equal access to all CDP and OCSP endpoints. If a particular engine does not have the same network access as other engines, then the service module should be disabled on that engine with restricted access.

If you see sporadic network access or "unable to connect" statuses for your CDP or OCSP endpoints (either in the Roots tree, or in the logs), it is likely that one of your engines does not have access to reach those endpoints.

CDP Monitoring and Revocation Checking does not honor engine partitioning in the Policy tree.

On a new installation, by default, the CRL Verification Service is enabled to verify the status of Certificate Revocation Lists (CRLs). Trust Protection Platform verifies CRLs on a configurable basis (at least every 24 hours). It is possible to enable the CRL Verification Service for all engines or on individual Trust Protection Platform engines.

You can also enable or disable individual CRL Distribution Points (CDPs). All CDPs are enabled by default when they are added automatically.

NOTE  It is not recommended to use the HTTPS protocol to update your CDPs. CDP servers are typically configured to use HTTP. If a CRL retrieval fails, verify that you are using HTTP.

Related Topics Link IconRelated Topics