[SR-Users] Q: about CRL list (TLS)

Vladimer Gabunia vgabunia at gh.ge
Sun Oct 25 13:10:26 CET 2015


hello all.
we compiled  kamailio with TLS Support.  but have next problem when using CRL Lits.
Our Certificate issuing scheme is follow:
Offline Root CA -> Enterprise SubCA -> Server and Phone Certificate
CRL list is signed by SubCA.
option  "require client certificate is enables (1) "
When we enable CRL list, phones are not registered.
CA file is offline RootCA   certificate in pem format.
We think that the reason is that СRL was signed by Subca or incorrect CRL format.
CRL is converted from MS CRL to PEM. (What is the format for the CRL)
maybe someone have experiance with similar scenarios?

thanks in advance!!

________________________________
[gh.ge]
ვლადიმერ გაბუნია
IT სამსახურის უფროსი
ტელ: (+995) 32 2505222 +8183
მობ: (995) 577 095333
შპს "ჯეო ჰოსპიტალს"
სათავო ოფისი
თბილისი 0160, ვაჟა-ფშაველას გამზ. № 16;
http://www.gh.ge <http://gh.ge>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.sip-router.org/pipermail/sr-users/attachments/20151025/77aec8fa/attachment.html>


More information about the sr-users mailing list