CRL Distribution Point Extension CRL Checker
Description
Uses the CRL distribution point extension of the certificate to determine which CRL to use. If a certificate does not provide the CRL distribution point extension, the fallbackChecker is used to check the certificate. Otherwise the CRL is obtained by the CRL obtainer and used to check the certificate. As long as the CRL is not expired, the CRL is cached in memory.
May be used by
OAuth 2.0 Client mTLS Authentication Caching Certificate Status Checker STET PSD2 Authenticator NextGenPSD2 Certificate Authenticator Certificate Authenticator Certificate Authenticator Certificate Token Authenticator HTTP Signature Verification Credential Extractor Client Certificate (X.509) Request Authentication
Properties
CRL Obtainer (
crlObtainer) Description
Accesses newer versions of the CRL.
Attributes
Plugin-Link
Optional
Assignable plugins
Fallback Checker (
fallbackChecker) Description
This checker is used when the CRL distribution point extension is not available on the certificate.
Attributes
Plugin-Link
Optional
Assignable plugins
Eagerly Loaded URLs (
eagerlyLoadedURLs) Description
The CRLs located at these URLs are downloaded upon startup of Airlock IAM. Otherwise a CRL is downloaded once the first certificate check uses the CRL, which can cause delays during the check.
Attributes
String-List
Optional
Keystore Config (
keystoreConfig) Description
The keystore containing the CA certificate to verify the signature of the CRL.
Attributes
Plugin-Link
Optional
Assignable plugins
Factory (
factory) Description
Creates a friendly representation of the X509 Certificate. Normally, the default plugin should be used.
Attributes
Plugin-Link
Optional
Assignable plugins
CRL Cache (
cacheRefreshInterval) Description
Defines the interval in minutes in which the internal cache is checked for expired CRLs, which are then updated asynchronously. Note that this has option has no security consequences, since an expired CRL is also updated before a check. However, this might cause delays.
Attributes
Integer
Optional
Default value
1
YAML Template (with default values)
type: MultiIssuerCRLChecker
id: MultiIssuerCRLChecker-xxxxxx
displayName:
comment:
properties:
cacheRefreshInterval: 1
crlObtainer:
eagerlyLoadedURLs:
factory:
fallbackChecker:
keystoreConfig: