Skip to content

Problem when using CRL validation on an Application domain #11

@TakahiroIchi

Description

@TakahiroIchi

Hi guys,

I want to configure CRL validation on an Application domain in IBM DataPower Gateway.
I'm using IBM DataPower Gateway Version 7.5.1.2

I followed this tutorial: CRLs in DataPower

I have configured the CRL Retrieval object in the default domain and the getting CRL has succeeded.
I found the following message in the default log.

[default log message] 0x806000a0 Successfully fetched valid CRL from HTTP source 'QTSP01_CRL_Retrieval

I configured Crypto Validation on an Application domain as Require CRL parameter is enabled.
But, the API request with client certificate could not access to an Application domain.
I found the following error message in the default log.

[default log error message] 0x81200026 SSL handshake certificate validation error with validation credentials QTSP01_CrytoValidation_CustomAppFW: unable to get certificate CRL

Since CRL Retrieval doesn't specify Crypto Validation on an Application domain, I configured Crypto Validation on each domain.

ws000016

[Crypto Valication on default domain]
image

[Crypto Valication on an application domain]
image

Cloud you tell me how to configure CRL validation on an Application domain.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions