From Root CA to User Authorization in nginx+Apache. Part 2. Certificate Revocation, CRL, and OCSP

General News

Summary

This article explains how to manage certificate revocation in a PKI setup using OpenSSL, CRL, and OCSP. It walks through configuring X.509 extensions, revoking certificates, generating CRLs, and verifying certificates with OpenSSL commands. It also shows how to run an OCSP responder and expose CRL and OCSP services through nginx and Apache. The final section ties these pieces together for practical use in web server and TLS deployments.

Classifications

industries
No industries detected
applications
Web and Content Management

AskAI Classifications

Labels
Open Source Software Developer Tools Data Infrastructure Software

Linked Companies