CRL and OCSP for trusted certificates are not checked.
All Replies
-
Hi @ThomasW
Can you provide your screenshot of configuration and more detailed test procedure to us ? (p.s. if there are screenshots would be better.)
If your ATP device does not validate client certificates that are signed by root CA, is there any error message appears?
Thanks
See how you've made an impact in Zyxel Community this year!
0 -
Hi @Zyxel_Jeff
Below is screenshot of Object -> Certificate -> "Trusted certifications" screen.- I've imported here the Root CA certificate of my private authority center and checked following option:
2. I've checked "Authenticate Client Certificates" in System -> WWW
3. I've created a client certificate and signed it by the same Root CA. Certificate is added to "Personal" directory in windows certificate store.
4. I've tested if it is possible to login to ATP. (Pointed web browser to external IP address of ATP device) connection is established and it is possible to login to ATP.
5. I've revoked client certificate in Root CA and published CRL
6. I've tested if access to ATP is revoked. Unfortunately, the client with revoked certificate still can login to ATP device using web browser.
0 -
Hi @Zyxel_Jeff
Below is screenshot of Object -> Certificate -> "Trusted certifications" screen.- I've imported here the Root CA certificate of my private authority center and checked following option:
2. I've checked "Authenticate Client Certificates" in System -> WWW
3. I've created a client certificate and signed it by the same Root CA. Certificate is added to "Personal" directory in windows certificate store.
4. I've tested if it is possible to login to ATP. (Pointed web browser to external IP address of ATP device) connection is established and it is possible to login to ATP.
5. I've revoked client certificate in Root CA and published CRL
6. I've tested if access to ATP is revoked. Unfortunately, the client with revoked certificate still can login to ATP device using web browser.
Thansk0 -
Hi is it any update on this? I still cannot use CRL list in atp device, any revoked certificate is accepted by device and users with revoked certificate can access device.0
-
Hi @ThomasWCould you provide the device config file to us via private message for further check?We would like to check the part of certificate authentication.
Thanks.See how you've made an impact in Zyxel Community this year!
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight