revoking an certificate should NOT delete the R line from the pki/index.txt #942
Unanswered
emacsimize
asked this question in
Help
Replies: 3 comments 4 replies
-
I have tested your theory and you are totally correct. Deleting the |
Beta Was this translation helpful? Give feedback.
4 replies
-
FTR: A Certificate Revocation List is only a List of |
Beta Was this translation helpful? Give feedback.
0 replies
-
PR welcome to fix this 🙂 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi
I was testing the revocation function the script and figured out that if you revoke more than one certificate the other won't be in the included in the generated crl.pem
Steps to reproduce
Reason for this is that openvpn-install.sh at
openvpn-install/openvpn-install.sh
Line 1190 in 506c86f
is deleting the R line from the index.txt . This is in my opinion very bad and results in a massive security issue. Since all previously revoked certificate would now be allowed to connect again.
second test:
use the script to
There is always the case that I'm talking totally bullshit and I'm all wrong but if this isn't the case. Please fix it ASAP.
cheers
Beta Was this translation helpful? Give feedback.
All reactions