【问题标题】:Tomcat 8 - Certificate Revocation List checking and cachingTomcat 8 - 证书吊销列表检查和缓存
【发布时间】:2017-07-05 19:09:04
【问题描述】:

我需要为 SSL/TLS HTTPS 连接启用“证书吊销列表”检查并在给定时间内缓存列表。 “分发点”位于信任库接受的根证书中。我希望,tomcat 的 bin/setenv.sh 中的以下行启用检查:

export JAVA_OPTS="-Dcom.sun.security.enableCRLDP=true"
  • 这是正确的吗?
  • 如何配置缓存?

谢谢

【问题讨论】:

  • @SScholl 找到任何配置了吗?
  • @harish chava 不幸的是没有。

标签: tomcat ssl caching ssl-certificate client-certificates


【解决方案1】:

您也可以添加选项:

-Dcom.sun.net.ssl.checkRevocation=true

请注意,这样做会影响 JSSE 的性能。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2016-11-13
    • 2018-04-21
    • 2018-01-15
    • 2018-12-26
    • 2021-12-18
    • 1970-01-01
    • 1970-01-01
    • 2011-07-18
    相关资源
    最近更新 更多