Skip to content

Commit 5f3db64

Browse files
committed
httpd: disable CRL checking
It was resulting in "tlsv1 alert unknown CA" errors for the certs (multiple) people were using. Only setting it to "none" worked; "chain no_crl_for_cert_ok" didn't work; "leaf no_crl_for_cert_ok" didn't work.
1 parent 166f324 commit 5f3db64

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

docker/apache.conf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,8 +26,9 @@ WSGIDaemonProcess topomerge home=/app
2626

2727
SSLCACertificatePath /etc/grid-security/certificates
2828
SSLCARevocationPath /etc/grid-security/certificates
29-
SSLCARevocationCheck chain
29+
#SSLCARevocationCheck chain
3030
#SSLCARevocationCheck chain no_crl_for_cert_ok
31+
SSLCARevocationCheck none
3132

3233
<Directory /app>
3334
Require all granted

0 commit comments

Comments
 (0)