Certificate Revocation Lists
The Certificate Revocation List (CRL) can be used to verify that the certificates used byare valid
and have not been compromised. A CRL is uploaded to and then associated with one or more
clusters in the cluster specific context. Whenever a certificate is used to authenticate a connection
to the cluster, the CRL is checked to make sure the certificate being used has not been revoked.
Equalizer provides support for Certificate Revocation Lists (CRLs) using a central CRL store to
which CRLs can be uploaded and then associated with as many clusters as required.
If a CRL attached to a cluster was generated by a Certificate Authority (CA) different from
the CA used to generate a client certificate presented when connecting to the cluster, an
error will occur, The CRL and client certificate must be signed by the same CA.
Installing a Certificate Revocation List (CRL)
Installed CRLs will be displayed in an accordion style list. Click on each list item to expand it and
display the contents of the CRL.
Proceed with the following to install a CRL using the GUI:
1. Click on the host name at the top of the left navigational pane and then click on
Global CRL
to display the following.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
245
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......