Security
Polycom, Inc.
153
Configure Certificate Revocation Settings
When certificate validation is enabled (refer to
Configure Certificate Validation Settings
), the RealPresence
Group system tries to validate the peer certificate chain on secure connection attempts for the applicable
network services.
Part of the validation process includes a step called revocation checking. This type of check involves
consulting with the CA that issued the certificate in question to see whether the certificate is still active or
has been revoked for some reason. Revoked certificates are considered invalid because they might have
been compromised in some way or improperly issued, or for other similar reasons. The CA is responsible
for maintaining the revocation status of every certificate that it issues. The RealPresence Group system can
check this revocation status by using either of the following methods:
●
Certificate revocation lists (CRLs). A CRL is a list of certificates that have been revoked by the CA.
A CRL must be installed on the RealPresence Group system for each CA whose certificate has been
installed on the system.
●
The Online Certificate Status Protocol (OCSP). OCSP allows the RealPresence Group system to
contact an OCSP responder, which is a network server that provides real-time certificate status
through a query/response message exchange.
You must configure the RealPresence Group system to use the revocation method most appropriate for
your environment.
To use CRLs:
1
Go to Admin Settings > Security > Certificates > Revocation.
2
Configure these settings on the Revocation page and click Save.
You can also view automatically and manually downloaded CRLs on this page. To remove a CRL from the
list, click Remove.
Note: CRL download limitation
The RealPresence Group systems automatically download CRLs from the Certificate Authorities
(CAs) that make CRLs available for retrieval by HTTP.
However, for CAs that do not allow HTTP retrieval of CRLs, the RealPresence Group system
administrator is responsible for manually installing and updating CRLs ahead of their expiration. It is
extremely important that CRLs be kept up to date.
Setting
Description
Revocation Method
Select the CRL method.
Allow Incomplete
Revocation Checks
When this field is enabled, a certificate in the chain is verified without a revocation
status check if no corresponding CRL for the issuing CA is installed.
The RealPresence Group system assumes that the lack of a CRL means the
certificate is not revoked. If a CRL is installed, the system performs a revocation
check when validating the certificate.
Add CRL
1
Click Browse to search for and select a CRL.
2
Click Open to add the CRL to the list.