Actions
Bug #8387
closed
Cannot use large CRLs
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Certificates
Target version:
-
Start date:
03/23/2018
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.4.2_1
Affected Architecture:
Description
Attempting to import CRL data for certificate authorities via the "System > Cert. Manager > Certificate Revocation" web interface .
Using the following command to create the X.509 CRL formatted data:
curl https://pki.<redacted>CA.crl | openssl crl -inform DER -out <redacted>_ca_crl.pem
The resulting file appears to be of the correct format as it beings with the BEGIN X509 CRL header and ends with the END X509 CRL footer. The data size is 28M. I am able to paste it into the CRL data field, but I get a "504 Gateway Time-out" a few minutes after clicking "Save".
A message similar to this appears in /var/log/system.log:
Mar 20 14:22:25 firewall firewall nginx: 2018/03/20 14:22:25 [error] 65974#100411: *
Actions