Community discussions

MikroTik App
 
krwi
just joined
Topic Author
Posts: 9
Joined: Mon Aug 21, 2017 3:49 pm

IPSec ignoring CRL

Fri Aug 25, 2017 8:34 pm

I have IPSec VPN setup with IKEv2 and RSA sign. auth. method, PKI infrastructure was on different linux host. I have imported CA cert on MikroTik and added CRL url. All works fine except CRL: revoked certificates still can connect. Its a bug or I missed something?
On Certificates->CRL WinBox window correct number of revoked certificates are shown so MiroTik dowloaded CRL correctly but not using it during cert validation.
crl.jpeg
You do not have the required permissions to view the files attached to this post.
 
krwi
just joined
Topic Author
Posts: 9
Joined: Mon Aug 21, 2017 3:49 pm

Re: IPSec ignoring CRL

Fri Aug 25, 2017 8:36 pm

I have latest RouterOS v6.40.2.