Skip to main content
zzarrouk
Staff
Staff
July 1, 2019

Technical Tip: FortiGate strict CRL check

  • July 1, 2019
  • 0 replies
  • 10217 views

Description

This article describes how to make the FortiGate denies access to a website having a revoked certificate.
 
Useful links:
 
 - Fortinet Documentation here.


Solution

By keeping the default configuration, the FortiGate allows access to external resources possessing revoked certificate.


FortiGate does not perform a strict CRL check by default.

 
The following configuration will make the FortiGate perform a strict CRL check:
config vpn certificate setting
    set ocsp-status enable
    set ssl-ocsp-status enable
    set ssl-ocsp-option certificate
    set strict-crl-check enable
    set strict-ocsp-check enable
end
In order to test the configuration, access here.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!