Hello.
Tell me please,
We are trying to revoke an ipsec certificate using a CRL updated via SCEP.
The CRL is added and updated correctly, but the certificate remains in Valid status.
How can I revoke a certificate for ipsec vpn using a crl list?
And why doesn’t the fortigate change the certificate to Invalid status if its serial number is in the crl?
Hello,
To revoke an IPsec certificate using a Certificate Revocation List (CRL) updated via SCEP,
Thanks for the answer.
We will import the CRL list to the device. But the certificate that we want to revoke has the Valid status.
How can we change the status? or how will fortigate understand that the certificate has been revoked and cannot be used for ipsec.
In fortios 7.2 there is no strict-crl-check parameter, from the article : https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-strict-CRL-check/ta-p/190669?ext...
User | Count |
---|---|
2276 | |
1236 | |
772 | |
452 | |
398 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.