public inbox for kernel-tls-handshake@lists.linux.dev
 help / color / mirror / Atom feed
* [PATCH 0/3] Add CRL checking to server and client
@ 2025-06-11  7:09 Rik Theys
  2025-06-11  7:09 ` [PATCH 1/3] Add server-side CRL checking Rik Theys
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Rik Theys @ 2025-06-11  7:09 UTC (permalink / raw)
  To: kernel-tls-handshake; +Cc: Rik Theys

These patches add CRL checking to the TLS client and server code.

It introduces an x509.crl configuration option that specifies the
location of a CRL in PEM format.

The CRL (certificate revocation list) can be used by an administrator
to block access to certificates that should no longer be trusted
for some reason.

See https://github.com/oracle/ktls-utils/issues/103

Rik Theys (3):
  Add server-side CRL checking
  Add client-side CRL checking
  Add x509.crl option to man page.

 src/tlshd/client.c       | 28 +++++++++++++++++
 src/tlshd/config.c       | 66 ++++++++++++++++++++++++++++++++++++++++
 src/tlshd/server.c       | 14 +++++++++
 src/tlshd/tlshd.conf.man |  9 +++++-
 src/tlshd/tlshd.h        |  2 ++
 5 files changed, 118 insertions(+), 1 deletion(-)

-- 
2.49.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2025-06-18 12:37 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-06-11  7:09 [PATCH 0/3] Add CRL checking to server and client Rik Theys
2025-06-11  7:09 ` [PATCH 1/3] Add server-side CRL checking Rik Theys
2025-06-11  7:09 ` [PATCH 2/3] Add client-side " Rik Theys
2025-06-11  7:09 ` [PATCH 3/3] Add x509.crl option to man page Rik Theys
2025-06-11 13:49 ` [PATCH 0/3] Add CRL checking to server and client Chuck Lever
2025-06-12 14:28   ` Long Xin
2025-06-16 14:39     ` Chuck Lever
2025-06-17  5:22       ` Rik Theys
2025-06-18 12:37         ` Chuck Lever

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox