Bug 34285

Summary: Include CRL Distribution Points in Certificates
Product: UCS Reporter: Michael Grandjean <grandjean>
Component: SSLAssignee: UCS maintainers <ucs-maintainers>
Status: RESOLVED WONTFIX QA Contact:
Severity: enhancement    
Priority: P5 CC: best, gulden, stephan.hendl, steuwer
Version: UCS 4.2Flags: best: Patch_Available+
Target Milestone: ---   
Hardware: Other   
OS: Linux   
See Also: https://forge.univention.org/bugzilla/show_bug.cgi?id=41230
https://forge.univention.org/bugzilla/show_bug.cgi?id=49755
What kind of report is it?: Feature Request What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?: Yes
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional):
Max CVSS v3 score:
Attachments: Add crlDistributionPoints to certificates

Description Michael Grandjean univentionstaff 2014-03-07 12:18:09 CET
It is possible to include so-called "CRL distribution points" in Certificates. These contain an http or ldap URI pointing to the Certificate Revocation List (CRL):

https://www.openssl.org/docs/apps/x509v3_config.html#CRL_distribution_points_

Since we already provide the CRL via "http://<hostname>/ucsCA.crl" we should include this hint where to find the CRL also in the Certificate itself.
Comment 1 Michael Grandjean univentionstaff 2014-10-08 11:00:57 CEST
Requested again via Ticket#2014081121000159
Comment 2 Michael Grandjean univentionstaff 2014-11-07 21:20:51 CET
FYI: in the Baseline Requirements of the CA/Browser Forum, CRL distribution points are mandatory:

> cRLDistributionPoints
> This extension MUST be present and MUST NOT be marked critical. 
> It MUST contain the HTTP URL of the CA’s CRL service.

https://cabforum.org/baseline-requirements-documents/
Comment 3 Michael Grandjean univentionstaff 2015-09-20 00:08:49 CEST
Created attachment 7178 [details]
Add crlDistributionPoints to certificates
Comment 4 Florian Best univentionstaff 2017-06-28 14:52:59 CEST
There is a Customer ID set so I set the flag "Enterprise Customer affected".
Comment 5 Ingo Steuwer univentionstaff 2020-07-03 20:55:52 CEST
This issue has been filed against UCS 4.2.

UCS 4.2 is out of maintenance and many UCS components have changed in later releases. Thus, this issue is now being closed.

If this issue still occurs in newer UCS versions, please use "Clone this bug" or reopen it and update the UCS version. In this case please provide detailed information on how this issue is affecting you.