Revoked Certificate is still valid by Nginx

Viewed 154

I have generated the certificates as given below:

Root-CA  ->  Intermediate-CA  ->  Server

Root-CA:
rootca.key
rootca.crt
rootca.crl

Intermediate-CA:
intermediateca.key
intermediateca.crt
intermediateca.crl

Server:
server.key
server.crt
server.crl

My openssl.conf for Server:

[ server_cert ]
basicConstraints        = CA:FALSE
nsCertType              = server
nsComment               = "OpenSSL Generated Server Certificate"
subjectKeyIdentifier    = hash
authorityKeyIdentifier  = keyid,issuer:always
keyUsage                = critical, digitalSignature, keyEncipherment
extendedKeyUsage        = serverAuth
crlDistributionPoints   = URI:http://www.example.com/server.crl

My Nginx conf:

server {
        listen 443 ssl;
        listen [::]:443 SSL;
        server_name www.example.com;

        ssl_certificate  /home/user/conffiles/intermediateca+server.crt;
        ssl_certificate_key /home/user/conffiles/server.key;

        ssl_verify_client on;
        ssl_client_certificate /home/user/conffiles/rootca.crt;
        ssl_verify_depth 3;
        ssl_crl /home/user/conffiles/intermediateca.crl;

        ssl_protocols  TLSv1.2;
        ssl_session_cache shared:SSL:1m;
        ssl_session_timeout 5m;
        ssl_ciphers HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers on;
}

Using the above config I have revoked server.crt and can verify and the output is:

error 23 at 0 depth lookup: certificate revoked
error server.crt: verification failed

Then I have gencrl and updated the intermediateca.crl. The problem is that when I visit the website it is still valid SSL the certificate is not revoked.

I am getting a Nginx Error:

SSL_do_handshake() failed (SSL: error:0A000126:SSL routines::unexpected eof while reading) while SSL handshaking

I don't understand what is wrong with the conf files. Please help me, I need this bug fixed. I appreciate your time. Thank you.

0 Answers
Related