I have generated the certificates as given below:
Root-CA -> Intermediate-CA -> Server
Root-CA:
rootca.key
rootca.crt
rootca.crl
Intermediate-CA:
intermediateca.key
intermediateca.crt
intermediateca.crl
Server:
server.key
server.crt
server.crl
My openssl.conf for Server:
[ server_cert ]
basicConstraints = CA:FALSE
nsCertType = server
nsComment = "OpenSSL Generated Server Certificate"
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
keyUsage = critical, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
crlDistributionPoints = URI:http://www.example.com/server.crl
My Nginx conf:
server {
listen 443 ssl;
listen [::]:443 SSL;
server_name www.example.com;
ssl_certificate /home/user/conffiles/intermediateca+server.crt;
ssl_certificate_key /home/user/conffiles/server.key;
ssl_verify_client on;
ssl_client_certificate /home/user/conffiles/rootca.crt;
ssl_verify_depth 3;
ssl_crl /home/user/conffiles/intermediateca.crl;
ssl_protocols TLSv1.2;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
}
Using the above config I have revoked server.crt and can verify and the output is:
error 23 at 0 depth lookup: certificate revoked
error server.crt: verification failed
Then I have gencrl and updated the intermediateca.crl. The problem is that when I visit the website it is still valid SSL the certificate is not revoked.
I am getting a Nginx Error:
SSL_do_handshake() failed (SSL: error:0A000126:SSL routines::unexpected eof while reading) while SSL handshaking
I don't understand what is wrong with the conf files. Please help me, I need this bug fixed. I appreciate your time. Thank you.