# opnsense-patch 2918f0e24
-rw------- 1 root wheel 956B Aug 6 10:35 server1.ca-rw------- 1 root wheel 1.2K Aug 6 10:35 server1.cert-rw------- 1 root wheel 1.3K Aug 6 10:35 server1.conf-rw------- 1 root wheel 0B Aug 6 10:35 server1.crl-verify-rw------- 1 root wheel 227B Aug 6 10:35 server1.keysrwxrwxrwx 1 root wheel 0B Aug 6 10:35 server1.sock-rw------- 1 root wheel 636B Aug 6 10:35 server1.tls-auth
Using the new setup, the behavior is still the same - the system creates a zero-byte '.crl-verify' file.
opnsense-patch -a kulikov-a 91e13ae
@coolmintQuoteUsing the new setup, the behavior is still the same - the system creates a zero-byte '.crl-verify' file.any chance that you forgot to change "Peer Certificate Revocation List" in openvpn server config? )
if you are willing to help sort out the reasons, can you try again (create a CRL and add a certificate to it) after:Code: [Select]opnsense-patch -a kulikov-a 91e13ae ?any errors adding cert to CRL? is CRL valid if you download via GUI? any errors in General log?
Cannot revoke certificate. See general log for details.
2022-08-07T20:18:43 Error opnsense Cert revocation error: CRL validation failed at first step.