Revocation list not updating in System -> Trust -> Revocation DNS issue?

Started by grapes2331, Today at 12:43:12 AM

Previous topic - Next topic
EDIT: I've changed my original post beacsue i have a better idea of what i think i swrong. Okay, I've been continuing to try and figure out why I can't get the CRL list to download. The issue is that when I push any of the below buttons to try and download, update, interact with the CRL nothing happens. It's not like I get an error or anything it just kind of stalls. I re-read the documentation and got confused originally. This is from the documentation.

QuoteA Certificate Revocation Lists (CRL) is a list of certificates that have been revoked by the certificate authority. Some services in OPNsense can use these to validate if a certificate is still valid to use even though it might not be expired.

Defining a CRL in OPNsense is not very complicated, just go to System ‣ Trust ‣ Revocation and click on the <+> sign for your (local) certificate authority to create a new CRL. When a CRL exists, you may edit it and add or remove certificates in it (using the pencil icon).

I'm importing a root CA and an intermediary certificate. This documentation with that + button mentioned is referring to a CA that is self-signed and created on this firewall. Is this something that is just automatically generated from the certificate when I import the root + intermediate?

Here is what I have I have inside the UI....



I think i made an error in my certificate when i defined my CRL URL, but i cant seem to find a way to easily inspect the certificate. Why is PKI so hard?

Can anyone point me in a direction of why these buttons appear to do nothing? I'm able to reach my CRL URL over HTTP but for some reason these buttons appear to do nothing.