summaryrefslogtreecommitdiffstats
path: root/base/tks/shared
diff options
context:
space:
mode:
authorEndi S. Dewata <edewata@redhat.com>2014-09-03 16:06:49 -0400
committerEndi S. Dewata <edewata@redhat.com>2014-09-03 16:55:51 -0400
commit223d15539b7bcc0df025025036af2935726e52e3 (patch)
tree879a4b999e7b29aa04a96a18b6e83c5da8874423 /base/tks/shared
parent5f863998006bc5521b1ad91e106b10cd3e748ad2 (diff)
downloadpki-223d15539b7bcc0df025025036af2935726e52e3.tar.gz
pki-223d15539b7bcc0df025025036af2935726e52e3.tar.xz
pki-223d15539b7bcc0df025025036af2935726e52e3.zip
Enabled certificate revocation checking by default.
The CS.cfg templates for all subsystems have been modified to enable certificate revocation checking during authentication. This will affect new installations only. Ticket #1117, #1134
Diffstat (limited to 'base/tks/shared')
-rw-r--r--base/tks/shared/conf/CS.cfg.in4
1 files changed, 4 insertions, 0 deletions
diff --git a/base/tks/shared/conf/CS.cfg.in b/base/tks/shared/conf/CS.cfg.in
index bd2858d02..41937d140 100644
--- a/base/tks/shared/conf/CS.cfg.in
+++ b/base/tks/shared/conf/CS.cfg.in
@@ -132,6 +132,10 @@ auths.instance.AgentCertAuth.agentGroup=Certificate Manager Agents
auths.instance.AgentCertAuth.pluginName=AgentCertAuth
auths.instance.TokenAuth.pluginName=TokenAuth
auths.revocationChecking.bufferSize=50
+auths.revocationChecking.enabled=true
+auths.revocationChecking.tks=tks
+auths.revocationChecking.unknownStateInterval=0
+auths.revocationChecking.validityInterval=120
authz._000=##
authz._001=## new authorizatioin
authz._002=##