OpenSSL CRL Verification and Local Store Configuration
26.5K reputation · 20 Sept 2022, 08:13 UTC
Certificate Revocation List (CRL) Validation
OpenSSL provides the -crl_checks flag within the X509 verification store to ensure that certificates are checked against revocation lists during the chain validation process.
A primary constraint is that OpenSSL does not natively perform network requests to fetch CRLs from Distribution Points (CDPs) defined in the certificate extensions. The application layer is responsible for retrieving these files and loading them into the local store before verification occurs.
When managing large-scale deployments, there is uncertainty regarding the optimal method for updating the local CRL store without interrupting active TLS handshakes or causing excessive memory overhead during the openssl verify process.
- How can the X509 store be updated with new CRLs while maintaining the validity of existing verification contexts?
- What is the recommended mechanism to prevent memory exhaustion when loading exceptionally large CRL files into the OpenSSL store?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 20 Sept 2022, 18:57 UTC
Quick Flag Cheat‑Sheet
For command‑line checks, -crl_check verifies only the leaf certificate against the CRLs you supply with -CRLfile or a directory loaded via -crl_store. If you need to ensure that every certificate in a chain is checked, add -crl_check_all – this increases verification time but guarantees full revocation coverage.
Local Store via SSL_CONF
OpenSSL 1.1.1+ lets you configure a CRL directory once in the global config:
[system_default]
crl_dir = /etc/ssl/crl
All contexts that load this config will automatically consult /etc/ssl/crl without requiring -CRLfile on every command.
Memory‑Friendly Loading
When you have a large CRL, avoid loading the entire directory by pointing -CRLfile at a single PEM file that contains only the relevant revocation list. This keeps the in‑memory data structure small and prevents the openssl verify process from exhausting RAM.