Answer the question
In order to leave comments, you need to log in
Mikrotik does certificate revocation affect IKE?
I set up an IKE server on Mikrotik, authentication is digital signature. Created CA certificates, server and client.
These are the authentication settings
Where SRV is the tls server certificate.
After I revoked the client certificate, its status changed to "KRT", but the connection is still going on.
I would very much like to manage vpn clients using certificates!
PS: The client was signed by CA, SRV too!
Answer the question
In order to leave comments, you need to log in
Checking if the certificate has been revoked occurs during phase 1 reauthentication. In Mikrotik, the Lifetime parameter in Profiles is responsible for this. But I'm not sure if it does reauthentication or rekeying.
In Mikrotik with a review, everything is bad. Because this system with certificates is far from being finalized. The KRT status is only a status, in fact, clients, as correctly noted, continue to connect without problems. Only the complete replacement of the sert in identity helps.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question