[x]

Site Alert(s):

  • Server maintenance Saturday Nov 22, 2008, 12:00 PM - 3:00 PM. The Knowledge Center will be unavailable during this time.
Rate this Article:
You must be signed in to rate again
Article Feedback Print View
Alternate Languages: N/A

Users Unable to Log On When HTTP Certificate Revocation List (CRL) Retrieval Fails

Document ID: CTX108765   /   Created On: Mar 1, 2006   /   Updated On: Jan 31, 2008
Average Rating: not yet rated

Symptoms

Users are unable to log on and “Revocation checking: Warning: Retrieving CRL failed” is recorded in the logs when “Require Client Certificates” is enabled.

Cause

The certificate references an HTTP Certificate Revocation List (CRL), but the retrieval mechanism currently requires the Content-Length HTTP header to be correctly set. If the Web server is dynamically generating the revocation list it may not be possible to set this header.

Resolution

The HTTP server publishing the CRL must set the Content-Length header. Usually this header is set for static content (for example, CRL files), but dynamic content must be buffered for this field to be calculated.

Status

This issue has been addressed in Access Gateway Standard Edition version 4.5 or later.

The latest version of the Access Gateway Standard Edition Software can be downloaded from CTX106192 - Access Gateway Software Updates.


Search
Knowledge Center
XenApp
XenApp Plugins (Clients)
XenServer
XenDesktop
NetScaler Application Delivery
Access Gateway
EdgeSight
Provisioning Server
WANScaler
Password Manager
Does it work with Citrix? Verify it - introducing the new Citrix Ready Community Verified