Skip to content

Revoking a client certificate #874

Closed Answered by jasikpark
phillroberts asked this question in Q&A
Discussion options

You must be logged in to vote

Yes, you will want to add all of the fingerprints of the compromised host certificates to the pki.blocklist for every host on the network. I would also recommend setting pki.disconnect_invalid to true, so that hosts will disconnect from hosts that are suddenly blocklisted. (For instance if you update the blocklist in the config while nebula is running & send a SIGHUP to trigger a re-read of the config)

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jasikpark
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants