Skip to content

Serve a CRL when configured, and test it in CI - #562

Open
Preston12321 wants to merge 1 commit into
crl-handlerfrom
crl-serving-and-tests
Open

Preston12321 wants to merge 1 commit into
crl-handlerfrom
crl-serving-and-tests

Conversation

@Preston12321

@Preston12321 Preston12321 commented Sep 27, 2026 •

Copy link
Copy Markdown

Add the crlListenAddress, crlBaseURL, crlMaxDelay and crlValidity config fields and their PEBBLE_CRL_* environment overrides. When both the listen address and base URL are set, Pebble serves its CRL over plain HTTP.

Document CRL support in the README and docker-compose.yml, expose port 4003 in the release image, and extend chisel2.py to revoke a certificate and check that it appears on the CRL with the right reason.

Fixes #531

Note: This change is entirely generated by Claude, but I provided significant guidance and have manually reviewed the diff

Add the crlListenAddress, crlBaseURL, crlMaxDelay and crlValidity config
fields and their PEBBLE_CRL_* environment overrides. When both the
listen address and base URL are set, Pebble serves its CRL over plain
HTTP.

Document CRL support in the README and docker-compose.yml, expose port
4003 in the release image, and extend chisel2.py to revoke a certificate
and check that it appears on the CRL with the right reason.
@Preston12321
Preston12321 added this pull request to stack #559 September 27, 2026 03:49
@Preston12321
Preston12321 marked this pull request as ready for review September 27, 2026 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support issuing CRLs

1 participant