<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Crl on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/crl/</link>
    <description>Recent content in Crl on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:20:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/crl/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Client Certificates From step-ca, And The Defaults That Lock Everyone Out</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</link>
      <pubDate>Fri, 09 Oct 2026 18:20:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</guid>
      <description>Using step-ca to issue client certificates for mTLS, tested with nginx and Caddy. The 24-hour limit and how to raise it, a CRL that rejects everyone until its scope is fixed, the root CRL nginx needs, publishing CRLs over HTTP, the refresh job that stops them lapsing, and the PKCS12 file and CA certificates a phone needs.</description>
    </item>
  </channel>
</rss>
