From: David Groep Date: Mon, 17 Dec 2015 10:00:00 +0200 Subject: New fetch-crl3 version 3.0.17 adding client-hinted proxy control Dear CAs, Relying Parties, Users, and all others interested, In this announcement of the IGTF: 1. Updated fetch-crl3 (3.0.17) adding client-hinted proxy control ========================================================================= 1. Updated fetch-crl3 (3.0.17) adding client-hinted proxy control ========================================================================= An additional option was added to fetch-crl3 to send cache-control headers as part of the CRL retrieval requests. This is useful in order to hint ot intermediate (http) caching proxies the maximum time for which the client (in this case: fetch-crl) expects the results to be cached. This 'maximum age' suggested by the client is independent from any server-provied hints (i.e. the maximum time suggested by the CA publishing the CRL on the given URL). Usually, the (client-side) proxy server will revalidate the CRL content with the original server after the shortest 'max-age' has passed. This option is OFF by default. To enable client-side cache control, add "cache_control_request=SSSS" to the fetch-crl3 configuration, either through the configuration file or via the "--define" option. The recommended value is 3600 (one hour). For documentation see http://www.nikhef.nl/grid/fetchcrl3/, and you can download the new version in RRM and source form at https://dist.eugridpma.info/distribution/util/fetch-crl/ This new version will also be available through Fedora EPEL and Debian is due time. It resolved fetch-crl3 bugzilla issue #26. ========================================================================= About this news letter ---------------------- This newsletter carries IGTF information intended for relying parties. For more information about this newsletter and how to subscribe, refer to the EUGridPMA web site at https://www.eugridpma.org/ +-----------------------------------------------------------------------+ | For information on the IGTF Distribution, how to use it and what is | | contains, please read the information at | | https://dist.eugridpma.info/distribution/igtf/README.txt | | | | This file contains important information for new users and should be | | read before installing this Distribution. | +-----------------------------------------------------------------------+ If you have suggestions or improvements for the distribution format, to have it better suit your needs, please contact the EUGridPMA PMA at or your Regional Policy Management Authority. See the IGTF web site (www.igtf.net) for further information.