<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN external CRL automatic renewing - OpenVPN restart]]></title><description><![CDATA[<p dir="auto">Hi Guys,<br />
<strong>Scenario:</strong></p>
<ul>
<li>External CRL (validity 24 hours)</li>
<li>Download CRL via Cronjob (every Hour) and drop it in /var/etc/openvpn/server1/ca/CA_CERT_NAME.r0</li>
</ul>
<p dir="auto">This works well. If a Certificate is revoked and CRL was downloaded Client is not able to connect any more.</p>
<p dir="auto"><strong>Problem:</strong><br />
Expiration Date of CRL seems to be cached.<br />
I need to restart openVPN Service every 24h becuase otherwise Clients are not able to Connect because of Expired CRL.</p>
<p dir="auto">This is really Strange. Why is revokation working with just Update the File but Expiration Date is not updated for OpenVPN Service?</p>
<p dir="auto">I need a CRL solution without restarting openVPN every Day.<br />
Any Ideas?</p>
<p dir="auto">(I can not change CRL Expiration Date)</p>
]]></description><link>https://forum.netgate.com/topic/170633/openvpn-external-crl-automatic-renewing-openvpn-restart</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 17:59:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/170633.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 09 Mar 2022 14:49:18 GMT</pubDate><ttl>60</ttl></channel></rss>