I wanted to practice using a CRL, to ensure I knew how it worked. So I put a CRL in the "Certificate Revocation List (Optional)" field of OpenVPN setup. It blocked the certificate, as expected.
Then, I rebuilt my OpenVPN setup from scratch with a new CA. Since I didn't have any certs to revoke, I left "Certificate Revocation List (Optional)" empty. But the firmware insists on adding "crl-verify crl.pem" to my config.ovpn file and all my connections fail until I expire a certificate.
It looks like once a CRL is used it cannot be cleared via the UI. How do I tell it I've rebuilt everything and I no longer want to provide a CRL?
Then, I rebuilt my OpenVPN setup from scratch with a new CA. Since I didn't have any certs to revoke, I left "Certificate Revocation List (Optional)" empty. But the firmware insists on adding "crl-verify crl.pem" to my config.ovpn file and all my connections fail until I expire a certificate.
It looks like once a CRL is used it cannot be cleared via the UI. How do I tell it I've rebuilt everything and I no longer want to provide a CRL?