OpenLimit Auto CRL Loader

To ensure that the usage of electronic signatures is and remains legally incontestable, signatures are based on certificates with a limited validity which are issued by trust centres. To verify their validity, the certification authorities publish lists of expired certificates. These certificate revocation lists have to be either downloaded manually, or you can hand over this laborious task to OpenLimit Auto CRL Loader. Auto CRL Loader was developed for companies that want to guarantee that certificate revocation lists used for signature verification are as up-to-date as possible, and at the same time cut down on their download traffic. This fully automatic tool is ideally suited to companies that place strict security demands on the IT infrastructure.

Stay up-to-date automatically
OpenLimit Auto CRL Loader updates certificate revocation lists at minute intervals fully automatically in a background process. This obviates the need for time-consuming manual downloads by users and means that it is virtually impossible for signatures to be verified against outdated lists. Auto CRL Loader functions in an extremely transparent manner. Event logs document exactly when and from where it has downloaded which certificate revocation lists. This means that you can always trace back every step should any doubts arise.

Keep all your users up-to-date from just one workstation
If you have installed the OpenLimit signature components on several workstations in your system, Auto CRL Loader enables you to ease your users’ workload. Configure a central unit in the system to download the latest certificate revocation lists and distribute them to all the other units. This will noticeably cut down your download traffic. You can even determine how the lists are distributed, for instance using Windows’ SMB sharing function. OpenLimit Auto CRL Loader runs on either server or client machines.

Update certificate revocation lists even in restrictive networks
Auto CRL Loader is the perfect solution for restrictive network architectures. Even where certain Internet applications are blocked for security reasons, all the workstations in the system still have access to up-to-date certificate revocation lists. If the TCP port 389 is not allowed to be opened, for example, Loader is capable of updating the lists independently of the OpenLimit SignCubes base components and making them accessible to any number of clients in a central certificate revocation list directory.

OpenLimit Auto CRL Loader

Product features

  • Certificate revocation lists are downloaded automatically via HTTP and LDAP
  • Lists can also be downloaded even if particular TCP ports have been blocked for clients
  • The updating of certificate revocation lists can be restricted to just one unit in the system (client or server)
  • Individually configurable distribution of list information using the Windows sharing functionality
  • Generates event logs

Download

Application fields

 OpenLimit