Enable SSO certificate revocation list checking
When single sign-on is enabled for your organization, a CRL is maintained. A CRL is a list of digital certificates that have been revoked and should not be trusted. If CRL checking is enabled,
BlackBerry AtHoc
checks the CRL before initiating a SAML authentication request to an identity provider or after receiving an SAML response from the IDP.- In the navigation bar, click
.
- In theSystem Setupsection, clickSecurity Policy.
- In theSSO CRL (Certificate Revocation List) Settingssection, select theEnable CRL Checkingoption.If theSSO CRL (Certificate Revocation List) Settingssection is not visible, single sign-on is not enabled. See Enable single sign-on for Self Service and Enable single sign-on for the BlackBerry AtHoc management system.
- In theCRL Timeout Intervalfield, enter the number of seconds to allow for certificate validation information to be retrieved from the CA. The minimum is 1 and the maximum is 60 seconds. The default is 20 seconds.
- Optionally, select theIgnore Verification Errorsoption. If this option is selected, a certificate that fails verification will continue to be used and an error is logged. If this option is not selected, any certificate that fails verification is not used.
- ClickSave.