OK. In that case, it must be every day. Cheers, Steve On 09/22/2015 03:53 PM, Sam Skipsey wrote:
Hi Steve,
Actually, just from reading the initial error message in the first email in this thread, the issue that Frederic had was precisely with CRL freshness and not the CAs themselves (and Daniela actually does mention that in her reply). It so happens that the dirac tool for "getting CAs" also gets an up-to-date CRL for each CA cert as well, which is what fixes the problem in this instance.
(Most, if not all, tools which rely on X509 authentication will reject CA chains with a stale CRL for that CA, as they can't guarantee that the cert presented has not been revoked since the last time they refreshed the CRL. That's what was happening here.)
Sam
-- Steve Jones sjones@hep.ph.liv.ac.uk Grid System Administrator office: 220 High Energy Physics Division tel (int): 43396 Oliver Lodge Laboratory tel (ext): +44 (0)151 794 3396 University of Liverpool http://www.liv.ac.uk/physics/hep/