Sun Java System Messaging Server 6 2005Q4 Administration Guide

Proxy Server and CRL Checking

If your system uses a proxy server between client applications and the Messaging Server, CRL checking can be blocked despite the fact that you correctly configured the S/MIME applet to perform CRL checking. When this problem occurs, users of Communications Express Mail receive error messages alerting them to revoked or unknown status for valid key certificates.

The following conditions cause the problem:

To solve this problem, you can:

  1. Set up the communications link between the client machines and proxy server as a secured link with SSL and leave all the configuration values as they are. Or,

  2. Leave the communications link unsecured and set checkoverssl to 0.

For more information see Securing Internet Links With SSL.