For example, if only CRL checking is enabled and the certificate doesn't have a CRL URI, if this option is enabled the connection is blocked.

When both CRL and OCSP checking are enabled, the block occurs only if both CRL and OCSP lack a URI.

Allowing wildcard certificates eases the strict matching burden when a Common Name match is required.

It is also helpful for domains that have multiple subdomains like or

SSL certificate verification is an important component of SSL security.

It is through certificate exchange and verification that the client, in this case Content Gateway, and the origin server verify that each is who it says it is.

This is a basic check that is important because many malicious sites operate with expired certificates.

