diff --git a/atst/domain/authnid/crl/__init__.py b/atst/domain/authnid/crl/__init__.py index 26956f09..3451e30e 100644 --- a/atst/domain/authnid/crl/__init__.py +++ b/atst/domain/authnid/crl/__init__.py @@ -182,6 +182,11 @@ class CRLCache(CRLInterface): except crypto.X509StoreContextError as err: if err.args[0][0] == CRL_EXPIRED_ERROR_CODE: if app.config.get("CRL_FAIL_OPEN"): + self._log_info( + "Encountered expired CRL for certificate with CN {} and issuer CN {}, failing open.".format( + parsed.get_subject().CN, parsed.get_issuer().CN + ) + ) return True else: raise CRLInvalidException("CRL expired. Args: {}".format(err.args))