Forum Discussion
Brent_J
Nimbostratus
Mar 10, 2014Machine Cert Check with OCSP failure check / Fall back to CRL
Hi, Running APM Edge 11.4.1 I'm trying to implement a solid SSO APM policy for Bitlocker secured Windows 8 build which will be robust enough to work even if an OCSP is offline.
Background of t...
Brent_J
Nimbostratus
Apr 23, 2014Have asked for a RFE to be raised. Has been a bit tardy on the response so far. Just answering their questions from PD regarding why this would be a good idea. So hopefully get a RFE reference soon. Also doesn't seem to be any way of requesting a machine cert at this time via iRule. Only User certs are currently supported which is frustrating.
Regards, Brent
vandenhoutenp_9
Nimbostratus
May 13, 2014Hi Brent,
I'm trying to do something similar. We don't have an OCSP responder available, is there an easy way to use a static CRL or the CRLDP in the machine cert to check the revocation status? I've tried a standard CRLDP check in the access policy directly after the machine cert auth check but this seems to revert to the client/user certificate that is presented at the start of the access policy.
Thanks
Peter
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects