Forum Discussion
jstaf
Dec 02, 2010Nimbostratus
Multiple (many) OCSP responders, multiple CAs and certificate check
Hello,
Is there a way to check certificates revocation status for a pre-loaded list of trusted CAs (50 to 100), just like a browser would do ?
The BIG-IP should extract the AIA field from the certificate and use it to contact the OCSP responder.
Is it something that the BIG-IP is aimed to do (just not check one or two OCSP responders, but many)? What is the limit?
Has it been done before ? Does someone have a configuration example?
Subsidiary question: if the AIA field does not exist, can the BIG-IP use the CRL field as a fallback? (again, just like internet browsers can do)
Kind regards
- hooleylistCirrostratusHi JTH,
- hooleylistCirrostratusI think this should be possible now with a hotfix on 10.2.4 or any 11.x version:
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects