Forum Discussion
hui_37443
Nimbostratus
Oct 08, 2009OCSP responder trouble shooting
One of our test server is having trouble to initiate an OCSP check. The authentication status value is always misleading 1. However, from the tcp trace, we have noticed that there has been no traffic heading to OCSP server.
On the shell console, we can run "curl -k https://ocsp.server" and get the default html response back. The corresponding tcp dump shows dns enquiry is maded and communication between Big-IP and OCSP Server happens after that. However in the runtime, nothing suggests that there is any effort to make the contact. I am running out of ideas here. The core functionality resides in the call "AUTH::authenticate" and therefore trace statements in iRule are not much useful.
Any suggestions that can help me to reveal the true nature of the issue?
- hui_37443
Nimbostratus
The version is 9.4.5. - hoolio
Cirrostratus
You could try copying the default OCSP auth iRule and add debug logging to see which code paths are being executed. - hoolio
Cirrostratus
There are also two related fixes available in a hotfix for 9.4.8 for OCSP functionality that may help you: - hui_37443
Nimbostratus
Here is the iRule we are using. It works on a dev box, which talks to the same OCSP server. Therefore, I believe it does the job. The trace log suggests "doing OCSP" & "authentication status of round 1 $tmm_auth_status" happens in same second. - hui_37443
Nimbostratus
Turned out to be the certificate name case issue. There has been no sign to show F5 having trouble to pick up the signing cert. One of the colleagues had similar experience before so we tried and the problem is gone. In general this trial & error approach is not very efficient. It would be great that F5 can provide some facilities to reveal the problems inside the builtin modules. - hoolio
Cirrostratus
Hi Hui, - dimka___104021
Nimbostratus
may be offtopic, but still couple words about 9.4.8: - hoolio
Cirrostratus
Hi Dimka,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects