Forum Discussion
OCSP revocated CA
Hello all,
we configured an APM policy that perform OCSP Auth for client certs whom is working great.
Now we would like to add a new piece and verify even if the Intermediate CA, that signed the client certs, has being revoked.
is it possible to do this using only APM or other LTM function that doesn't involve the OCSP Stapling?
we tried with OCSP stapling but it didn't working properly and is not scalable, so we wonder if there are alternatives.
thank you
- Leslie_HubertusRet. Employee
Hi Satoshino - I see that nobody has come by to answer this yet. I think my colleague Lucas_Thompson may be able to help, though.
- Lucas_ThompsonEmployee
Hi Satoshino,
You present an interesting problem, it sounds like you're trying to ignore the certificate trust chain? Could you explain further how you'd like to do it? I don't exactly understand how you'd correctly validate trust when one member of the trust chain is invalid.
An APM policy for OCSP will query the CA for OCSP status.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com