Forum Discussion
0_11329
Nimbostratus
Jun 03, 2008Valid certificate is identified as revoked by "OCSP Authentication error redirect" IRule
Hi,
As part of the implementation of a PKI, I try to use the "OCSP Authentication error redirect" IRule in a BigIP 1500 LTM (version 9.3.1) intended to redirect the Client browser t...
hoolio
Cirrostratus
Nov 30, 2009Hi Randy,
It would be easier to configure the OCSP server(s) in a pool and then add logic to your OCSP auth iRule which checks [active_members $ocsp_server_pool] > 1 before trying the OCSP authentication. You could send an HTTP response or TCP reset back to the client if the pool was down.
If you do want to create a VIP, you could do it on a free loopback IP address like 127.0.0.100 and then configure this internal VIP address as the OCSP responder address.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects