Forum Discussion
0_11329
Nimbostratus
Jun 03, 2008Valid certificate is identified as revoked by "OCSP Authentication error redirect" IRule
Hi,
As part of the implementation of a PKI, I try to use the "OCSP Authentication error redirect" IRule in a BigIP 1500 LTM (version 9.3.1) intended to redirect the Client browser t...
hoolio
Cirrostratus
Nov 30, 2009Hi Randy,
It would be easier to configure the OCSP server(s) in a pool and then add logic to your OCSP auth iRule which checks [active_members $ocsp_server_pool] > 1 before trying the OCSP authentication. You could send an HTTP response or TCP reset back to the client if the pool was down.
If you do want to create a VIP, you could do it on a free loopback IP address like 127.0.0.100 and then configure this internal VIP address as the OCSP responder address.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects