<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error querying OCSP responder in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-querying-ocsp-responder/m-p/464908#M102545</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200753"&gt;@W1nterfl00d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there additional information in the sslmgr.log ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the S/N of a certificate is NOT listed in a CRL, which has IDP extension, the certificate status is marked as UNKNOWN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Source: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldJCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldJCAS&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 10 Feb 2022 15:53:36 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2022-02-10T15:53:36Z</dc:date>
    <item>
      <title>Error querying OCSP responder</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-querying-ocsp-responder/m-p/464096#M102448</link>
      <description>&lt;P&gt;We have an issue with the R3 root certificate caused by the OCSP Certificate Revocation Checking within our decryption profile. We're seeing all sites using this certificate being blocked due to unknown issuer. When we run the "debug sslmgr view ocsp all" we can see the responder URL as unavailable with&amp;nbsp;error querying OCSP responder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've checked the OCSP and CRL traffic leaving our nodes and can see tcp-fins for all matching traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a support case open for this but it's going nowhere, has anyone encountered a similar issue before / have any CLI commands to help our investigation?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Ellis&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 09:28:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-querying-ocsp-responder/m-p/464096#M102448</guid>
      <dc:creator>W1nterfl00d</dc:creator>
      <dc:date>2022-02-08T09:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Error querying OCSP responder</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-querying-ocsp-responder/m-p/464908#M102545</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200753"&gt;@W1nterfl00d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there additional information in the sslmgr.log ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the S/N of a certificate is NOT listed in a CRL, which has IDP extension, the certificate status is marked as UNKNOWN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Source: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldJCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldJCAS&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 10 Feb 2022 15:53:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-querying-ocsp-responder/m-p/464908#M102545</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-02-10T15:53:36Z</dc:date>
    </item>
  </channel>
</rss>

