<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OCSP query in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33100#M24258</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are implementing a SSL-VPN solution using Global Protect and our own CA. From what I have seen the OCSP queries are made on demand, when the certificate is presented for the first time, and then at a fixed interval(60 minutes). I tried changing the interval using the "debug sslmgr set ocsp-next-update-time" but did not have any effect on the update interval.&lt;/P&gt;&lt;P&gt;I wanted to test the PKI infrastructure and modify the state of a certain certificate. Even though I cleared the ocsp cache "debug sslmgr delete ocsp all", when I used the certificate for witch PA had cached a oscp query(that I deleted earlier) PA used the old state of the certificate.&lt;/P&gt;&lt;P&gt;Is there any other way to effectively clear the ocsp cache, or modify the ocsp update time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Costin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Apr 2013 15:54:20 GMT</pubDate>
    <dc:creator>conceptelectronics</dc:creator>
    <dc:date>2013-04-04T15:54:20Z</dc:date>
    <item>
      <title>OCSP query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33100#M24258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are implementing a SSL-VPN solution using Global Protect and our own CA. From what I have seen the OCSP queries are made on demand, when the certificate is presented for the first time, and then at a fixed interval(60 minutes). I tried changing the interval using the "debug sslmgr set ocsp-next-update-time" but did not have any effect on the update interval.&lt;/P&gt;&lt;P&gt;I wanted to test the PKI infrastructure and modify the state of a certain certificate. Even though I cleared the ocsp cache "debug sslmgr delete ocsp all", when I used the certificate for witch PA had cached a oscp query(that I deleted earlier) PA used the old state of the certificate.&lt;/P&gt;&lt;P&gt;Is there any other way to effectively clear the ocsp cache, or modify the ocsp update time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Costin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Apr 2013 15:54:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33100#M24258</guid>
      <dc:creator>conceptelectronics</dc:creator>
      <dc:date>2013-04-04T15:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33101#M24259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can clear the cache using the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On MP:&lt;/P&gt;&lt;P&gt;debug sslmgr delete ocsp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On DP:&lt;/P&gt;&lt;P&gt;debug dataplane reset ssl-decrypt certificate-cache, or &lt;/P&gt;&lt;P&gt;debug dataplane reset ssl-decrypt certificate-status&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Apr 2013 19:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33101#M24259</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-04-04T19:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33102#M24260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That solved the cache clearing problem, but I still have an issue with the ocsp update time.&lt;/P&gt;&lt;P&gt;And also there is a difference in the time showed on the device and in the ocsp debug.&lt;/P&gt;&lt;P&gt;admin@pa5050(active)&amp;gt; debug sslmgr view ocsp all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current time is: Fri Apr&amp;nbsp; 5 10:19:48 2013&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Count&amp;nbsp;&amp;nbsp; Serial Number (HEX)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Update&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Revocation Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reason&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Issuer Name Hash&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OCSP Responder URL&lt;/P&gt;&lt;P&gt;------- ---------------------------------------- ----------- ------------------------ ------------------------ ----------&lt;/P&gt;&lt;P&gt;[&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] 15BA94EB8D8B7993&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Apr 11 15:02:34 2013 GMT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 09b9f61a&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tpp.sniep.ro/ocsp"&gt;http://tpp.sniep.ro/ocsp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@pa5050(active)&amp;gt; show clock&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fri Apr&amp;nbsp; 5 13:19:55 EEST 2013&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@pa5050(active)&amp;gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 10:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33102#M24260</guid>
      <dc:creator>conceptelectronics</dc:creator>
      <dc:date>2013-04-05T10:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33103#M24261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The current time is listed in UTC whereas the clock is listed per the time zone configured on the device. I will have to look for the update time issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Apr 2013 16:46:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-query/m-p/33103#M24261</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-04-08T16:46:26Z</dc:date>
    </item>
  </channel>
</rss>

