<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible and OK to disable user cert caching? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46107#M33872</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've confirmed that certificates are cached.&lt;/P&gt;&lt;P&gt;The command to show the cache is&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt certificate-cache&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To delete the cache certs then issue.&lt;/P&gt;&lt;P&gt;debug dataplane reset ssl-decrypt certificate-cache&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what I really want is to turn off caching altogether so that if I revoke a cert, the user can't connect anymore.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Dec 2014 02:12:05 GMT</pubDate>
    <dc:creator>x</dc:creator>
    <dc:date>2014-12-10T02:12:05Z</dc:date>
    <item>
      <title>Is it possible and OK to disable user cert caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46103#M33868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After revoking a cert being for GP, the device is still able to connect. I found that it is cached somehow. So is it possible and OK to disable the caching of user certs for authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;&amp;gt; show system setting ssl-decrypt setting&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : vsys1&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Forward Proxy Ready&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Inbound Proxy Ready&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Disable ssl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Disable ssl-decrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Notify user&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Proxy for URL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Wait for URL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Block revoked Cert&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Block timeout Cert&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Block unknown Cert&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Cert Status Query Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;URL Category Query Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;&lt;STRONG&gt;Use Cert Cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1" style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; vertical-align: baseline;"&gt;Verify CRL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;yes&lt;/SPAN&gt;&lt;SPAN class="s2" style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt; &lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;Verify OCSP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;CRL Status receive Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; padding: 0px; border: 0px currentColor; border-image: none; line-height: 1.5em; font-family: 'courier new', courier; font-size: 10pt; font-style: inherit; font-weight: inherit; vertical-align: baseline;"&gt;OCSP Status receive Timeout&amp;nbsp;&amp;nbsp; : 5&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 18:53:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46103#M33868</guid>
      <dc:creator>zac_hg</dc:creator>
      <dc:date>2014-12-09T18:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible and OK to disable user cert caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46104#M33869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;or can the CRL checking be done more frequently.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 18:59:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46104#M33869</guid>
      <dc:creator>zac_hg</dc:creator>
      <dc:date>2014-12-09T18:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible and OK to disable user cert caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46105#M33870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/people/czetazate"&gt;czetazate,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="1977590" style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;/A&gt;Creating a Certificate Profile&lt;/P&gt;&lt;P class="NV_Navigation" style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 10pt; font-style: italic; font-weight: bold; margin: 0 0 10pt;"&gt;&lt;SPAN class="Wingdings" style="font-family: 'Wingdings 3'; font-size: 10pt; font-style: normal;"&gt;&lt;/SPAN&gt;&lt;A name="1977591"&gt;&lt;/A&gt;Device &amp;gt; Certificate Management &amp;gt; Certificate Profile&lt;/P&gt;&lt;TABLE cellspacing="0" class="TW_TableWide" style="margin: 10pt 0 20pt; padding: 5pt 6pt 3pt; color: #000000; font-family: 'Times New Roman'; font-size: medium;" summary=""&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 1px; border-top-color: #000000; border-top-style: solid; border-top-width: 1px; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1977636"&gt;&lt;/A&gt;Use CRL&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 1px; border-top-color: #000000; border-top-style: solid; border-top-width: 1px; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0 0 3pt; text-indent: 0pt;"&gt;&lt;A name="1977638"&gt;&lt;/A&gt;Select the check box to use a certificate revocation list (CRL) to verify the revocation status of certificates.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 1px; border-top-color: #000000; border-top-style: solid; border-top-width: 1px; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1977640"&gt;&lt;/A&gt;Use OCSP&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 1px; border-top-color: #000000; border-top-style: solid; border-top-width: 1px; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0 0 3pt; text-indent: 0pt;"&gt;&lt;A name="1977642"&gt;&lt;/A&gt;Select the check box to use OCSP to verify the revocation status of certificates.&lt;/P&gt;&lt;P class="NT_NoteTable" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; font-style: italic; margin: 0 0 7pt; text-indent: 0pt;"&gt;&lt;SPAN class="Bold" style="font-weight: bold;"&gt;note: &lt;/SPAN&gt;&lt;A name="2007224"&gt;&lt;/A&gt;If you select both OCSP and CRL, the firewall first tries OCSP and only falls back to the CRL method if the OCSP responder is unavailable.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Checking the "use CRL" option should be sufficient.&amp;nbsp; The caveats would be, that if the firewall can not get to the CRL imbedded in the certificate, it would be considered valid.&amp;nbsp; Also, if there is no CRL in the certificate, same behavior.&amp;nbsp; You can check your "service routes"(by default the MGMT port), and make sure that the firewall can get to the CRL to check the certificate status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;The certificate will usually tell where its corresponding CRL is hosted.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;You can find out from the cert where the CRL is hosted as follows:&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/downloadImage/2-34728-9711/crl.png" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #006595;"&gt;&lt;IMG __jive_id="17216" alt="crl.png" class="jive-image jiveImage" height="451" src="https://live.paloaltonetworks.com/legacyfs/online/17216_crl.png" style="border: 0px; font-weight: inherit; font-style: inherit; font-family: inherit;" width="407" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Ensure there is connectivity to the CRL link (check for general http/https connectivity, inline web proxies etc)&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;If it is an http link, you can simply pcap on the mgmt interface going to the IP where the CRL is hosted to check if the CRL is being downloaded or not.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&amp;gt; debug sslmgr view crl [CRL URL]&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&amp;gt; debug sslmgr statistics&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;sslmgr statistics&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Count&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;------------------------------ -----------&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Cert-status request lost&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Cert-status request received&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Cert-status request processed&amp;nbsp; 0&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Certificates revoked by CRL&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Certificates revoked by OCSP&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Certificates confirmed by CRL&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6940"&gt;Controlling GlobalProtect VPN Access with OCSP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5837"&gt;How to Configure an OCSP Responder&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 19:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46105#M33870</guid>
      <dc:creator>dmaynard</dc:creator>
      <dc:date>2014-12-09T19:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible and OK to disable user cert caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46106#M33871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dmaynard, yes I did see the document and confirmed that the CRL is reachable and I can see the CRL that is loaded onto the firewall. The problem is that it stays there unless you run a series of commands. I can't remember exactly the sequence but I had to delete the CRL and then kept trying to connect (which kept succeeding) but eventually I managed to get the client or firewall to check the CRL. So now, I'd like to either disable the caching, adjust the timeout period when the next CRL check is or somehow force the firewall to grab a new CRL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 19:59:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46106#M33871</guid>
      <dc:creator>zac_hg</dc:creator>
      <dc:date>2014-12-09T19:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible and OK to disable user cert caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46107#M33872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've confirmed that certificates are cached.&lt;/P&gt;&lt;P&gt;The command to show the cache is&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt certificate-cache&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To delete the cache certs then issue.&lt;/P&gt;&lt;P&gt;debug dataplane reset ssl-decrypt certificate-cache&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what I really want is to turn off caching altogether so that if I revoke a cert, the user can't connect anymore.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 02:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-and-ok-to-disable-user-cert-caching/m-p/46107#M33872</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2014-12-10T02:12:05Z</dc:date>
    </item>
  </channel>
</rss>

