<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSLMGR certificate ocsp verification failed.Certificate  status unavailble in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217392#M62892</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30218"&gt;@DaxVC&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So what certificate are you actually trying to reach out too, and is it a CRL server that you manage or not? If you are recieving an unauthroized response status then the SSLMGR will give you these responses. This is expected and you aren't getting access to the CRL and therefore you aren't able to verify that the certificate is actually still valid.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jun 2018 18:23:38 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-06-11T18:23:38Z</dc:date>
    <item>
      <title>SSLMGR certificate ocsp verification failed.Certificate  status unavailble</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217142#M62833</link>
      <description>&lt;P&gt;I'm getting the following error while I can reacht the OCSP server....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSLMGR certificate ocsp verification failed.Certificate 5200000D638821F4E9A6409C10000400000D63 status is unavailable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug sslmgr view ocsp all&lt;/P&gt;&lt;P&gt;Current time is: Fri Jun 8 08:33:33 2018&lt;/P&gt;&lt;P&gt;Count Serial Number (HEX) Status Next Update Revocation Time Reason&lt;BR /&gt;Issuer Name Hash&lt;BR /&gt;OCSP Responder URL&lt;BR /&gt;------- ---------------------------------------- ----------- ------------------------ ------------------------ ----------&lt;BR /&gt;[ 1] 5200000E3AF2940BAE3FD132E4000400000E3A unavailable Jun 08 07:25:11 2018 GMT&lt;BR /&gt;3b6a1760&lt;BR /&gt;http://crl.&lt;EM&gt;removed&lt;/EM&gt;.be/ocsp&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 08:37:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217142#M62833</guid>
      <dc:creator>DaxVC</dc:creator>
      <dc:date>2018-06-08T08:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSLMGR certificate ocsp verification failed.Certificate  status unavailble</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217193#M62845</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30218"&gt;@DaxVC&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would verify that the&amp;nbsp;&lt;EM&gt;firewall&lt;/EM&gt; can reach the ocsp verification source. It may be that you simply don't have a rule in place for the mangement interface to check this, however you can check it due to a policy being created to allow you to browse to that source. I would also double check what your timeout is and verify that you have it set so that the firewall actually has enough time to fetch the status.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 15:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217193#M62845</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-08T15:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSLMGR certificate ocsp verification failed.Certificate  status unavailble</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217315#M62875</link>
      <description>&lt;P&gt;There is a FW rule active which allows http access to the CRL server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the wireshark captures is the OCSP responseStatus: unauthorized (6)&lt;/P&gt;&lt;P&gt;I found some articles referring to the NONCE setting on the AD server, but this option is enabled..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/EAP-TLS-with-OCSP-check-fails-with-error-quot-OCSP-response/ta-p/234120" target="_blank"&gt;https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/EAP-TLS-with-OCSP-check-fails-with-error-quot-OCSP-response/ta-p/234120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://social.technet.microsoft.com/Forums/office/en-US/7a518f7d-b39a-4c1c-9344-df71ffbf046f/2008-ocsp-server-error-message-quotunauthorizedquot6?forum=winserversecurity" target="_blank"&gt;https://social.technet.microsoft.com/Forums/office/en-US/7a518f7d-b39a-4c1c-9344-df71ffbf046f/2008-ocsp-server-error-message-quotunauthorizedquot6?forum=winserversecurity&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.blackberry.com/kb/articleDetail?ArticleNumber=000035512" target="_blank"&gt;http://support.blackberry.com/kb/articleDetail?ArticleNumber=000035512&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 07:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217315#M62875</guid>
      <dc:creator>DaxVC</dc:creator>
      <dc:date>2018-06-11T07:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSLMGR certificate ocsp verification failed.Certificate  status unavailble</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217392#M62892</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30218"&gt;@DaxVC&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So what certificate are you actually trying to reach out too, and is it a CRL server that you manage or not? If you are recieving an unauthroized response status then the SSLMGR will give you these responses. This is expected and you aren't getting access to the CRL and therefore you aren't able to verify that the certificate is actually still valid.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sslmgr-certificate-ocsp-verification-failed-certificate-status/m-p/217392#M62892</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-11T18:23:38Z</dc:date>
    </item>
  </channel>
</rss>

