We recently had a case where we were seeing high proxy_wait_pkt_drop and SSL decryption sessions were taking a while to connect. After a week or two of back and forth support advised us to disable Certificate Revocation Checking (both CRL and OCSP) under decryption settings and that appears to have fixed the issue. Support also mentioned that those settings were just checking the revocation status of our ssl-forward-trust cert and doing us no good anyway and the box independatly pulled CRLs. That doesn't sound right to me, is that correct? And if so how do we block sites with revoked certs, https://revoked.badssl.com/ now seems to be signed by our ssl-forward-trust cert with no issue. How can we prevent signing revoked certificates?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!