SSLMGR certificate ocsp verification failed.Certificate status unavailble

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSLMGR certificate ocsp verification failed.Certificate status unavailble

L2 Linker

I'm getting the following error while I can reacht the OCSP server.... 

 

 

SSLMGR certificate ocsp verification failed.Certificate 5200000D638821F4E9A6409C10000400000D63 status is unavailable

 

> debug sslmgr view ocsp all

Current time is: Fri Jun 8 08:33:33 2018

Count Serial Number (HEX) Status Next Update Revocation Time Reason
Issuer Name Hash
OCSP Responder URL
------- ---------------------------------------- ----------- ------------------------ ------------------------ ----------
[ 1] 5200000E3AF2940BAE3FD132E4000400000E3A unavailable Jun 08 07:25:11 2018 GMT
3b6a1760
http://crl.removed.be/ocsp

3 REPLIES 3

Cyber Elite
Cyber Elite

@DaxVC,

I would verify that the firewall can reach the ocsp verification source. It may be that you simply don't have a rule in place for the mangement interface to check this, however you can check it due to a policy being created to allow you to browse to that source. I would also double check what your timeout is and verify that you have it set so that the firewall actually has enough time to fetch the status. 

There is a FW rule active which allows http access to the CRL server.

 

In the wireshark captures is the OCSP responseStatus: unauthorized (6)

I found some articles referring to the NONCE setting on the AD server, but this option is enabled..

 

https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/EAP-TLS-with-OCSP-check-fails-with-...

 

https://social.technet.microsoft.com/Forums/office/en-US/7a518f7d-b39a-4c1c-9344-df71ffbf046f/2008-o...

 

http://support.blackberry.com/kb/articleDetail?ArticleNumber=000035512

@DaxVC,

So what certificate are you actually trying to reach out too, and is it a CRL server that you manage or not? If you are recieving an unauthroized response status then the SSLMGR will give you these responses. This is expected and you aren't getting access to the CRL and therefore you aren't able to verify that the certificate is actually still valid. 

  • 6843 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!