- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-08-2018 01:37 AM
I'm getting the following error while I can reacht the OCSP server....
SSLMGR certificate ocsp verification failed.Certificate 5200000D638821F4E9A6409C10000400000D63 status is unavailable
> debug sslmgr view ocsp all
Current time is: Fri Jun 8 08:33:33 2018
Count Serial Number (HEX) Status Next Update Revocation Time Reason
Issuer Name Hash
OCSP Responder URL
------- ---------------------------------------- ----------- ------------------------ ------------------------ ----------
[ 1] 5200000E3AF2940BAE3FD132E4000400000E3A unavailable Jun 08 07:25:11 2018 GMT
3b6a1760
http://crl.removed.be/ocsp
06-08-2018 08:12 AM
I would verify that the firewall can reach the ocsp verification source. It may be that you simply don't have a rule in place for the mangement interface to check this, however you can check it due to a policy being created to allow you to browse to that source. I would also double check what your timeout is and verify that you have it set so that the firewall actually has enough time to fetch the status.
06-11-2018 12:08 AM
There is a FW rule active which allows http access to the CRL server.
In the wireshark captures is the OCSP responseStatus: unauthorized (6)
I found some articles referring to the NONCE setting on the AD server, but this option is enabled..
http://support.blackberry.com/kb/articleDetail?ArticleNumber=000035512
06-11-2018 11:23 AM
So what certificate are you actually trying to reach out too, and is it a CRL server that you manage or not? If you are recieving an unauthroized response status then the SSLMGR will give you these responses. This is expected and you aren't getting access to the CRL and therefore you aren't able to verify that the certificate is actually still valid.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!