10-28-2016 08:54 AM - edited 10-28-2016 08:58 AM
We recently had a case where we were seeing high proxy_wait_pkt_drop and SSL decryption sessions were taking a while to connect. After a week or two of back and forth support advised us to disable Certificate Revocation Checking (both CRL and OCSP) under decryption settings and that appears to have fixed the issue. Support also mentioned that those settings were just checking the revocation status of our ssl-forward-trust cert and doing us no good anyway and the box independatly pulled CRLs. That doesn't sound right to me, is that correct? And if so how do we block sites with revoked certs, https://revoked.badssl.com/ now seems to be signed by our ssl-forward-trust cert with no issue. How can we prevent signing revoked certificates?