- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-30-2015 04:33 AM
Our GlobalProtect setup does OCSP checking of client certificates, to an internal OCSP-server. Every once in a while, the lookup fails (as in no response from server, connection denied, or whatever), and the client is denied access (Gateway gpgw.domain.com: Required client certificate is not found). There will be successful lookups just before and just after the failing lookups. I'm well aware that this might be/probably is a problem with my internal network, but I'd still like to know for certain why the lookups fail...
Is there a way to find out what kind of error the PA firewall is seeing? (Connection timeout, 404, etc)
We're running 6.1.1, with GP 2.1.2
The sslmgr log shows the following:
2015-03-30 11:00:24.754 +0200 [OCSP] URL http://ocsp-server/ocsp serialno: 48xxx
2015-03-30 11:00:24.754 +0200 debug: pan_ocsp_fetch_ocsp(pan_crl.c:1992): [0] OCSP checking ... depth 0, URI: http://ocsp-server/ocsp
2015-03-30 11:00:24.754 +0200 debug: pan_ocsp_certchain_to_file(pan_crl.c:1147): root_ca_fname(xxx)
2015-03-30 11:00:24.771 +0200 debug: pan_ocsp_query_responder(pan_crl.c:1917): certificate valid time information (Issuer: Not Before[Mar 16 07:27:31 2010 GMT]; Not After[Jan 19 14:08:09 2020 GMT]; Cert: Not
Before[Jan 20 16:20:38 2015 GMT]; Not After[Jan 20 16:20:38 2016 GMT];)
2015-03-30 11:00:24.771 +0200 debug: pan_ocsp_parse_response(pan_crl.c:1269): Error querying OCSP responder
2015-03-30 11:00:24.771 +0200 Error: pan_ocsp_parse_response(pan_crl.c:1312): Failed to query OCSP responsder
2015-03-30 11:00:24.771 +0200 Error: pan_ocsp_parse_response(pan_crl.c:1355): [OCSP] The result of Certificate status query is unavailable for serial number[48xxx] and uri[http://ocsp-server/ocsp]
2015-03-30 11:00:24.771 +0200 Error: pan_ocsp_fetch_ocsp(pan_crl.c:2104): pan_ocsp_parse_response() failed
2015-03-30 11:00:24.771 +0200 debug: sslmgr_check_status(sslmgr_main.c:801): [0] OCSP check result is 'unavailable', depth 0
2015-03-30 11:00:24.771 +0200 debug: sslmgr_check_status(sslmgr_main.c:1007): [0] final status: unavailable; reason: error querying OCSP responder; depth: 0; BY OCSP
2015-03-30 11:00:24.771 +0200 Send cookie:18 session:0 status:3 to DP
debug sslmgr view ocsp http://ocsp-server/ocsp also just gives "unavailable" as status, with time of last check as "next update" time. Retrying the connection ("Rediscover network") doesn't necessarily help, which leads me to believe that the PA caches 'unavailable'-repsonses (which may not always be what you want)? I haven't tried flushing the OCSP cache, but this problem only happens once in a while, and most of the time goes away by itself immediately (because the next OCSP request succeeds)
Opinions or suggestions, anyone?