OCSP Profiles
Certificate authorities use Online Certificate Status Protocol (OCSP) to get the revocation status of x.509 digital certificates. When a user requests the validity of a certificate, an OCSP request is sent to an OCSP server for verification against a trusted certificate authority. The OCSP server then returns a response indicating whether the certificate is good, revoked, or unknown.
Prerequisites
- At least one OCSP URL must be added from the OCSP page.
- OCSP URL must be published in the AIA field of the certificate with the AppViewX OCSP server URL.
- Plugins required: OCSP Server and OCSP Generator must be deployed for OCSP to work.
- OCSP Responder Setup
- Ensure the following plugins are enabled:
- avx-pkiaas-ca-server
- avx-pkiaas-cert-ocsp-server
- avx-pkiaas-cert-ocsp-generator
- avx_platform_gateway_external
- avx_vendor_cert_scep_agent
- Ensure the following plugins are enabled:
- OCSP HTTP Response Verification
- Use the following command to verify the presence of the required service
port:
bash kubectl get svc -A | grep "avx-platform-gateway-scep" - Ensure that the 30022 port is listed. This port is critical for serving OCSP HTTP responses, which are used to check certificate statuses.
- Use the following command to verify the presence of the required service
port:
You can select one or more certificates from the inventory and click Actions > Revocation Check to perform revocation validation. After successful validation, the certificate status is reflected through color-coding in the Common Name column.
You can create the following OCSP profile by going to PKI+ > Validation Authority > OCSP:
- If you want to activate a selected OCSP signing certificate, you can do it from
Actions > OCSP Signing. The OCSP configuration is updated with the
selected certificate.Note: An OCSP signing certificate can be revoked only on deleting the CA. If an OCSP signing certificate is revoked or deleted from the CERT+ > Certificate Inventory > Server page, then the OCSP responder will not work. To remediate this action, you can create a new OCSP signing certificate by going to CERT+ > Certificate Action > Enroll Certificate and following the procedure explained in the Section, Creating OCSP Signing Certificate.