OCSP Profiles

Certificate authorities use Online Certificate Status Protocol (OCSP) to get the revocation status of x.509 digital certificates. When a user requests the validity of a certificate, an OCSP request is sent to an OCSP server for verification against a trusted certificate authority. The OCSP server then returns a response indicating whether the certificate is good, revoked, or unknown.

Prerequisites

On-premise deployments using AppViewX PKIaaS Native CA
  • At least one OCSP URL must be added from the OCSP page.
  • OCSP URL must be published in the AIA field of the certificate with the AppViewX OCSP server URL.
  • Plugins required: OCSP Server and OCSP Generator must be deployed for OCSP to work.
  • OCSP Responder Setup
    • Ensure the following plugins are enabled:
      • avx-pkiaas-ca-server
      • avx-pkiaas-cert-ocsp-server
      • avx-pkiaas-cert-ocsp-generator
      • avx_platform_gateway_external
      • avx_vendor_cert_scep_agent
  • OCSP HTTP Response Verification
    • Use the following command to verify the presence of the required service port:
      bash kubectl get svc -A | grep "avx-platform-gateway-scep"
    • Ensure that the 30022 port is listed. This port is critical for serving OCSP HTTP responses, which are used to check certificate statuses.

You can select one or more certificates from the inventory and click Actions > Revocation Check to perform revocation validation. After successful validation, the certificate status is reflected through color-coding in the Common Name column.

Note: OCSP routed via CC will work only with the latest version of CC.

You can create the following OCSP profile by going to PKI+ > Validation Authority > OCSP:

OCSP Signing: By default, an OCSP signing certificate is created along with a new CA chain creation. Clicking this field lists all the valid OCSP signing certificates available in the AppViewX PKI inventory along with common name, serial number, issuer common name, extended key usage, and status.
Note: Only one OCSP signing certificate is active at any given point of time.
  • If you want to activate a selected OCSP signing certificate, you can do it from Actions > OCSP Signing. The OCSP configuration is updated with the selected certificate.
    Note: An OCSP signing certificate can be revoked only on deleting the CA. If an OCSP signing certificate is revoked or deleted from the CERT+ > Certificate Inventory > Server page, then the OCSP responder will not work. To remediate this action, you can create a new OCSP signing certificate by going to CERT+ > Certificate Action > Enroll Certificate and following the procedure explained in the Section, Creating OCSP Signing Certificate.