FreeRADIUS InkBridge

OCSP Module

The ocsp module provides OCSP checking of TLS certificates.

Its primary use case is within the verify certificate processing section of the tls-session virtual server when verifying client certificates during EAP-TLS.

Certificates can be verified against an OCSP Responder. This makes it possible to immediately revoke certificates without the distribution of new Certificate Revocation Lists (CRLs).

In addition to the configuration items below, the behaviour of OCSP can be altered by runtime attributes.

After OCSP verification completes, the request.TLS-OCSP-Cert-Valid attribute will be added after OCSP completes. One of the following values will be set:

Value Description

no

OCSP responder indicated the certificate is not valid.

yes

OCSP responder indicated the certificate is valid.

skipped

OCSP checks were skipped.

If an OCSP check is performed, the request.TLS-OCSP-Next-Update attribute will also be added. The value of this will attribute be the number of seconds until the certificate state need be refreshed. This can be used as a Cache-TTL value if you wish to use the cache module to store OCSP certificate validation status.

If when the OCSP check is performed, if a control.TLS-OCSP-Cert-Valid attribute is present, its value will force the outcome of the OCSP check, and the OCSP responder will not be contacted. Values map to the following OCSP responses:

Value Description

no

Invalid.

yes

Valid.

skipped

If softfail = yes value else invalid.

override_cert_url

Override OCSP url in certificate being verified.

The OCSP Responder URL will be automatically extracted from the certificate in question. To override the OCSP Responder URL set override_cert_url = yes.

url

URL to use as OCSP responder endpoint.

If the OCSP Responder address is not extracted from the certificate, the URL can be defined here.

use_nonce

Should a nonce be included in OCSP requests.

If the OCSP Responder can not cope with nonce in the request, then it can be disabled here.

  • For security reasons, disabling this option is not recommended as nonce protects against replay attacks.

  • Microsoft AD Certificate Services OCSP Responder does not enable nonce by default. It is more secure to enable nonce on the responder than to disable it in the query here.

softfail

Should the module soft fail if the OCSP responder doesn’t respond.

Normally an error in querying the OCSP responder (no response from server, server did not understand the request, etc) will result in a validation failure.

To treat these errors as soft failures and still accept the certificate, enable this option.

this may enable clients with revoked certificates to connect if the OCSP responder is not available. Use with caution.

When softfail is enabled and there is an error in querying the OCSP responder the module returns noop rather than fail.

verfifycert

Should the certificate presented in OCSP responses be verified

Default is yes

ca_file

Trusted Root CA list

All of the CA’s in this list will be

ca_path

Directory where additional CAs are located if needed.

Default Configuration

ocsp {
#	override_cert_url = yes
#	url = "http://127.0.0.1/ocsp/"
#	use_nonce = no
#	softfail = no
#	verifycert = yes
#	ca_file = ${cadir}/rsa/ca.pem
#	ca_path = ${cadir}
}