OCSP Module
The ocsp module provides OCSP checking of TLS certificates.
Its primary use case is within the verify certificate processing
section of the tls-session virtual server when verifying client
certificates during EAP-TLS.
Certificates can be verified against an OCSP Responder. This makes it possible to immediately revoke certificates without the distribution of new Certificate Revocation Lists (CRLs).
In addition to the configuration items below, the behaviour of OCSP can be altered by runtime attributes.
After OCSP verification completes, the request.TLS-OCSP-Cert-Valid
attribute will be added after OCSP completes. One of the following
values will be set:
| Value | Description |
|---|---|
no |
OCSP responder indicated the certificate is not valid. |
yes |
OCSP responder indicated the certificate is valid. |
skipped |
OCSP checks were skipped. |
If an OCSP check is performed, the request.TLS-OCSP-Next-Update
attribute will also be added. The value of this will attribute be the
number of seconds until the certificate state need be refreshed. This
can be used as a Cache-TTL value if you wish to use the cache module
to store OCSP certificate validation status.
If when the OCSP check is performed, if a
control.TLS-OCSP-Cert-Valid attribute is present, its value will
force the outcome of the OCSP check, and the OCSP responder will not
be contacted. Values map to the following OCSP responses:
| Value | Description |
|---|---|
no |
Invalid. |
yes |
Valid. |
skipped |
If |
- override_cert_url
-
Override OCSP url in certificate being verified.
The OCSP Responder URL will be automatically extracted from the
certificate in question. To override the OCSP Responder URL set
override_cert_url = yes.
- url
-
URL to use as OCSP responder endpoint.
If the OCSP Responder address is not extracted from the certificate, the URL can be defined here.
- use_nonce
-
Should a nonce be included in OCSP requests.
If the OCSP Responder can not cope with nonce in the request, then it can be disabled here.
|
- softfail
-
Should the module
softfail if the OCSP responder doesn’t respond.
Normally an error in querying the OCSP responder (no response from server, server did not understand the request, etc) will result in a validation failure.
To treat these errors as soft failures and still accept the
certificate, enable this option.
| this may enable clients with revoked certificates to connect if the OCSP responder is not available. Use with caution. |
When softfail is enabled and there is an error in querying the OCSP
responder the module returns noop rather than fail.
- verfifycert
-
Should the certificate presented in OCSP responses be verified
Default is yes
- ca_file
-
Trusted Root CA list
All of the CA’s in this list will be
- ca_path
-
Directory where additional CAs are located if needed.