Page History
Add_workflow_for_techpubs | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Panel | ||||
---|---|---|---|---|
In this section:
|
Excerpt | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
OverviewThe Online Certificate Status Protocol (OCSP) enables SBC applications to determine the revocation status of a given certificate. OCSP is used to satisfy some of the operational requirements of providing timely revocation information. When a peer sends certificates, an OCSP client (e.g. SIPFE) issues a status request to an OCSP responder and suspends acceptance of the certificates in question until the responder provides a response. The OCSP client needs the address/URL of the OCSP responder, the certificate to be checked, and the certificate issuer’s certificate. The OCSP URL can be FQDN or IPv4 address plus port number. The
SBC supports adding OCSP configuration to an existing/new TLS profile, and performing automatic OCSP checking in OpenSSL library without making substantial changes to OCSP clients (SIPFE, etc.). The OCSP clients may be involved when OCSP checking returns errors. The user may create up to four OCSP profiles per system as described in "Key Concepts" section below. The SBC can act in TLS server role as well as TLS client role.
Key ConceptsThe user may create up to four OCSP profiles per system, each specifying the OCSP capabilities and protocol parameters applying to one or more TLS connections that use the profile (a SIP/TLS connection may reference an OCSP profile in its assigned TLS profile). The OCSP profile is referenced by the existing TLS profile.
When configuring an OCSP profile, be aware that you may delete a given OCSP profile when it is not referenced by any TLS connections. When OCSP is enabled for a TLS connection, every individual certificate in the chain presented by the peer device during the establishment of the connection is validated against an OCSP responder for its revocation status. When the
To View OCSP ProfilesOn the SBC main screen, go to Configuration > System Provisioning > Security Configuration > OCSP Profile. The OCSP Profile window is displayed. |
To Edit an OCSP ProfileTo edit any of the OCSP Profile in the list, click the radio button next to the specific OCSP Profile name. The Edit Selected OCSP Profile window is displayed as in the following figure. |
Make the required changes and click Save at the right hand bottom of the panel to save the changes made. To Create an OCSP ProfileTo create a new OCSP Profile, click New OCSP Profile on the OCSP Profile List panel. The Create New OCSP Profile window is displayed. |
To Copy an OCSP ProfileTo copy an OCSP Profile, click the radio button next to the specific OCSP Profile to highlight the row. Click Copy OCSP Profile on the OCSP Profile List panel. The Copy Selected OCSP Profile window is displayed. Figure 4: Security Configuration - OCSP Profile Copy Window |
Make the required changes to the required fields and click Save to save the changes. The copied OCSP Profile is displayed at the bottom of the original OCSP Profile in the OCSP Profile List panel. To Delete an OCSP Profile
|