Configures the default Online Certificate Status Protocol (OCSP) URL so that the appliance can validate certificate revocation.
If an OCSP URL is found in the certificate, the OCSP responder (also referred as an OCSP server) is queried to determine the status of the certificate revocation. If an OCSP URL is not found in the certificate or the appliance cannot communicate with the OCSP responder from the certificate, a default URL, which is configured on the appliance, is used.
For details about certificate revocation, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.
Note
This command is not currently used on the Intelligent Virtual Execution - Server compute node.
Syntax
[no] aaa authentication certificate ocsp default url <URL>
Parameters
no
Use the no form of this command to remove the default OCSP URL.
URL
Default URL that is configured on the appliance. This URL is based on the configuration of the OCSP override responder.
Example
The following example shows how to configure the default Online Certificate Status Protocol (OCSP) URL.
hostname (config) # aaa authentication certificate ocsp default url http://10.3.13.219:80
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Endpoint Security (HX): Release 2.5
Network Security: Release 7.9.1
Intelligent Virtual Execution - Server: Release 7.9.1
Email Security — Server: Release 7.9.0