aaa authentication certificate ocsp enable

Prev Next

Enables the Online Certificate Status Protocol (OCSP) so that the appliance can verify the status of the certificate revocation. When OCSP is enabled and the appliance cannot reach the OCSP server, the user is denied access to the Web UI.

OCSP allows the appliance to check if a certificate has been revoked without downloading and searching the entire list.

Note

OCSP is enabled by default.

For details about certificate revocation, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

[no] aaa authentication certificate ocsp enable

Parameters

no

Use the no form of this command to disable OCSP for certificate authentication.

Example

The following example shows how to enable OCSP.

hostname (config) # aaa authentication certificate ocsp enable

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Network Security: Release 7.9.1

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0