Use the menu options in this section to add the verification OCSP URL so that the appliance can validate certificate revocation. PKI must be selected and CAC must be enabled as the authentication method to add the OSCP URL.
To add the verification OCSP URL:
Log in to the NDR as npadmin using the NDR address or FQDN. For example:
$ ssh npadmin@10.1.0.1or
$ ssh npadmin@exampleFQDNEnter privileged mode:
npadmin@ia> enableEnter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>Enter configuration mode:
npadmin@ia# configure systemEnter configuration CAC mode.
npadmin@ia(config)# authenticationIn the CAC/PIV configuration menu, select
2to configure the current authentication methodSelect
2to add the verification OCSP URL. PressEnter.Enter the verification OCSP URL so that certificate revocation can be validated. Press
Enter.The configuration of the OCSP URL is displayed in the CAC/PIV configuration menu.
Select
Sto save your settings and exit the menu.