Perform one or both of the following steps, depending on whether the
firewall will use
Online
Certificate Status Protocol (OCSP) or the
Certificate Revocation List (CRL) method to verify the
revocation status of certificates. If the firewall will use both, it
first tries OCSP; if the OCSP responder is unavailable, the firewall
then tries the CRL method.
Depending on the Certificate Status Timeout
value you specify in step 2, the firewall might register a timeout
before either or both of the Receive Timeout
intervals pass.
Define the total timeout interval for revocation status requests.
Enter the
Certificate Status Timeout.
This is the interval (1-60 seconds) after which the firewall stops
waiting for a response from any certificate status service and
applies the session-blocking logic you optionally define in step 3.
The Certificate Status Timeout relates to the
OCSP/CRL Receive Timeout as follows:
Click
OK.
(
Optional) Define the blocking behavior for a certificate status of
“unknown” or a revocation status request timeout.
Select , and select an existing profile or create a new
one.
Edit the SSL Forward Proxy
Server Certificate
Verification settings.
Click
OK.
Commit your changes.