Perform one or both of the following steps, depending on whether the
firewall will use the
method to verify the
revocation status of certificates.
If the firewall will use both, it first tries OCSP; if the OCSP
responder is unavailable, the firewall then tries the CRL
method.
Depending on the Certificate Status Timeout
value you specify in the next step, the firewall might register a
timeout before either or both of the Receive Timeout
(sec) intervals pass.