Forum Discussion

Todd_Roberts_93's avatar
Todd_Roberts_93
Icon for Nimbostratus rankNimbostratus
Mar 06, 2007

OCSP redirect??

Hi,

 

 

I was wondering if anyone else was doing the same or had a solution to the following.

 

 

I am doing client and server side SSL and checking user Certs for revocation status of an OCSP responder. The thing that we are seeing is that if a user has a revoked Cert the LTM just drops the connection. Is there a way to capture the response from the OCSP responder and redirect the users to a sorry page? Or send them a message regarding their Cert status?

 

 

-Todd

 

3 Replies

  • Please check out the Kevin Stewart's iRules 2006 2nd place entry:

     

     

    http://devcentral.f5.com/Default.aspx?tabid=108

     

    Click here

     

     

  • Thanks for the reply....

     

     

    I have tried Kevin Stewart’s iRule and every time we hit the VIP for testing it failed the F5 over to the stand by unit. Any ideas? Or maybe a simpler iRule you might know of?

     

     

    -Todd

     

  • That's not so good. I'd check your logs and also check /var/core to see if you are getting a TMM panic, the OS version you're on might have a bug. If that's the case, open a support case.

     

     

    Perhaps Kevin can lend an insightful hand, as well as his OS version??