<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with OCSP, few questions regarding the configuration in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212160#M8563</link>
    <description>&lt;P&gt;Since I dont like to assume anything, I would not say that, but based on what customer informed me, it does work...is it officially supported, I have no clue, sorry.&lt;/P&gt;
&lt;P&gt;Is it possible that OCSP on intermediate CA is not supported? I dont know 100% if that would be the case, but based on the research I did, appears it is doable. How, that Im not certain.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 11:16:56 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-04-24T11:16:56Z</dc:date>
    <item>
      <title>Help with OCSP, few questions regarding the configuration</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212099#M8553</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read the SK about implementing OCSP (&lt;A href="https://support.checkpoint.com/results/sk/sk37803" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk37803&lt;/A&gt;) and have a few questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Step 3 of the SK mentions to add the&amp;nbsp;&lt;SPAN&gt;OCSP server's certificate data (Base64 encoded DER format)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Is this the OCSPs servers' machine certificate? Or the certificate of the root CA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- According to Windows Server Best Practice and the default certificate template for OCSP servers, they renew every 2 weeks. Do I really need to add the OCSP certificate? Is there a workaround? I know on Cisco devices you can disable the verification for OCSP Server response signing. I haven't found a corresponding setting on CP side. Can I leave the certificate empty?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- We have two OCSP servers behind a loadbalancer, if I need to specify the OCSP servers certificate, we'll run into another issue since we can only add once certificate. Do you know of any solution for that?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any further advice/help is appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 15:04:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212099#M8553</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2024-04-23T15:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Help with OCSP, few questions regarding the configuration</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212125#M8554</link>
      <description>&lt;P&gt;Here is what I recall from this sk, but maybe someone else can confirm for sure.&lt;/P&gt;
&lt;P&gt;1) Yes, its servers machine cert&lt;/P&gt;
&lt;P&gt;2) I know customer that did end up leaving field empty and that worked, is that the right way? I cant say for sure, but it does work&lt;/P&gt;
&lt;P&gt;3) That I honestly have no clue, but thats super valid concern, since load balancer is involved&lt;/P&gt;
&lt;P&gt;If I were you, I would open TAC case to get an official response.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 02:02:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212125#M8554</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-24T02:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help with OCSP, few questions regarding the configuration</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212127#M8555</link>
      <description>&lt;P&gt;Hey Andy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already had a case open but their response was "I think it is mandatory since it is a part of the steps described in the SK. It does not say whether it is mandatory or optional, so it's best to assume that it is mandatory.".&amp;nbsp; (That was from an escalation engineer)&lt;/P&gt;&lt;P&gt;So it seems they don't know either... But if you have experience with leaving it empty, it might be possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yesterday in a maintenance window, I tried to configure OCSP again and followed the SK step by step except leaving the certificate empty.&lt;/P&gt;&lt;P&gt;In the customers environment, only the Intermediate CA supports OCSP but the SK explicitly mentions the Root CA so I tried the following in GuiDBedit:&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;1. Assign OCSP server object to Root CA like mentioned in the SK &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In iked.elg debugs I can see some OCSP related debugs but the verification ends with "fwCert_ValRevoke_cb: OCSP responder returned an 'unauthorized' status"&lt;/LI&gt;&lt;LI&gt;The certificate I was using is definitely not revoked(checked that with PKI team)&lt;/LI&gt;&lt;LI&gt;POST requests to /OCSP can be seen in the web server logs&lt;/LI&gt;&lt;LI&gt;My guess would be that it tries to check my certificate which is issued by the Intermediate CA, against the Root CA&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;2. Assign OCSP server object to Intermediate CA&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="3"&gt;Comparing the flow, I don't see any related OCSP debugs&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="3"&gt;POST requests to /OCSP are not present&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Is it possible that OCSP on Intermediate CAs is not supported?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Thank you and best regards&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Constantin&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 06:18:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212127#M8555</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2024-04-24T06:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Help with OCSP, few questions regarding the configuration</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212160#M8563</link>
      <description>&lt;P&gt;Since I dont like to assume anything, I would not say that, but based on what customer informed me, it does work...is it officially supported, I have no clue, sorry.&lt;/P&gt;
&lt;P&gt;Is it possible that OCSP on intermediate CA is not supported? I dont know 100% if that would be the case, but based on the research I did, appears it is doable. How, that Im not certain.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 11:16:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Help-with-OCSP-few-questions-regarding-the-configuration/m-p/212160#M8563</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-24T11:16:56Z</dc:date>
    </item>
  </channel>
</rss>

