Hello everyone,
We recently enabled HTTPs encryption, with an implied bypass except a few hosts for testing.
HTTPs inspection is also completely in fail-open mode.
One of our servers that is using an API out to an internet endpoint has been having issues, first it was related to https inspection probing but adding a domain based exception prior to probing rules has fixed that issue. But recently we have been seeing intermittent errors with it.
Only thing I see in logs is an app/url Detect for an unreachable OSCP server. Exact Error message below
OCSP responder returned an 'unauthorized' status reply. Refer to sk159872 for more details.
Certificate DN: '...........' Requested Server Name: ............ See sk159872
I tried adding the entire cert chain to the trusted CA list to no avail.
I more than likely will be getting a tac case opened for this but was wondering if anyone knew of any quick options here.
Thanks,