cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1317
Views
0
Helpful
1
Replies

OCSP request to a specific TCP port

Hello 

We plan to place OCSP responder behind HA Proxy.

Is it possible to configure ISE to send ocsp requests to a specific TCP port for example 888?

In  OCSP Profile

URL  http://test.domai.com:888/ocsp 

Has anyone tested it this way?

1 Reply 1

Mike.Cifelli
VIP Alumni
VIP Alumni

I have not tested this, but I dont see why it would not work.  As long as the responder is listening on that port I dont see this being an issue.  In the OCSP profile you are configuring the url to use.  I would recommend testing it by disabling this under the trusted cert/s for which you assign the OCSP profile to: Reject the request if OCSP Responder is unreachable.  This way clients will remain unaffected.  Then once you confirm it works or does not work you can re-enable.  HTH!