Configure Revocation Status Verification of Certificates Used for SSL/TLS Decryption (PAN-OS & Panorama)
Focus
Focus

Configure Revocation Status Verification of Certificates Used for SSL/TLS Decryption (PAN-OS & Panorama)

Table of Contents


Configure Revocation Status Verification of Certificates Used for SSL/TLS Decryption (PAN-OS & Panorama)

  1. Define the service-specific timeout intervals for revocation status requests.
    1. Select DeviceSetupSession and, in the Session Features section, select Decryption Certificate Revocation Settings.
    2. Perform one or both of the following steps, depending on whether the firewall will use Online Certificate Status Protocol (OCSP) or the Certificate Revocation List (CRL) method to verify the revocation status of certificates. If the firewall will use both, it first tries OCSP; if the OCSP responder is unavailable, the firewall then tries the CRL method.
      • In the CRL section, select the Enable check box and enter the Receive Timeout. This is the interval (1-60 seconds) after which the firewall stops waiting for a response from the CRL service.
      • In the OCSP section, select the Enable check box and enter the Receive Timeout. This is the interval (1-60 seconds) after which the firewall stops waiting for a response from the OCSP responder.
      Depending on the Certificate Status Timeout value you specify in step 2, the firewall might register a timeout before either or both of the Receive Timeout intervals pass.
  2. Define the total timeout interval for revocation status requests.
    1. Enter the Certificate Status Timeout.
      This is the interval (1-60 seconds) after which the firewall stops waiting for a response from any certificate status service and applies the session-blocking logic you optionally define in step 3. The Certificate Status Timeout relates to the OCSP/CRL Receive Timeout as follows:
      • If you enable both OCSP and CRL—The firewall registers a request timeout after the lesser of two intervals passes: the Certificate Status Timeout value or the aggregate of the two Receive Timeout values.
      • If you enable only OCSP—The firewall registers a request timeout after the lesser of two intervals passes: the Certificate Status Timeout value or the OCSP Receive Timeout value.
      • If you enable only CRL—The firewall registers a request timeout after the lesser of two intervals passes: the Certificate Status Timeout value or the CRL Receive Timeout value.
    2. Click OK.
  3. (Optional) Define the blocking behavior for a certificate status of “unknown” or a revocation status request timeout.
    1. Select Objects Decryption Decryption Profile, and select an existing profile or create a new one.
    2. Edit the SSL Forward Proxy Server Certificate Verification settings.
      • To block SSL/TLS sessions when the OCSP or CRL service returns a certificate revocation status of “unknown,” select Block sessions with unknown certificate status. Otherwise, the firewall proceeds with the session.
      • To block SSL/TLS sessions after the firewall registers a request timeout, select Block sessions on certificate status check timeout. Otherwise, the firewall proceeds with the session.
    3. Click OK.
  4. Commit your changes.