OCSP Status_request Is Not Transmitted by the Firewall When Decryption Is Performed
2044
Created On 12/27/22 12:22 PM - Last Modified 02/14/24 01:06 AM
Symptom
OCSP "status_request" is not transmitted by the firewall when decryption is performed.
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- Decryption Policy
- OCSP (Online Certificate Status Protocol) "status_request"
Cause
- Some clients use OCSP Stapling to improve the efficiency of a TLS handshake when OCSP is used.
- A receive stage packet capture on the firewall contains the "status_request" extension from the client request:
- A transmit stage packet capture on the firewall does not contain a "status_request",
Resolution
- OCSP Stapling is not currently supported by Palo Alto Decryption.
- The behavior of "status_request" being stripped from the request is expected.