Skip to main content
ndumaj
Staff
Staff
November 13, 2023

Technical Tip: How to enable OCSP support and OCSP responder errors on FortiNAC

  • November 13, 2023
  • 0 replies
  • 2273 views
Description This article provides an OCSP introduction and configuration in FortiNAC. Follow this document for a description:

OCSP for X.509 certificate revocation checking 


This protocol specifies the data that needs to be exchanged between an application checking the status of one or more certificates and the server providing the corresponding status.

 

This specification defines the following definitive response indicators for use in the certificate status value:

  • Good: The 'good' state indicates a positive response to the status inquiry.
  • Revoked: The 'revoked' state indicates that the certificate has been revoked, either temporarily (the revocation reason is certificateHold) or permanently.
  • Unknown: The 'unknown' state indicates that the responder does not know about the certificate being requested, usually because the request indicates an unrecognized issuer that is not served by this responder.
Scope FortiNAC legacy, FortiNAC-F.
Solution

Enable Online Certificate Status Protocol (OCSP) support in FortiNAC.
Go into FortiNAC -> Network -> RADIUS -> Local RADIUS configuration Details and enable OCSP.


OCSP.png

 

If enabled, EAP-TLS client certificates will have OCSP verification performed using the URL embedded in the client certificate.
Important: Certificates must contain the OCSP URL. Otherwise, client authentication will fail.

Enable RADIUS debug and Troubleshooting:


OCSP1.png

 

Error: OCSP: Response Status: unauthorized <---- This means that OCSP Service Nonces is not enabled on the Server.


OCSP2.png


Microsoft implementation of OCSP is compliant with RFC 5019 The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume Environments, which is a simplified version of RFC 2560 X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP.

It is possible to force the Microsoft OCSP service to accept those signed requests and reply with the correct signed response. Navigate to Revocation Configuration -> RevocationConfiguration1 -> Edit Properties and select the option to Enable NONCE extension support.


OCSP3.png

 
Related documents:
RFC 6960 (Section 2)
Microsoft OCSP handshake issue

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!