Fortinet white logo
Fortinet white logo

CLI Reference

config vpn certificate ocsp-server

config vpn certificate ocsp-server

OCSP server configuration.

config vpn certificate ocsp-server
    Description: OCSP server configuration.
    edit <name>
        set url {string}
        set cert {string}
        set secondary-url {string}
        set secondary-cert {string}
        set unavail-action [revoke|ignore]
        set source-ip {string}
    next
end

config vpn certificate ocsp-server

Parameter

Description

Type

Size

Default

name

OCSP server entry name.

string

Maximum length: 35

url

OCSP server URL.

string

Maximum length: 127

cert

OCSP server certificate.

string

Maximum length: 127

secondary-url

Secondary OCSP server URL.

string

Maximum length: 127

secondary-cert

Secondary OCSP server certificate.

string

Maximum length: 127

unavail-action

Action when server is unavailable (revoke the certificate or ignore the result of the check).

option

-

revoke

Option

Description

revoke

Revoke certificate if server is unavailable.

ignore

Ignore OCSP check if server is unavailable.

source-ip

Source IP address for dynamic AIA and OCSP queries.

string

Maximum length: 63

config vpn certificate ocsp-server

config vpn certificate ocsp-server

OCSP server configuration.

config vpn certificate ocsp-server
    Description: OCSP server configuration.
    edit <name>
        set url {string}
        set cert {string}
        set secondary-url {string}
        set secondary-cert {string}
        set unavail-action [revoke|ignore]
        set source-ip {string}
    next
end

config vpn certificate ocsp-server

Parameter

Description

Type

Size

Default

name

OCSP server entry name.

string

Maximum length: 35

url

OCSP server URL.

string

Maximum length: 127

cert

OCSP server certificate.

string

Maximum length: 127

secondary-url

Secondary OCSP server URL.

string

Maximum length: 127

secondary-cert

Secondary OCSP server certificate.

string

Maximum length: 127

unavail-action

Action when server is unavailable (revoke the certificate or ignore the result of the check).

option

-

revoke

Option

Description

revoke

Revoke certificate if server is unavailable.

ignore

Ignore OCSP check if server is unavailable.

source-ip

Source IP address for dynamic AIA and OCSP queries.

string

Maximum length: 63