Certificate Authority

Certificate Authority (CA) is an authority in a network that issues and manages security credentials and public keys for message encryption. As part of a Public Key Infrastructure (PKI), a CA checks with a registration authority (RA) to verify information provided by the requestor of a digital certificate. If the RA verifies the requestor's information, the CA can then issue a certificate. The CA also specifies the validity periods of certificates and revokes certificates as needed by publishing CRLs or using Online Certificate Status Protocol (OCSP).

The end entity can choose the revocation type of interest through configuration. OCSP is used for obtaining revocation status of a certificate. When an end entity receives a peer certificate, it sends an OCSP request (over HTTP) to the OCSP server (responder) to know the revocation status of the certificate. The OCSP responder replies back with a signed OCSP Response stating whether the certificate is Good, Revoked or Unknown. If it is not able to process the OCSP request, it reports appropriate errors. The OCSP response can have additional extensions (like OCSPSigning bit) to help customize a particular PKI scheme. If expected extensions are not available in the OCSP response, the end entity can refuse to accept a peer connection.

OCSP Responder running on a Linux device may or may not accept OCSP request received through the HTTP GET method. In such cases, OCSP requests must be sent using the HTTP Post method.

The revocation-check ocsp command is used to set OCSP as the revocation type.

device(config-pki-trustpoint-trust1)# revocation-check ocsp

The ocsp http post command is used to configure the HTTP post method.

device(config-pki-trustpoint-trust1)# ocsp http post