Red Hat Training

A Red Hat training course is available for Red Hat JBoss Web Server

10.3. Configure httpd to validate OCSP certificates

Before configuring httpd to validate OCSP certificates ensure Certificate Authority (CA) and OCSP Responder is configured properly. Follow this procedure to perform OCSP validation of client certificates:

Procedure 10.1. To httpd to validate OCSP certificates

  • Use the SSLOCSPEnable attribute to enable OCSP validation.
    # Require valid client certificates (mutual auth)
      SSLVerifyClient require
      SSLVerifyDepth  3
      # Enable OCSP
      SSLOCSPEnable on
      SSLOCSPDefaultResponder http://10.10.10.25:3456
      SSLOCSPOverrideResponder on