OCSP (Online Certificate Status Protocol) is designed to provide real-time revocation status. If an OCSP responder returns a status of 'unknown' , it means the responder has no record of the certificate. From a security standpoint, ClearPass treats any response other than 'Good' as a failure. To prevent potential unauthorized access via certificates that the PKI cannot verify, ClearPass will reject the authentication attempt.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit