OCSP Certificate Status Checker
Description
A configurable certificate status checker using OCSP (Online Certificate Status Protocol) to check the status of certificates.
The OCSP responder to check the revocation status of a certificate is determined by the X509v3 Authority-Information-Access-Extension of the certificate. The issuer certificate to sign the response must be provided in the configured truststore (OCSP signing delegation is not supported, therefore the certificate to sign the response must be the issuer certificate of the certificate for which the request was performed).
May be used by
OAuth 2.0 Client mTLS Authentication Caching Certificate Status Checker STET PSD2 Authenticator NextGenPSD2 Certificate Authenticator Certificate Authenticator Certificate Authenticator CRL Distribution Point Extension CRL Checker Certificate Token Authenticator HTTP Signature Verification Credential Extractor Client Certificate (X.509) Request Authentication
Properties
OCSP Client (
ocspClient) Description
The OCSP-Client to perform the OCSP requests.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Trust Store Path (
trustStorePath) Description
Keystore file name containing trusted certificates of trusted OCSP responders.
Attributes
File/Path
Mandatory
Trust Store Type (
trustStoreType) Description
Identifies the type of the keystore.
Attributes
String
Optional
Default value
JKS
Allowed values
JKS, PKCS12
Trust Store Password (
trustStorePassword) Description
The password used verify the authenticity of the trust store.
Depending on the keystore type, leaving this property empty (or undefined) has a different effect:
- JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
- PKCS12: an error occurs.
Attributes
String
Optional
Sensitive
Disable Nonce Validation (
disableNonceValidation) Description
Request and response are cryptographically bound using a nonce to prevent replay attacks. IAM always sends a nonce with the request and validates the nonce in the response. For OCSP servers that don't return the nonces, validation can be disabled.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: OcspCertificateStatusChecker
id: OcspCertificateStatusChecker-xxxxxx
displayName:
comment:
properties:
disableNonceValidation: false
ocspClient:
trustStorePassword:
trustStorePath:
trustStoreType: JKS