Validity check of syslog server certificates is performed on the TOE during upload as well as during session establishment with the syslog server.
OCSP responders must be setup for the leaf as well as intermediate CA certificates so that the TOE can process the certificates with OCSP URLs in them.
If the connection cannot be established for the validity check, the administrator should check that:
The OCSP responders are setup for all leaf and intermediate CA certificates during loading as well as connection establishment.
OCSP responders are set up as per the information in the OCSP URL of the certificates such as IP address and port number
Index file being passed to the OCSP responders include correct details of all certificates being verified.
Appropriate OCSP signer and CA certificates and private keys are passed to the responders.
OCSP requests and responses use CertID.issuerNameHash and CertID.issuerKeyHash parameters to validate the revocation status of CA certificates.
Note
In a Common Criteria (CC) evaluated configuration, revocation using OCSP is not claimed for Sensor - Manager channel.