Skip to content

GlobalProtect guide: add a revocation check with OCSP - #565

Merged
joshdrake merged 2 commits into
mainfrom
docs/globalprotect-revocation
Oct 6, 2026
Merged

joshdrake merged 2 commits into
mainfrom
docs/globalprotect-revocation

Conversation

@joshdrake

@joshdrake joshdrake commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What changes

The GlobalProtect guide told readers to "Configure OCSP or CRL if your CA publishes one." This replaces that line with a new step, 7. Check certificate revocation:

  • What a Smallstep authority with active revocation puts in each certificate, and how to confirm it.
  • Use OCSP, and do not select Use CRL.
  • Which certificate profile option decides fail-open or fail-closed when the responder cannot be reached.
  • How to revoke a certificate with the API (decimal serial), and what the firewall logs when it refuses one.
  • The firewall's two status caches, and the two commands that clear them.
  • What happens when the firewall cannot reach the responder, including the one-hour back-off after five failures.

Step 2.6 now points to the new step.

For reviewers

  • This states publicly that PAN-OS 12.1.5 cannot use the Smallstep CRL and that the OCSP answer is cached for 24 hours. Say if the wording should be softer.
  • The text gives no cache duration beyond the 24-hour Next Update.
  • vale reports spelling errors for sslmgr and dataplane inside the new code blocks, the same class of error the file already has for its JSON field names.

Replaces the one line that said to configure OCSP or CRL with a step tested on
PAN-OS 12.1.5: what Smallstep publishes, why to use OCSP and not the CRL, the
option that decides fail-open or fail-closed, how to revoke, the firewall's
two status caches and how to clear them, and what happens when the responder
cannot be reached.
@joshdrake joshdrake changed the title GlobalProtect guide: add a tested revocation check with OCSP GlobalProtect guide: add a revocation check with OCSP Oct 6, 2026
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@joshdrake
joshdrake marked this pull request as ready for review October 6, 2026 21:13
@joshdrake
joshdrake requested a review from a team as a code owner October 6, 2026 21:13
@joshdrake
joshdrake merged commit 99bcf80 into main Oct 6, 2026
3 of 4 checks passed
@joshdrake
joshdrake deleted the docs/globalprotect-revocation branch October 6, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants