Wireless Access

 View Only
  • 1.  Clearpass and OCSP configuration

    Posted Feb 03, 2026 08:18 AM

    Hello,

    I'm looking to configure OCSP in Clearpass with Microsoft PKI environment.  

    In my service, I used authentication method EAP-TLS with OCSP enabled.

    When my clients tried to connect to our wifi, it received that error:

     Do I have to add some permission to the OCSP server for Clearpass ?  Have you any idea that I could check?

    Thank you!



    -------------------------------------------


  • 2.  RE: Clearpass and OCSP configuration

    Posted Feb 03, 2026 08:32 AM

    Is the OCSP URL reachable?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Clearpass and OCSP configuration

    Posted Feb 03, 2026 09:11 AM

    Yes URL reachable, i tested it with cerutil -url.

    -------------------------------------------



  • 4.  RE: Clearpass and OCSP configuration
    Best Answer

    Posted Feb 03, 2026 09:37 AM

    Hello!

    I just found the solution in another forum (https://learn.microsoft.com/en-us/answers/questions/1184100/ocsp-handshake-issue).

    I activated NONCE extension support in properties of the Revocation Configuration on the OCSP server and reboot.

    All is working now.

    Thank you

    -------------------------------------------



  • 5.  RE: Clearpass and OCSP configuration

    Posted Feb 03, 2026 04:25 PM

    Great, thank you very much for this useful information. It has been very helpful to me.



    ------------------------------
    Daniel Ruiz
    -----------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support.
    Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
    ------------------------------



  • 6.  RE: Clearpass and OCSP configuration

    Posted Feb 03, 2026 05:10 PM

    For OCSP, by default ClearPass uses nonce with random value (to prevent replay attack) and it expects the same nonce value back. also if you have a OCSP server that does not support nonce check, then you can turn off the nonce check in ClearPass server settings



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------