Forum Discussion

Chris_Bone's avatar
Chris_Bone
Icon for Nimbostratus rankNimbostratus
Aug 13, 2013

OCSP Responder i-Rule

I need an i-Rule to poll specific OCSP responder URL's every few seconds to test reachability/availability and then send a snmp trap if a response is not received within a given time.

 

Can anyone help. Cheers Chris

 

1 Reply

  • Your best bet I think is a custom external monitor. You can use OpenSSL to actually test the responders (make an OCSP request), and then use one of the command line SNMP tools (ie. snmpset) based on the OCSP response. Create a pool of all of your OCSP servers, apply the monitor, and it'll cycle through them on a defined schedule. Take a look at the sample monitors in /config/monitors.