-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
-
Web proxy support for outbound calls to IDP or third party endpoints
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Configure protected user as an authentication factor in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
-
-
Configure DNS resource records
-
Configure NetScaler as a non-validating security aware stub-resolver
-
Jumbo frames support for DNS to handle responses of large sizes
-
Caching of EDNS0 client subnet data when the NetScaler appliance is in proxy mode
-
Use case - configure the automatic DNSSEC key management feature
-
Use Case - configure the automatic DNSSEC key management on GSLB deployment
-
-
-
Source IP address whitelisting for GSLB communication channels
-
Use case: Deployment of domain name based autoscale service group
-
Use case: Deployment of IP address based autoscale service group
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Support for hybrid Post Quantum cryptography on the frontend
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
Zero-touch certificate management
-
Cert Revocation using OCSP or OCSP Stapling in Zero Touch Cert Management
-
-
-
Authentication and authorization for System Users
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Certificate revocation using OCSP or OCSP stapling in zero touch certificate management
The certificate revocation using OCSP or OCSP Stapling in zero touch certificate management feature introduces automatic creation and management of OCSP responders for certificates handled through the zero touch certificate management workflow.
OCSP validation in zero touch management only works if the certificate includes an OCSP URL in the Authority Information Access (AIA) extension. Since external or Command Line Interface (CLI) OCSP responder configurations are unavailable for zero touch certificates, OCSP revocation check cannot be performed when the AIA field is missing.
This feature automates the creation and binding of an OCSP responder using the OCSP URL embedded within the certificate itself. This validation capability applies to certificates:
-
Pulled from the Console Cert Repository into NetScaler.
-
Received by NetScaler from a peer during the SSL/TLS handshake process.
The system automatically creates and manages OCSP responders based on the method by which NetScaler receives the certificate, provided the certificate contains the OCSP field in the AIA extension.
| Certificate Source | Action Upon Certificate Receipt | Responder Lifespan or Management |
|---|---|---|
| Pulled from Console Cert Repository | An OCSP responder is created using the OCSP URL from the certificate and is immediately bound to that certificate. | The OCSP responder persists in NetScaler as long as the certificate exists. |
| From a Peer During SSL Handshake | An OCSP responder is created using the OCSP URL from the certificate and is immediately bound to that certificate. | The OCSP responder is deleted after 15 minutes if it remains unused. |
This feature ensures automation of all manual configurations that was previously required for certificate revocation. By binding the OCSP responder directly from the certificate’s embedded OCSP URL, it:
-
Eliminates dependencies on other certificates.
-
Ensures that all certificate types (server, client, and CA) have their necessary OCSP responder bindings for automated revocation checks.
Global zero touch OCSP parameter configuration
Default values for Zero Touch OCSP settings are provided automatically and can be viewed with the show zerotouch command. These global settings are used to validate the received OCSP response.
| Parameter | Description |
|---|---|
| -ocspCacheTimeout |
Minimum: 1 Maximum: 43200
Default: 1 Unit: Minutes Units: Minutes |
| -ocspHttpMethod
|
Possible Values: POST or GET
Default: POST |
| -ocspTrustResponder
|
Possible Values: YES or NO
Default: NO |
| -ocspUseNonce
|
Possible Values: ENABLED or DISABLED
Default: ENABLED |
| -ocspResptimeout
|
Minimum: 100 Maximum: 120000
Default: 2000 Units: Milliseconds |
| -ocspbatchingDelay |
Minimum: 1 Maximum: 10000
Default: 100 Units: Milliseconds |
| -ocspbatchingDepth |
Minimum: 1 Maximum: 8 Default: 1
Default: 1 |
| -ocspUrlResolveTimeout |
Minimum: 100 Maximum: 2000 Default: 100 Units: Milliseconds.
Default: 100 Units: Milliseconds |
| -ocspProducedAtTimeSkew |
Maximum: 86400
Default: 300 Units: Seconds |
Example modification (if necessary)
set ssl zerotouchparam -ocspCacheTimeout 1 -ocspBatchingDepth 1 -ocspBatchingDelay 100 -ocspResptimeout 4000 -ocspUrlResolveTimeout 1000 -ocspProducedAtTimeSkew 300 -ocspUseNonce ENABLED -ocspTrustResponder YES -ocspHttpMethod POST
<!--NeedCopy-->
SSL policy support for Per-virtual server or service control
SSL policies can be used to control OCSP revocation checks at a granular level (for each virtual server or service)
Front-end SSL handshake (client-Side)
OCSP stapling
Used to send the OCSP response as a certificate status handshake message to the SSL client.
The option to cache OCSP responses is provided at the policy level, enabling each virtual server or service to decide whether to cache OCSP responses. Cached responses are reused later, eliminating the need to send OCSP requests repeatedly.
Operational flow:
-
When a ClientHello message includes the status_request extension, the server parses this extension.
-
If ocspStapling is ENABLED through policy binding:
-
If the cache is ENABLED and a valid cache entry is available in NetScaler, the cached OCSP response is used and sent to the client.
-
If a cache entry is not available, an OCSP request is sent using the OCSP responder created from the SSL server certificate. The SSL handshake is put on hold until the request timeout.
-
-
The received OCSP response is validated using the global OCSP settings from
zerotouchparam. -
The OCSP response is then cached if CACHE ENABLE is set in the SSL action of the SSL policy.
Note:
OCSP stapling is available in the profile and can be used to enable the feature. However, if OCSP Stapling is enabled in both the profile and a policy, the policy settings takes precedence.
| Parameter | Description |
|---|---|
| ocspStapling | ENABLED or DISABLED |
| ocspCache | ENABLED or DISABLED (Default: DISABLED) |
Example configuration:
add ssl action ocsp_stapling_action -ocspStapling ENABLED -cache ENABLED
add ssl policy ocsp_stapling_policy -rule TRUE -action ocsp_stapling_action
bind ssl vserver vs192 -policyName ocsp_stapling_policy -priority 10 -type CLIENTHELLO_REQ
<!--NeedCopy-->
Client certificate authentication OCSP validation
Used to validate the revocation status of a client certificate received during the handshake.
| Parameter | Description |
|---|---|
| ocspCertValidation
|
Possible Values: Disable, Optional and Mandatory
Default: DISABLED |
| ocspCache
|
Possible Values: Disable or Enabled
Default: DISABLED |
Note:
When the SSL action uses the
ocspStaplingorocspCertValidationattributes, only the TRUE expression is supported.
Example configuration (client auth):
add ssl action ocsp_peercert_action -ocspCertValidation MANDATORY -ocspCache ENABLED
add ssl policy ocsp_peercert_policy -rule TRUE -action ocsp_peercert_action
bind ssl vserver vs74 -policyName ocsp_peercert_policy -priority 10 -type CLIENT_AUTH_VAL
<!--NeedCopy-->
Backend SSL handshake (server-side)
Used to validate the revocation status of the server certificate received from the backend SSL server.
| Parameter | Description |
|---|---|
| ocspCertValidation
|
Possible Values: Disabled, Optional, and Mandatory
Default: DISABLED |
| ocspCache
|
Possible Values: Disabled or Enabled
Default: DISABLED |
Example configuration:
add ssl action ocsp_peercert_action -ocspCertValidation MANDATORY -ocspCache ENABLED
add ssl policy ocsp_peercert_policy -rule TRUE -action ocsp_peercert_action
bind ssl vserver vs74 -policyName ocsp_peercert_policy -priority 10 -type SERVER_AUTH_VAL
<!--NeedCopy-->
Notes:
- When the SSL action uses the
ocspStaplingorocspCertValidationattributes, only the TRUE expression is supported.- Policy support feature is supported to both Zero Touch and non-Zero Touch Certificates. For non-Zero Touch Certificates, policy binding takes precedence over SSL Profile settings.
Limitations
OCSP responder creation limits:
The number of automatically created OCSP responders is subject to system-wide limits to ensure stability and resource management.
| Certificate Source | Limit | Behavior When Limit is Reached |
|---|---|---|
| Certificates from Console | 4096 | Certificate creation succeeds, but no permanent OCSP responder is created. If OCSP stapling is configured on the VIP, a responder is created temporarily during the SSL handshake to fetch the status, and then deleted immediately after serving the response to maintain the limit. |
| Certificates from SSL Peer During Handshake | 1024 | A responder is created to perform the revocation check. After the handshake, the responder is added to the cache only if an existing entry can be evicted from the Least Recently Used (LRU) list. If eviction is not possible, the new OCSP responder is immediately deleted. |
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.