To configure Client Certificate Check
Click Certificate Check.
To enable client certificate checking and CAC support on the SonicWall Security Appliance, select Enable Client Certificate Check. If you enable this option, the other options become available. A warning confirmation message displays:
To activate the client certification cache, select Enable Client Certificate Cache.
The cache expires 24 hours after being enabled.
To select a Certification Authority (CA) certificate issuer, choose one from the Client Certificate Issuer drop-down menu. The default is thawte Primary Root CA - G3.
If the appropriate CA is not listed, you need to import that CA into the SonicWall Security Appliance. See Managing Certificates section.
To enable the Online Certificate Status Protocol (OCSP) check to verify the client certificate is still valid and has not been revoked, select Enable OCSP Checking. When this option is enabled, the field displays and the Enable periodic OCSP Check option displays.
Enter the URL of the OSCP server that verifies the status of the client certificate in the OCSP Responder URL field.
The OCSP Responder URL is usually embedded inside the client certificate and does not need to be entered. If the client certificate does not have an OCSP link, you can enter the URL link. The link should point to the Common Gateway Interface (CGI) on the server side, which processes the OCSP checking. For example: http://10.103.63.251/ocsp.