OSCP request cache time

Ruslan Mullagaliev 0 Reputation points
2025-07-01T07:00:19.02+00:00

Hello, everyone!

I recently added an OSCP check to the Azure Application Gateway because we use mTLS to communicate with the tablet. It's working well, but as far as I know, the AGW uses a cache mechanism to store the answer from the OCSP server for between 4 and 24 hours, depending on the nextUpdate value. How can I check this value?

Second, are AGW logs expected to not store declined requests with absent or revoked certificates? In the AccessLog and FirewallLog, I only see successful requests, even though I receive a 400 error in the browser for both scenarios.

Thanks in advance!

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,219 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.