The ocsp-url from-ca command configures the PKI entity to obtain the OCSP server's URL from the Authority Info Access (AIA) option in the CA certificate.
The undo ocsp-url from-ca command disables the PKI entity from obtaining the OCSP server's URL from the Authority Info Access (AIA) option in the CA certificate.
By default, a PKI entity does not obtain OCSP server's URL from the CA certificate's AIA option.
Usage Scenario
If a certificate to be checked through OCSP contains the AIA option, run this command to configure the PKI entity to obtain OSCP server's URL from the AIA option. If the certificate does not contain the AIA option, run the ocsp url command to configure the OCSP server's URL.
Precautions
The system can check whether a certificate is revoked only after the ca-name command is executed to associate the PKI realm with a CA.