OCSP


is ocsp responder checking certificate status against crl/deltacrl or ca database?

if it's against crl/deltacrl isn't there still possibility ocsp response valid although certificate may have been revoked?

thanks,

paul

per last point, talking ocsp servers in general.

microsoft uses crls make revocation decision. tumbleweed uses direct connection ca database

what need remember 2008/2008r2 ocsp responders built increase performance of revocation checking, not timeliness of revocation response.

the ocsp server never ca publish new crl. if there no cached crl, online responder check see if updated crl exists.

brian



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group