OCSP
is ocsp responder checking certificate status against crl/deltacrl or ca database?
if it's against crl/deltacrl isn't there still possibility ocsp response valid although certificate may have been revoked?
thanks,
paul
per last point, talking ocsp servers in general.
microsoft uses crls make revocation decision. tumbleweed uses direct connection ca database
what need remember 2008/2008r2 ocsp responders built increase performance of revocation checking, not timeliness of revocation response.
the ocsp server never ca publish new crl. if there no cached crl, online responder check see if updated crl exists.
brian
Windows Server > Security
Comments
Post a Comment