[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

OCSP



Hi,

I'm just wondering where, according to the RCF, the OCSP responder may get his information besides a CRL? May an OCSP responder get his information from a list of to-be-published-certificates-on-the-crl? If so, how can an entity check the validity of an OCSP respondes if the source of the OCSP responder is a system he/she cannot check? 
Which ways are open to an OCSP responder to retrieve information about certificates? May those 'ways' also contain proprietary means?
Should a responds by an OCSP responder always be in such a way that it can be validated without the use of an OCSP responder, this implies that an OCSP responder can only use a CRL as a basis of his response or any other public way?

Best regards,
Haaino