[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
OCSP
Hi,
I'm just wondering where, according to the RCF, the OCSP responder may get his information besides a CRL? May an OCSP responder get his information from a list of to-be-published-certificates-on-the-crl? If so, how can an entity check the validity of an OCSP respondes if the source of the OCSP responder is a system he/she cannot check?
Which ways are open to an OCSP responder to retrieve information about certificates? May those 'ways' also contain proprietary means?
Should a responds by an OCSP responder always be in such a way that it can be validated without the use of an OCSP responder, this implies that an OCSP responder can only use a CRL as a basis of his response or any other public way?
Best regards,
Haaino