Further, the requestor which sent a nonce and received a
non-nonced response can today infer "responder does not support
nonces."The requirement is to bind a request to its associated response and thus enable relying parties to mitigate replay risks. I remain curious to an understanding of how unilateral server-side response extensions achieve this effect.
In the instance of explicit delegation from a certification authority, there then exists a business entity which places itself in a position of risk against damage claims. Are you suggesting that an OCSP responder's unilateral inclusion of a technical artifact is an assertion of willingness to absorb such risks?
Thanks, Dave