against the root CA using their own ocsp requests. Because most clients will silently ignore ocsp if the query times out, ocsp is not a reliable means of mitigating https server key compromise. Server edit Open Source edit Boulder, 15 CA and ocsp responder developed and used by Let's Encrypt ( Go ) ejbca, 16 CA and ocsp responder ( Java ) XiPKI, 17 CA and ocsp responder. The ocsp request format supports additional extensions. An ocsp responder may be queried for revocation information by delegated path validation (DPV) servers.

The, online Certificate, status Protocol (ocsp) is an Internet protocol used for obtaining the revocation status of.509 digital certificate. It is described in RFC 6960 and is on the Internet standards track. Online Certificate Diploma Programs.

Ocsp does not, by itself, perform any DPV of supplied certificates. An attacker in such a position is also typically in a position to interfere with the client's ocsp queries. In this scenario, Carol's CA database is the only trusted location where a compromise to Alice's certificate would be recorded.

"Revocation checking and Chrome's CRL".