How Ocsp Services Work; Ocsp Response Signing - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

About OCSP Services

How OCSP Services Work

An OCSP service works as follows:
A CA is set up to issue certificates that include the Authority Information
1.
Access Extension whose value identifies an OCSP responder that can be
queried for the status of the certificate.
One or more CAs periodically publishes CRLs to an OCSP responder.
2.
The OCSP responder maintains the CRL it receives from the CA(s).
3.
An OCSP-compliant client verifies the status of a certificate by sending
4.
requests containing all the information required to identify the certificate to the
OCSP responder for verification. The applications determine the location of the
OCSP responder from the value of the
Extension
The OCSP responder determines if the request contains all the information
5.
required by the responder to process it. If it does not, or if it is not enabled for
the requested service, a rejection notice is sent. If it does have enough
information, it processes the request and sends back a report stating the status
of the certificate. See "OCSP Responses," on page 169 for details on the
responses sent by an OCSP service.

OCSP Response Signing

Every response that the client receives, including a rejection notification, is digitally
signed by the responder; the client is expected to verify the signature to ensure that
the response came from the responder to which it submitted the request. The key
the responder uses to sign the message depends on how the OCSP responder is
deployed in a PKI setup. RFC 2560 recommends that the key used to sign the
response belong to one of the following:
The CA that issued the certificate and whose status is being verified by the
responder.
A responder whose public key, which corresponds to the private key it uses to
sign responses, is trusted by the client. Such a responder is called a trusted
responder.
168
Netscape Certificate Management System Administrator's Guide • February 2003
in the certificate being validated.
Authority Information Access

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents