Global Information Lookup Global Information

Online Certificate Status Protocol information


OCSP
Online Certificate Status Protocol
StatusProposed Standard
Year started4 February 2002 (2002-02-04)[1]
First published11 February 2013 (2013-02-11)[1]
Authors
  • Stefan Santesson
  • Michael Myers
  • Rich Ankney
  • Ambarish Malpani
  • Slava Galperin
  • Carlisle Adams
  • Mohit Sahni
Base standards
  • Uniform Resource Identifier (URI)
  • Secure/Multipurpose Internet Mail Extensions (S/MIME)
DomainDigital certificate
Website
  • RFC 6960: OCSP
  • RFC 8954: OCSP Nonce Extension

The Online Certificate Status Protocol (OCSP) is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate.[2] It is described in RFC 6960 and is on the Internet standards track. It was created as an alternative to certificate revocation lists (CRL), specifically addressing certain problems associated with using CRLs in a public key infrastructure (PKI).[3] Messages communicated via OCSP are encoded in ASN.1 and are usually communicated over HTTP. The "request/response" nature of these messages leads to OCSP servers being termed OCSP responders.

Some web browsers (e.g., Firefox[4]) use OCSP to validate HTTPS certificates, while others have disabled it.[5][6] Most OCSP revocation statuses on the Internet disappear soon after certificate expiration.[7]

  1. ^ a b Santesson, Stefan; Myers, Michael; Ankney, Rich; Malpani, Ambarish; Galperin, Slava; Adams, Carlisle (June 2013). "History for draft-ietf-pkix-rfc2560bis-20". Retrieved December 23, 2021.
  2. ^ A., Jesin (June 12, 2014). "How To Configure OCSP Stapling on Apache and Nginx". Community Tutorials. Digital Ocean, Inc. Retrieved March 2, 2015.
  3. ^ "OCSP Stapling". GlobalSign Support. GMO GlobalSign Inc. August 1, 2014. Retrieved March 2, 2015.
  4. ^ "CA/Revocation Checking in Firefox". wiki.mozilla.org. Retrieved 29 June 2022.
  5. ^ "Are revoked certificates detected in Safari and Chrome?". 20 September 2017. Retrieved 29 June 2022.
  6. ^ "CRLSets". Retrieved 29 June 2022.
  7. ^ Korzhitskii, Nikita; Carlsson, Niklas (2021). "Revocation Statuses on the Internet". In Hohlfeld, Oliver; Lutu, Andra; Levin, Dave (eds.). Passive and Active Measurement. PAM 2021. LNCS. Vol. 12671. pp. 175–191. arXiv:2102.04288. doi:10.1007/978-3-030-72582-2_11. ISBN 978-3-030-72582-2. ISSN 0302-9743.

and 26 Related for: Online Certificate Status Protocol information

Request time (Page generated in 1.0709 seconds.)

Online Certificate Status Protocol

Last Update:

The Online Certificate Status Protocol (OCSP) is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate. It is described...

Word Count : 1704

OCSP stapling

Last Update:

The Online Certificate Status Protocol (OCSP) stapling, formally known as the TLS Certificate Status Request extension, is a standard for checking the...

Word Count : 1445

HTTPS

Last Update:

Online Certificate Status Protocol (OCSP) to verify that this is not the case. The browser sends the certificate's serial number to the certificate authority...

Word Count : 4373

Certificate revocation list

Last Update:

certificates. Trusted third party Web of trust Certificate authority Online Certificate Status Protocol "What is Certificate Revocation List (CRL)? - Definition...

Word Count : 1258

Extended Validation Certificate

Last Update:

Extended Validation certificates do not require issuing certificate authorities to immediately support Online Certificate Status Protocol for revocation checking...

Word Count : 2006

Certificate revocation

Last Update:

soft where they do. Certificate revocation lists are too bandwidth-costly for routine use, and the Online Certificate Status Protocol presents connection...

Word Count : 3599

Certificate authority

Last Update:

fail-soft where they do. Certificate revocation lists are too bandwidth-costly for routine use, and the Online Certificate Status Protocol presents connection...

Word Count : 5156

Public key certificate

Last Update:

indicating whether certificates are still valid. They provide this information through Online Certificate Status Protocol (OCSP) and/or Certificate Revocation...

Word Count : 4444

Root certificate

Last Update:

well as issuing backdating certificates. WoSign and StartCom issued a fake GitHub certificate. Online Certificate Status Protocol (OCSP) Superfish SHA-1 Timestamp...

Word Count : 789

Offline root certificate authority

Last Update:

509 Certificate server Extended Validation Certificate Intermediate certificate authority Validation authority Key ceremony Online Certificate Status Protocol...

Word Count : 487

IPsec

Last Update:

AH RFC 4555: IKEv2 Mobility and Multihoming Protocol (MOBIKE) RFC 4806: Online Certificate Status Protocol (OCSP) Extensions to IKEv2 RFC 4868: Using HMAC-SHA-256...

Word Count : 5081

Public key infrastructure

Last Update:

fail-soft where they do. Certificate revocation lists are too bandwidth-costly for routine use, and the Online Certificate Status Protocol presents connection...

Word Count : 4068

CertCo

Last Update:

known as Acquire); and an Online Certificate Status Protocol (OCSP) responder for validating X.509 public key certificates. It went out of business in...

Word Count : 841

S2n

Last Update:

are Server Name Indication, Application-Layer Protocol Negotiation, and Online Certificate Status Protocol. s2n supports the main ciphers in use today,...

Word Count : 421

StrongSwan

Last Update:

supports certificate revocation lists and the Online Certificate Status Protocol (OCSP). A unique feature is the use of X.509 attribute certificates to implement...

Word Count : 767

Digital signature

Last Update:

revocation status requires an "online" check; e.g., checking a certificate revocation list or via the Online Certificate Status Protocol. Very roughly...

Word Count : 5198

Cybersecurity information technology list

Last Update:

Digital signature Certificate policy Certificate Practice Statement Certificate revocation list Online Certificate Status Protocol Computerized utilities...

Word Count : 1789

Network Security Services

Last Update:

the format of certificates used for authentication in public-key cryptography. OCSP (RFC 2560). The Online Certificate Status Protocol (OCSP) governs...

Word Count : 1250

Comparison of email clients

Last Update:

auth, not sure about collaboration suite Online Certificate Status Protocol - Description: RFC 2560 Certificate revocation list - Description: RFC 3280...

Word Count : 2275

Transport Layer Security

Last Update:

Security (TLS) is a cryptographic protocol designed to provide communications security over a computer network. The protocol is widely used in applications...

Word Count : 17090

Index of cryptography articles

Last Update:

compression function • One-way function • Onion routing • Online Certificate Status Protocol • OP-20-G • OpenPGP card • OpenSSH • OpenSSL • Openswan •...

Word Count : 2943

ONTAP

Last Update:

Ethernet network detects maximum MTU size. In ONTAP 9.2: Online Certificate Status Protocol (OCSP) for LDAP over TLS; iSCSI Endpoint Isolation to specify...

Word Count : 11085

Security and safety features new to Windows Vista

Last Update:

the Online Certificate Status Protocol (OCSP) providing real-time certificate validity checking, CRL prefetching and CAPI2 Diagnostics. Certificate enrollment...

Word Count : 5891

Regional Transport Office

Last Update:

the Regional Transport Office/Officer to inspect and issue a certification for protocol management of VIP convoys for to ensure safety and to avoid mismanagement...

Word Count : 820

Notary

Last Update:

in the register or protocol. Taking an acknowledgment (in the United States) of execution of a document and preparing a certificate of acknowledgement...

Word Count : 1086

Features new to Windows Vista

Last Update:

up to 256 bits outlined in RFC 3268 and certificate revocation checking using Online Certificate Status Protocol. The TLS implementation has also been updated...

Word Count : 13863

PDF Search Engine © AllGlobal.net