| (I) An Internet protocol used by a client to obtain from a server
the validity status and other information concerning a digital
certificate.
(C) In some applications, such as those involving high-value
commercial transactions, it may be necessary to obtain certificate
revocation status that is more timely than is possible with CRLs
or to obtain other kinds of status information. OCSP may be used
to determine the current revocation status of a digital
certificate, in lieu of or as a supplement to checking against a
periodic CRL. An OCSP client issues a status request to an OCSP
server and suspends acceptance of the certificate in question
until the server provides a response.
|