Introduction

The Online Certificate Status Protocol (OCSP) provides a way to verify the status of certificates, for example when establishing VPN connections. The devices use this protocol to investigate whether the issuer has revoked the certificate before its expiry, so marking it as invalid.

Certificate issuers update the status of all issued certificates on a special server, the OCSP responder. The OCSP client (e.g. a VPN router that wants to establish a connection) uses the HTTP protocol to send an OCSP request to the responder to verify the certificate. The responder answers with a signed response, which the OCSP client uses to verify its validity. The message from the OCSP responder describes one of the following conditions:
You can use the OCSP to complement or substitute certificate verification by certificate revocation lists (CRL). OCSP offers the following advantages when compared to CRLs:

www.lancom-systems.com

LANCOM Systems GmbH | A Rohde & Schwarz Company | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E‑Mail info@lancom.de

LANCOM Logo