RFC 6960 Proposed Standard

X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP

S. Santesson, M. Myers, R. Ankney, A. Malpani, S. Galperin, C. Adams · 2013-06

Abstract

This document specifies a protocol useful in determining the current status of a digital certificate without requiring CRLs. Additional mechanisms addressing PKIX operational requirements are specified in separate documents. This document obsoletes RFC 2560.

Why This RFC Matters

RFC 6960 defined OCSP as a real-time alternative to Certificate Revocation Lists (CRLs) for checking whether a TLS certificate has been revoked before the end of its validity period. Unlike CRLs that must be downloaded and parsed in their entirety, an OCSP request asks a CA's responder about one specific certificate, returning a signed 'good', 'revoked', or 'unknown' response. OCSP Stapling (RFC 6066) extends this by having the server include a pre-fetched OCSP response in the TLS handshake, improving both performance and privacy, and is now the standard approach for certificate status in modern TLS deployments.

관련 프로토콜

관련 용어

Security에서 더 보기