RFC 4806:Online Certificate Status Protocol (OCSP)...
RFC-Ref

certificate


Click on the red underlined text to get to the source

... public key based authentication. Confirmation of certificate reliability is essential in order to achieve the security ...
... public key cryptography provides. One fundamental element of such confirmation is reference to certificate revocation status (see [RFC3280 ...
... RFC3280] for additional detail). The traditional means of determining certificate revocation status is through the use of Certificate Revocation Lists ...
... certificate revocation status is through the use of Certificate Revocation Lists (CRLs). IKEv2 allows ...
... participant. Such network access deadlock further contributes to a reduced reliance on the status of certificate revocations in favor of blind trust ...
... IKEv2 signaling of a certificate's revocation status. ...
... OCSP for in-band signaling of certificate revocation status. A new content encoding ...


... IANA Considerations section of this document): Certificate Encoding Value -------------------- ----- OCSP ...
... OCSP responder certificate hashes in the Certificate Authority field of the CERTREQ ...
... certificate hashes in the Certificate Authority field of the CERTREQ payload ...
... (a) the CA who issued the certificate (b) a Trusted Responder ...
... Responder (Authorized Responder) who holds a specially marked certificate issued directly by the CA, indicating that the responder ...
... OCSP response is signed by the CA who issued the certificate. In case of (c), the OCSP response is signed by the CA ...
... Payload indicates the presence of an OCSP response in the Certificate Data field of the CERT ...
... CERT payload carrying a certificate can be achieved by matching the OCSP response CertID field to the certificate ...
... certificate can be achieved by matching the OCSP response CertID field to the certificate. See [RFC2560] for the definition of OCSP response ...


... trust anchor hashes as the Certification Authority value of a single CERTREQ message. There is no means however to indicate which among those ...
... message. There is no means however to indicate which among those hashes, if present, relates to the certificate of a trusted OCSP responder ...
... hashes. The Certification Authority value in an OCSP request CERTREQ SHALL be ...
... nodes be configured to try OCSP and, if there is no response, attempt to determine certificate revocation status by some other means. ...
... OCSP response CERT payload corresponding to the certificate needed to verify its signature on IKEv2 ...
... payload is out of scope of this document. The Certificate Data field of an OCSP response CERT ...


... HDR, SK {IDi, CERT(certificate),--> CERT(OCSP Response ...
... IDr, CERT(certificate), CERT(OCSP Response ...
... Initiator sends in (3) both a CERT payload carrying its certificate and an OCSP response CERT ...
... OCSP response CERT payload covering that certificate. In (3), Initiator also requests an OCSP response ...
... payload. In (4), the Responder returns its certificate and a separate OCSP response CERT ...
... OCSP response CERT payload covering that certificate. It is important to note that in this scenario, the Responder ...
... Responder in (2) does not yet possess the Initiator's certificate and therefore cannot form an OCSP request as defined in [RFC2560 ...
... gateway. Note that OCSP is used for the certificate status check of the server side IKEv2 ...
... the server side IKEv2 certificate and not for certificates that may be used within EAP ...
... server side IKEv2 certificate and not for certificates that may be used within EAP methods ...
... IDr, CERT(certificate), CERT(OCSP Response ...


... replay attacks in which an old (good) response is replayed prior to its expiration date but after the certificate has been revoked. Deployments of OCSP should carefully ...


... IKEv2 Cert Encoding field of the Certificate Payload format. Official assignment of the "OCSP Content" extension to the Cert Encoding ...
... IANA. Certificate Encoding Value -------------------- ----- OCSP ...


... X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP", RFC 2560prop, June 1999. ...
... Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile ...
... X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile", RFC 3280prop ...



Google
Web
RFC-Ref