Two way OCSP Stapling and Configuring Windows responder URLs w/o AIA presence

daniel bryan <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CAJKvcBSV8rbVOyXJA0j-jTsA2tvg==yz9Gfns3SU6ZYUG=+dbQ@mail.gmail.com>
I believe i understand the concept of OCSP stapling in regards to a
webserver presenting it's own certificate status to the browser client in
the TLS handshake. I am curious if a client (personal certificate with
digital signature key usage) authenticating to a webserver with their
certificate can also present it's own certificate status so the webserver
doesn't have to determine the status from an OCSP service.

1.) Does the standard allow for this? I believe it does since the verbage
says "It allows the presenter of a certificate to bear the resource cost
involved in providing OCSP responses by appending ("stapling") a
time-stamped <https://en.wikipedia.org/wiki/Timestamp> OCSP response signed
<https://en.wikipedia.org/wiki/Cryptographic_signature> by the CA to the
initial TLS Handshake
<https://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_handshake>"

2.) How is this configured in client browsers, are 3rd party addons
required?

Vaguely related, but i remember their being a dependency on windows ability
to provide a stapled response via IIS. It required the presence of an OCSP
url in the webservers AIA field. I would like to overwrite/hardcode the
URL, like you can do in (certmgr.msc) certificate properties adding a
responder URL. Sort of like doing a "SSLStaplingForceURL uri" directive in
apache.  I posted this question on the iss forums about this, but was not
able to get a resolution.
http://forums.iis.net/t/1221792.aspx?OCSP+STAPLING+ForceURL+Option


1.) Is it possible to configure windows to use a specific responder url for
providing stapled responses when an ocsp url is not present in the AIA of
the servers certificate?




Thanks,

Dan

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.