Re: Clarification on OCSP with nonce

"Dr. Pala" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Hi Koichi,

unfortunately the current status of OCSP responders is not the greatest
- for most CAs in the "browsers" ecosystem, responses are pre-calculated
and delivered via CDNs. Thus, the NONCE can not be added to responses.

We are currently working with different partners (some public CAs and
other entities) on proposing an updated version the OCSP specs (think of
it as OCSPv2) that address the current limitations of the protocol (we
need this in many ecosystems where millions of devices are deployed) by
lowering the number of signatures required from an OCSP responder - this
would also help in producing shorter-lived responses thus increasing the
security of the system (e.g., instead of the validity being 3 to 7 days,
responses can have few hours to 1 day validity periods).

Since there is no venue at the IETF to propose this work, we are
currently working with other standardization groups that are willing to
address this issue :D

In case you are interested in participating, please let me know, we are
very open to collaboration :D

Cheers,
Max


On 3/12/18 10:06 AM, Koichi Sugimoto wrote:
>
> Hello.
>
>  
>
>  
>
> There is a description about OCSP with nonce in RFC 6960, but there is
> no description for the behavior of OCSP responder when the client
> sends an OCSP request with nonce.
>
> Specifically, will the OCSP responder that receives the OCSP request
> with nonce give me an opinion on whether to omit the nonce and return
> the response?
>
> In the discussion on the previous OCSP, I remember that there was an
> opinion that the conclusion has already been made in RFC 3161
> regarding the behavior of nonce, and there is nothing to argue about OCSP.
>
> Recently OCSP traffic has been increasing, so in order to reduce the
> load on the signature engine of the OCSP responder, I often want to
> clarify because I want to omit the nonce and return a response.
>
>  
>
>  
>
> Regards,
>
> Koichi Sugimoto.
>
>
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.