Re: Optimizing OCSP - Time for some spec work ?
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Denis <[email protected]> writes: >What you are proposing is not an optimization of OCSP but something >different It is very definitely an optimisation of OCSP, and in particular one that's far better than the current "optimisation" of droppping the nonce and accepting replayed responses as current as a hack to deal with OCSP's non-scalability. The only concern I'd have is that it'd need to have some data on how effective it'll actually be in practice. Let's say you have x% loading due to revocations, so x% of all certs are revoked, and also y% loading of cert statuses, so y% of certs are actively queried via OCSP. At what point does x get high enough that the fragmentation of the serial number ranges negates any specific benefit from pre-generating responses for a subrange, and how much mitigation do different y values provide for the fragmentation issue? So it'd need a research publication to demonstrate there's a benefit, and under what conditions, after which it'd certainly be a better bugfix for OCSP than the accept-replayed-responses kludge. Peter. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix