Re: Optimizing OCSP - Time for some spec work ?

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Denis <[email protected]> writes:

>What you are proposing is not an optimization of OCSP but something 
>different

It is very definitely an optimisation of OCSP, and in particular one that's 
far better than the current "optimisation" of droppping the nonce and 
accepting replayed responses as current as a hack to deal with OCSP's 
non-scalability.

The only concern I'd have is that it'd need to have some data on how
effective it'll actually be in practice.  Let's say you have x% loading due
to revocations, so x% of all certs are revoked, and also y% loading of cert
statuses, so y% of certs are actively queried via OCSP.  At what point does
x get high enough that the fragmentation of the serial number ranges negates
any specific benefit from pre-generating responses for a subrange, and how 
much mitigation do different y values provide for the fragmentation issue?

So it'd need a research publication to demonstrate there's a benefit, and
under what conditions, after which it'd certainly be a better bugfix for
OCSP than the accept-replayed-responses kludge.

Peter.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.