View Issue Details

IDProjectCategoryView StatusLast Update
001032110000-012: DiscoverySpecpublic2025-05-09 09:28
ReporterMatthias Damm Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
Product Version1.05.04 
Summary0010321: CheckRevocationStatus, OCSP and OCSP stapling
Description

The CheckRevocationStatus method in Part 12 has the same problems like OCSP, it es even worse than for web server. Every client AND every server would need to call this method for every secure channel create and renew.

In addition it requires that a server is also a client to the GDS. But especially small embedded servers have problems to store large CRLs files.

In OCSP this problem is solved with OCSP stapling.
https://en.wikipedia.org/wiki/OCSP_stapling

We should discuss options to use something similar (in this case mainly from client to server) like OCSP stapling.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-05-09 09:28 Matthias Damm New Issue