7.11. Using the Online Certificate Status Protocol

One of the drawbacks of using certificates is that as the number of certificates grows, expires, or ultimately become revoked, the number of revoked certificates in the CRL becomes very large and cumbersome to send back and forth. Using the Online Certificate Status Protocol (OCSP), administrators are able to implement a system that, instead of sending the complete list of revoked certificates, is able to respond to a request about a single certificate within the organization. This greatly reduces the amount of data traffic and optimizes the infrastructure for other tasks.

7.11.1. Online Responders

Any computer that is currently running the Online Responder service can function in the online ...

Get MCITP: Windows Server® 2008 Enterprise Administrator, Study Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.