Online Certificate Status Protocol (OCSP)
Online Certificate Status Protocol, or OCSP, enables clients to verify whether a digital certificate remains valid or has been revoked by the responsible Certificate Authority. A client sends a request to an OCSP responder, which provides information about the current certificate status. Possible responses include “good”, “revoked” and “unknown”. OCSP is commonly used with TLS certificates and provides an alternative to Certificate Revocation Lists, which require clients to download lists of revoked certificates. An extension known as OCSP Stapling allows the server to retrieve the certificate status periodically and provide the signed status information directly to the client during the TLS connection process. This can reduce additional requests while improving privacy and connection performance.