The Online Certificate Status Protocol (OCSP) is an internet protocol for obtaining the real-time revocation status of a digital certificate from a responder operated by or on behalf of the issuing certificate authority. A client queries the responder for a specific certificate and receives a signed reply stating whether it is good, revoked, or unknown. OCSP offers a more immediate and bandwidth-efficient alternative to downloading full certificate revocation lists, and OCSP stapling lets servers present a recent status to avoid client-side lookups.

Overview

  • Revocation lets a certificate be invalidated before its natural expiry, for example after a key compromise; OCSP makes checking that status fast and targeted.
  • Rather than fetching and parsing a large revocation list, a client asks only about the certificate it cares about.
  • OCSP stapling improves both performance and privacy by having the server attach a recent, signed status to the TLS handshake.
  • The protocol is a core part of the web’s trust model, ensuring that compromised or mis-issued certificates can be rejected.

Mechanisms

  • Request and response: a client sends a certificate identifier and receives a CA-signed status.
  • Responder infrastructure: highly available services answer status queries at scale.
  • OCSP stapling: servers cache and present a recent response, removing client-side lookups.
  • Must-staple: a certificate extension requiring a stapled response, hardening against soft-fail.
  • Signed assertions: responses are cryptographically signed to prevent forgery.

Applications

  • TLS certificate validation in browsers and clients during the handshake.
  • Mutual TLS and machine-to-machine authentication needing fresh status.
  • Code-signing and document-signing trust chains.
  • Enterprise PKI deployments managing certificate lifecycle and revocation.

Provenance