|
All, In order to comply with FIPS 201, U.S. Federal agencies are going to be required to begin deploying PKI to all of their employees in the near future. FIPS 201 requires that certificate status information be made available via OCSP for authentication certificates. In order to help ensure that the OCSP responders that are deployed for this purpose can work with as many clients as possible, we are looking to provide guidance to those who will be setting up OCSP responders. I have developed the initial draft guidance document (attached), which is slightly long that one page in length. This guidance was developed using the draft Lightweight OCSP Profile for High Volume Environments Internet-draft as the basis for most of its content. We are seeking feedback from people who are knowledgeable about the capabilities of OCSP clients. In particular, we would like to know if existing OCSP clients would be able to interoperate with OCSP responders that functioned in conformance with this guidance or if the guidance would need to be adjusted in order to ensure interoperability. We are also interested in knowing whether the rules imposed on OCSP responders could be relaxed without compromising interoperability. In particular, section 4.2.2.2 of RFC 2560 states that clients "MUST reject the response if the certificate required to validate the signature on the response fails to meet at least one of the following criteria:
Any information that people could provide us on this issue would be appreciated. Thanks, Dave |