OCSP Stapling
OCSP Stapling: TLS mechanism in which the serverServerA system that provides applications, data, or network services to other systems. transmits a signed status response regarding the certificate. The term is relevant to the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.
How it works and where it fits
The security of OCSP Stapling comes from the combination of algorithm, parameters, keys, protocol, and implementation. A mathematically strong primitive can be defeated by an unsuitable mode, weak randomness, incorrect certificate validation, or exposed keys. The intended objective must therefore be explicit: confidentiality, integrity, authenticity, or non-repudiation.
Practical security relevance
In practice, key and certificate management is often more decisive than algorithm choice alone. Generation, storage, distribution, rotation, revocation, and destruction require defined controls and monitoring. Compatible parameters, maintained libraries, migration capability, and a response process for compromised keys are also necessary; proprietary cryptographic constructions should be avoided.
Related concepts
- Certificate Revocation ListCertificate Revocation ListList of certificates revoked prior to their expiration.: List of certificates revoked prior to their expiration.
- Digital CertificateDigital CertificateElectronic proof of identity that links a public key to an entity.: Electronic proof of identity that links a public key to an entity.
- Certificate AuthorityCertificate AuthorityTrusted entity that issues and validates digital certificates.: Trusted entity that issues and validates digital certificates.
- Transport Layer SecurityTransport Layer SecurityProtects network connections through encryption, authentication, and integrity checks.: Protects network connections through encryption, authentication, and integrity checks.