<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Security Hype 7.4-OCSP, CRL, and Vista&#8217;s new SSL tricks</title>
	<link>http://www.securityhype.com/blog/archives/23</link>
	<description>Security clarity. One listener at a time.</description>
	<pubDate>Wed, 07 Jan 2009 14:06:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Chris Knadle</title>
		<link>http://www.securityhype.com/blog/archives/23#comment-208</link>
		<dc:creator>Chris Knadle</dc:creator>
		<pubDate>Mon, 12 Nov 2007 18:15:58 +0000</pubDate>
		<guid>http://www.securityhype.com/blog/archives/23#comment-208</guid>
		<description>I've been looking into setting up an OCSP responder for SSL certificates since from what I've heard many systems don't check CRLs by default, but will check via OCSP.  At least some browsers don't check CRLs, and where they do at least some ask for the user to import a CRL list manually; whereas OCSP setup is a couple of clicks to activate it.  So from the user standpoint, OCSP is much easier to set up and use.  From the admin point of view OCSP is more difficult because it requires making special SSL keys for the OCSP responder, and finding documentation on how to do that isn't straightforward.

-- Chris</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been looking into setting up an OCSP responder for SSL certificates since from what I&#8217;ve heard many systems don&#8217;t check CRLs by default, but will check via OCSP.  At least some browsers don&#8217;t check CRLs, and where they do at least some ask for the user to import a CRL list manually; whereas OCSP setup is a couple of clicks to activate it.  So from the user standpoint, OCSP is much easier to set up and use.  From the admin point of view OCSP is more difficult because it requires making special SSL keys for the OCSP responder, and finding documentation on how to do that isn&#8217;t straightforward.</p>
<p>&#8211; Chris</p>
]]></content:encoded>
	</item>
</channel>
</rss>
