- What's the difference between OCSP and CRL?
- CRLs (Certificate Revocation Lists) are full lists of revoked certificates, fetched periodically. OCSP is a real-time per-certificate status query. OCSP is faster for individual checks; CRLs are more reliable for offline verification.
- What's OCSP must-staple?
- An X.509 certificate extension that instructs TLS clients to reject the certificate if a valid OCSP staple is not provided in the handshake — converting OCSP from soft-fail to hard-fail, closing the blocking attack.
- Does it fetch the OCSP response for me?
- No. Nothing is queried from this page. It reads the certificate's real Authority Information Access extension, computes the SHA-1 certID a query would carry, and writes the exact openssl ocsp command. Paste the response back and it is decoded and its signature verified against the embedded responder certificate.