arrow
Return

Exploring the HTTPS OCSP Ecosystem: A Comprehensive Study

delete2026-01-01
delete0
PRE
AI
H
HengSheng Wang
S
ShuShang Wen
W
Wang Wei *
DOI:10.1007/978-3-032-01806-9_4delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The widely-used HTTPS protocol relies on Transport Layer Security (TLS) to enable users to browse websites correctly and confidentially. Verifying the validity of HTTPS certificates is essential, and the Online Certificate Status Protocol (OCSP) plays a key role in checking certificate validity. However, OCSP itself faces examinations due to issues such as delays and privacy concerns. Moreover, all components involved in the OCSP protocol-web server software, OCSP responders, and browsers-often fail to adequately support Active OCSP, OCSP Stapling, and OCSP Must-Staple. To explore the current state of the OCSP ecosystem, we conducted large-scale scans of domains in the Tranco list in October 2023 and November 2024, and performed a month-long evaluation of their corresponding OCSP responders in both periods. We analyzed the support for OCSP from browsers and web server software. We found that none of the components adequately supports OCSP: Most OCSP responders experienced inaccessibility, and no web server software fully and correctly supported OCSP Stapling. Furthermore, most browsers do not respect OCSP Must-Staple and often neglect OCSP revocation checks.
Keywords:
PKI
HTTPS
certificate revocation
OCSP

Journal

A
APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2025 SATELLITE WORKSHOPS: AIHWS, AIOTS, QSHC, SCI, PRIVCRYPT, SPIQE, SIMLA, AND CIMSS 2025, PT II
IF:
0
Papers:
16
Citations:
0

Organization

C
chinese academy of sciences
Scholars:
55.9W
Papers: 44.7W
Citations: 704