Hacker News new | past | comments | ask | show | jobs | submit login

I wondered the same thing when setting up OCSP stapling. My conclusion was that the largest benefit is to the issuer, because OCSP allows them to use a different private key for initial issuance and for status responses. So the issuing key could be stored with much stricter security.

OTOH I assume that in reality half the world's CAs store their signing keys in an Access database on an unpatched Windows XP laptop, so it may be moot.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: