OCSP Nonce Extension
From RFC 2560:
4.4.1 Nonce
The nonce cryptographically binds a request and a response to prevent replay attacks. The nonce is included as one of the requestExtensions in requests, while in responses it would be included as one of the responseExtensions. In both the request and the response, the nonce will be identified by the object identifier id-pkix-ocsp-nonce, while the extnValue is the value of the nonce.
View at oid-info.com
http://www.ietf.org/rfc/rfc2560.txt
Internet Assigned Numbers Authority (IANA)
OID | Name | Sub children | Sub Nodes Total | Description |
---|---|---|---|---|
1.3.6.1.5.5.7.48.1.1 | basic-response | 0 | 0 | OCSP Basic Response |
1.3.6.1.5.5.7.48.1.3 | crl | 0 | 0 | Certificate Revocation List (CRL) reference |
1.3.6.1.5.5.7.48.1.4 | response | 0 | 0 | Response types understood by an Online Certificate Status Protocol (OCSP) client |
1.3.6.1.5.5.7.48.1.5 | no-check | 0 | 0 | OCSP No Check Extension 4.2.2.2.1 Revocation Checking of an Authorized Responder Since an Authorized OCSP responder provides … |
1.3.6.1.5.5.7.48.1.6 | archive-cutoff | 0 | 0 | OCSP Archive Cutoff Extension |
1.3.6.1.5.5.7.48.1.7 | service-locator | 0 | 0 | OCSP Service Locator Extension |
1.3.6.1.5.5.7.48.1.8 | id-pkix-ocsp-pref-sig-algs | 0 | 0 | Client indication of preferred signature algorithms |