OCSP Revocation Checking
If enabled, Online Certificate Server Protocol (OCSP) will be used to check all local and remote certificates. The issuer of the response certificate must be trusted as well in order to verify signatures.
Select the wrench icon to open the OCSP Settings window:
- OCSP Responder URI: This setting is optional. If specified, this responder URI will be used in addition to any certificate Authority Information Access extensions when checking for OCSP revocation. Only HTTP URIs are supported.
- Hard Fail: When enabled, this connector will depend on the remote OCSP provider. If an OCSP response cannot be retrieved or verified for any reason, all connections will fail revocation checks. Use this option if you need very strict OCSP security settings, at the cost of being dependent on the reliability of the public OCSP server.