Hacker News new | ask | show | jobs
by minusf 1482 days ago
i think because what is asked for is a list of revoked certs, and the connection being used could be already on that blacklist. the list must available without the involvement of what is being checked.
1 comments

That's not what OCSP is. OCSP just lets you query the status of a cert.