Thank you, Ziyu! However, these three are no use without actual query
building and querying OCSP responder.

On Thu, 2012-05-03 at 16:06 +0800, Ziyu Liu wrote:
> You can use these functions to do the OCSP verification during the ssl
> handshaking.
> 
> #define SSL_set_tlsext_status_ids(ssl, arg) \
> SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_IDS,0, (void *)arg)
> 
> #define SSL_get_tlsext_status_ocsp_resp(ssl, arg) \
> SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_OCSP_RESP,0, (void *)arg)
> 
> #define SSL_set_tlsext_status_ocsp_resp(ssl, arg, arglen) \
> SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_OCSP_RESP,arglen, (void
> *)arg)
> 
> 
> 
> 
> 
> At 2012-05-03 15:23:49,"Alexander Komyagin" <[email protected]> wrote:
> >Hi! In our project we want to perform a complete global switch to OCSP
> >certificate verification (for a number of reasons we don't want CRL's
> >anymore) to make openldap, openvpn and others use OCSP.
> >
> >Unfortunately I didn't find any implemented way to perform such a switch
> >in OpenSSL. There is only one check_revocation() function, which checks
> >a chain against CRL's. I think that check_revocation() can be altered to
> >use OCSP instead just like ocsp-app does. Or shall I use any other place
> >to perform OCSP verification?
> >
> >Thanks!
> >-- 
> >Best wishes,
> >Alexander Komyagin
> >
> >
> >______________________________________________________________________
> >OpenSSL Project                                 http://www.openssl.org
> >Development Mailing List                       [email protected]
> >Automated List Manager                           [email protected]
> 
> 

-- 
Best wishes,
Alexander Komyagin

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to