Skip to main content
A CRL tells a validator every certificate an internal CA has ever revoked, and the validator downloads the whole list to check one certificate. The Online Certificate Status Protocol (OCSP, RFC 6960) answers a narrower question: is this one certificate revoked right now. Infisical runs an OCSP responder for each internal CA that has OCSP enabled. Load balancers, VPN concentrators, and mutual TLS gateways often check OCSP while ignoring CRLs entirely.
OCSP is available for internal CAs. A certificate from an external CA such as ACME, DigiCert, AWS Private CA, or Venafi carries its own issuer’s responder URL, and only that issuer can answer for it.

How it works

  • Every end-entity certificate issued while OCSP is enabled carries the responder URL in its Authority Information Access extension, which is where validators read it from. Certificates for intermediate CAs aren’t covered.
  • A validator sends the certificate’s serial number and two hashes identifying the issuer, then receives a signed answer of good, revoked, or unknown.
  • The CA signs the response, so a validator can verify it without trusting the transport.
  • Revoking a certificate changes the answer Infisical returns straight away. How soon a validator sees the change depends on how long it caches the previous response.
  • A serial the CA never issued returns unknown rather than good.
Only certificates issued after OCSP is enabled carry the responder URL. Enabling OCSP doesn’t change certificates that already exist, so reissue one if it needs to be checkable over OCSP.

Prerequisites

  • An internal CA with a certificate installed.
  • The Enterprise plan.
  • A responder URL your validators can reach. Infisical builds it from the instance URL, so a self-hosted instance that validators can’t resolve needs a reachable address configured first.

Enable OCSP

On the Enterprise plan, OCSP is on by default for every internal CA you create. You can turn it off while creating the CA, in the Distribution step, or at any time afterwards. Enable it yourself for a CA created before you had the plan, or one where it was turned off.
1

Open the CA

Go to Certificate Authorities and select the internal CA.
2

Edit the Revocation card

Select the pencil icon on the Revocation card.
3

Turn OCSP on

Turn on Enable OCSP, then select Save.
4

Copy the responder URL

The Revocation card now shows the responder URL. Certificates issued from this point carry it.

Verify the responder

Use openssl with the certificate and its issuer:
A working responder prints Response verify OK followed by the status:

Limitations

  • Certificates issued before OCSP was enabled don’t carry the responder URL.