Online validation with OCSP
Check in real time whether a certificate is still valid or has been revoked.
OCSP service
OCSP (Online Certificate Status Protocol) is the mechanism that lets a relying party check, in real time, whether a specific certificate is valid or has been revoked. Instead of downloading a full list of revoked certificates, the client sends a query with the certificate's serial number and receives a signed response with the current status.
Lamassu integrates its own OCSP responder that serves these queries by consulting the internal certificate database directly. No external component is required.
How the responder works in Lamassu
When a client requests the status of a certificate, the responder locates the certificate by its serial number and determines its status from the internal record:
- If the certificate is active, the response indicates
Good. - If the certificate has been revoked, the response indicates
Revokedand includes the revocation timestamp and the RFC 5280 reason code. - If the serial number is not found or the status is not recognizable, the response indicates
Unknown.
The OCSP response is signed by the issuing CA of the queried certificate, using the cryptographic engine associated with that CA. Lamassu does not use a delegated OCSP signing certificate: the CA acts directly as the responder.
Each response has a validity window of 24 hours, reflected in the response's thisUpdate and nextUpdate fields. Clients that cache responses must take this window into account when determining how long a response remains valid.
Embedding in issued certificates
The OCSP responder URL is automatically embedded in the AIA (Authority Information Access) extension of every certificate issued by Lamassu. Clients that verify certificates can read this URL directly from the certificate without additional configuration.
HTTP endpoints
The responder accepts both formats defined in RFC 6960:
GET /ocsp/{ocsp_request}includes the OCSP request Base64url-encoded within the URL itself.POST /ocspsends the request in the body withContent-Type: application/ocsp-request.
Example query with curl using POST:
curl -X POST https://<LAMASSU_HOST>/ocsp \
-H "Content-Type: application/ocsp-request" \
--data-binary @request.der \
-o response.derThe response has Content-Type: application/ocsp-response and contains the OCSP response in DER format.
Check from the interface
From the certificates screen of Lamassu you can launch an OCSP request directly against the selected certificate with the OCSP Check action. This action shows the status returned by the responder without needing external tools.
References
- RFC 6960 - X.509 Internet Public Key Infrastructure Online Certificate Status Protocol – OCSP
- RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile (revocation reasons, section 5.3.1)