BuildOCSPRequest
חתימות דיגיטליות
תיאור
מקודדת בקשת סטטוס OCSP עבור תעודה לפי RFC 6960
תחביר
Delphi
Function TPDFlib.BuildOCSPRequest(Const SubjectCertDER, IssuerCertDER: AnsiString): AnsiString;פרמטרים
| SubjectCertDER | התעודה שאת מצבה שואלים, בקידוד DER |
|---|---|
| IssuerCertDER | התעודה שהנפיקה אותו, בקידוד DER |
ערכי החזרה
| Request | ה-OCSPRequest, מקודד DER |
|---|---|
| Empty string | אחת התעודות לא ניתנה לקריאה, או ששתיהן לא שייכות יחד; GetTimeStampError נושא את הסיבה. |
הערות
ה-CertID נבנה משם המנפיק והמספר הסידורי של תעודת ה-subject ומהמפתח הציבורי של תעודת המנפיק, מגובבים ב-SHA-1 כפי שקובע RFC 6960 §4.1.1; ה-hash מזהה את התעודה ואינו מגן על שום דבר
The pair is checked before anything is encoded: the subject certificate's issuer name must be the issuer certificate's subject name. A mismatched pair produces a request the responder answers with unknown, which reads like a revocation problem rather than a caller mistake, so it is refused here instead.
לא מבוקש nonce; רשויות רבות משרתות תגובות שהופקו מראש ודוחות בקשה עם nonce מיידית, ותגובה השמורה ב-document security store מאומתת מאוחר יותר ולא נבדקת בזמן אמת
ראו גם
FetchOCSPResponse, GetOCSPResponseStatus, GetCertificateOCSPURLs