How to do OCSP requests using OpenSSL and CURL

OCSP multiple response handling: Support has been enabled for handling of multiple OCSP single responses from an OCSP responder in a response packet. In addition to the debug log messages the following debug log message will be displayed: CRYPTO_PKI: Number of single Responses in OCSP response:1(this value can change depending upon the number

Online Certificate Status Protocol — OpenSSL Certificate The OCSP responder requires a cryptographic pair for signing the response that it sends to the requesting party. The OCSP cryptographic pair must be signed by the same CA that signed the certificate being checked. Create a private key and encrypt it with AES-256 encryption.

The nonce extension is used to avoid replay attacks during the interval in which the previous OCSP response for a certificate is not expired but responder has a changed status for that certificate. Including client's Nonce value in the OCSP response makes sure that the response is a latest response from the server and not a old copy.

OCSP Configuration — Snowflake Documentation Fail-Close¶. The fail-close behavior is more restrictive to interpreting the OCSP CA response. If the client or driver does not receive a valid OCSP CA response for any reason, the connection fails.. Since this behavior is not default based on the versions listed in the fail-open section, fail-close must be configured manually within each driver or connector.