How to do OCSP requests using OpenSSL and CURL

The nonce extension is used to avoid replay attacks during the interval in which the previous OCSP response for a certificate is not expired but responder has a changed status for that certificate. Including client's Nonce value in the OCSP response makes sure that the response is a latest response from the server and not a old copy.

