>> We have no plans to do this. May be will put it into your plans ?
> Doubtful. We have lots of other work to do. Writing a full-strength
database-backed OCSP responder is outside of our interests.

Ok. In such situation, can you add ability of using multiple -CA, -rkey,
-rsigner parameters of trinity, at least ?
That OSSL at Ocsp responder mode could handle arrived request through all
specified parameters of trinity: -CA1, -rkey1, -rsigner1; -CA2, -rkey2,
-rsigner3 and so on ?

Besides, there is "Support Multiple CA certs in ocsp app" commit -
https://github.com/akamai/openssl/commit/7f5ed141fef8509b589b5a5601f0ec2bf5e08faf


Alex.

P. S.: I am ready to make some donation for it.
_______________________________________________
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

Reply via email to