Validation Policy
The Validation Policy screen allows you to define the validation settings required for the selected LOTL/TSL. These settings determine how ADSS Server validates certificates and OCSP responses when processing the Trusted List.

The following table describes the available configuration items:
|
Items |
Description |
|
Primary Method |
Specifies the primary certificate revocation checking method. You can select OCSP (AIA) or CRL (CDP). |
|
Secondary Method |
Specifies the secondary certificate revocation checking method to use if the primary method cannot be used. You can select OCSP (AIA) or CRL (CDP). |
|
Add Nonce Extension |
Adds a nonce (a number used only once) to the OCSP request. ADSS Server verifies that the OCSP response contains the same nonce value. This helps protect against replay attacks. |
|
Add Service Locator Extension |
Adds the OCSP responder URL obtained from the target certificate's AIA (Authority Information Access) extension to the OCSP request as a Service Locator extension. This allows the OCSP responder to forward the request to another OCSP responder if it cannot process the request itself. |
|
Sign OCSP Request |
Enables signing of OCSP requests when the OCSP responder requires signed requests. When enabled, select the OCSP Request Signing Certificate from the certificates already available in Key Manager. |
|
Verify OCSP Responder's Certificate |
Enables revocation checking of the OCSP responder's certificate. This check is generally not required because OCSP responder certificates typically contain the NOCHECK extension. |
|
Verify OCSP Responder is Authorised by the CA |
Verifies that the OCSP responder providing the response is authorised by the same CA that issued the target certificate. ADSS Server also verifies that the OCSP responder certificate is specifically authorised for OCSP Signing through the Extended Key Usage (EKU) extension. |
|
Hash Algorithm |
Specifies the hash algorithm used to generate the OCSP request and, where applicable, to sign the OCSP request. |
|
Clock Tolerance |
Specifies the allowed difference between the local system time and the time contained in an OCSP response. This ensures that responses are considered sufficiently fresh even when system clocks are not perfectly synchronised. A value of at least 100 seconds is recommended. |
|
Response Timeout |
Specifies the maximum number of seconds that the OCSP Service waits for a response from the OCSP responder before considering the communication unsuccessful. A value of at least 10 seconds is recommended. Set this value to 0 to allow an unlimited timeout. |
After configuring the required validation settings, click Next to continue.
|
|
Important: If all TSL checkboxes are selected, any new TSL discovered during a subsequent LOTL fetch is automatically added to the configuration. |
See also
