<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.pala-odin" target="https://datatracker.ietf.org/doc/html/draft-pala-odin-01">
   <front>
      <title>OCSP over DNS (ODIN)</title>
      <author initials="M." surname="Pala" fullname="Massimiliano Pala">
         <organization>CableLabs</organization>
      </author>
      <date month="October" day="26" year="2017" />
      <abstract>
	 <t>   With the increase number of protocols and applications that rely on
   digital certificates to authenticate either the communication channel
   (TLS) or the data itself (PKIX), the need for providing an efficient
   revocation system is paramount.  Although the Online Certificate
   Status Protocol (OCSP) [RFC6960] allows for efficient lookup of the
   revocation status of a certificate, the distribution of this
   information via HTTP or HTTPS is not particularly efficient for high
   volume websites without incurring in high distribution costs (e.g.,
   CDN).

   In particular, this specification defines how to distribute OCSP
   responses over DNS and how to define OCSP-over-DNS URLs in
   certificates.  The use of the DNS system to distribute such
   information is meant to lower the costs of providing revocation
   services and increase the availability of revocation information by
   using the distributed nature of the DNS infrastructure.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-pala-odin-01" />
   
</reference>
