SECURING
For Domino®, OCSP checks are only made during S/MIME signature verification by the Notes® client. Revoked certificates generate an error message to the user, and all OCSP transaction information is placed in the client's local LOG.NSF database. Users have the option of accepting the revoked certificate.
To take advantage of this feature, a non-Domino OCSP responder must be available within the organization to perform signature verification.
OCSP is enabled by policy, through a setting on the Keys and Certificates tab of the Security Policy Settings document.
Parent topic: TLS and S/MIME for clients