18Oca
How revocation status of delegated OCSP responder is verified at the client side?
If the OCSP signing is delegated explicitly to another entity and that delegated OCSP responder is compromised, how to revoke the certificate and convey the revocation information to a client? We need CRL for this?