The ocsp nonce enable command adds a nonce extension to the OCSP request sent by a PKI entity.
The undo ocsp nonce enable command cancels the configuration.
By default, the OCSP request sent by a PKI entity contains a nonce extension.
Only devices in NETCONF mode support this command.
To improve security and reliability of communication between a PKI entity and OCSP server, this command adds a nonce extension (a random value) to the OSCP request sent by the PKI entity. If the nonce extension values on the PKI entity and OCSP server are different, communication fails.