Add durable multi-authority OCSP responders with strict request parsing,
issuer-bound serial lookup, stable revocation views, signed responses,
nonce policies and bounded protocol execution.
Complete in-process and packaged OCSP validation and close the PKI server
after the final architecture, security and release audit.