Welcome! Log In Create A New Profile

Advanced

Re: OCSP stapling for client certificates

June 28, 2015 12:20PM
Hi,

Actually, I had the same questions.
Is this something that's available by now, or is it in the pipeline of any new release of Nginx or will it never be?

I'm just asking since I believe this might be a good feature to add since CRL's could get very big when lots of certificate have been revoked, and since it is not a realtime updating mechanism.

By using a OCSP, there is a little overhead of contacting the OCSP for checking each client certificate that is being validated...
I believe this to be much more efficient than regularly downloading/uploading a CRL and reloading Nginx. This process can fail on multiple locations which makes it harder to track and a big disadvantage of the CRL's is that they are not realtime updated, which is the case for OCSP's.
This way revoking a certificate will cause it to immediately retract the access to client certificate secured applications (for all new sessions).

Is it already supported in some version of Nginx or is it planned somewhere in the future?

Many thanks,
Kind regards,

Francis Claessens.
Subject Author Posted

OCSP stapling for client certificates

Mohammad Dhedhi August 27, 2014 12:52PM

Re: OCSP stapling for client certificates

Maxim Dounin August 27, 2014 12:56PM

Re: OCSP stapling for client certificates

prozit June 28, 2015 12:20PM

Re: OCSP stapling for client certificates

Maxim Dounin July 05, 2015 07:44PM

Re: OCSP stapling for client certificates

itplayer April 13, 2019 05:16AM

Re: OCSP stapling for client certificates

ramirezc December 04, 2019 12:31PM

Re: OCSP stapling for client certificates

Frank Liu December 04, 2019 12:56PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 215
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready