Maxim Dounin
September 29, 2021 09:26AM
Hello!

On Wed, Sep 29, 2021 at 12:47:58PM +0800, Jeffrey 'jf' Lim wrote:

> http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling
> has a note about not needing 'ssl_trusted_certificate' if
> ssl_certificate has intermediate certificates. I do not see a similar
> note for ssl_stapling_verify
> (http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling_verify)
> though. Is this also the same?

No. To verify OCSP response OpenSSL needs a full chain up to a
trusted root certificate.

--
Maxim Dounin
http://mdounin.ru/
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

ssl_stapling_verify: do we need 'ssl_trusted_certificate' if the intermediate certs are present in ssl_certificate?

Jeffrey 'jf' Lim September 29, 2021 12:50AM

Re: ssl_stapling_verify: do we need 'ssl_trusted_certificate' if the intermediate certs are present in ssl_certificate?

Maxim Dounin September 29, 2021 09:26AM

Re: ssl_stapling_verify: do we need 'ssl_trusted_certificate' if the intermediate certs are present in ssl_certificate?

Jeffrey 'jf' Lim September 29, 2021 09:44AM

Re: ssl_stapling_verify: do we need 'ssl_trusted_certificate' if the intermediate certs are present in ssl_certificate?

Jeffrey 'jf' Lim October 06, 2021 11:14PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 179
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 500 on July 15, 2024
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready