Welcome! Log In Create A New Profile

Advanced

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Maxim Dounin
January 22, 2016 12:50PM
Hello!

On Fri, Jan 22, 2016 at 05:38:06PM +0000, Alessandro Ghedini wrote:

> # HG changeset patch
> # User Alessandro Ghedini <alessandro@cloudflare.com>
> # Date 1453481233 0
> # Fri Jan 22 16:47:13 2016 +0000
> # Node ID c6668c14a2d168307bcfade0cc2e01c92c31312a
> # Parent a8c4f65236ad90138863d5295ca059a3d37da37e
> Proxy: add support for OCSP stapling verification from upstream
>
> This patch adds the "proxy_ssl_stapling_verify" option that controls OCSP
> stapling verification from an upstream server.
>
> The option allows three values:
>
> - "off" (default): disable OCSP stapling completely.
> - "on": request OCSP stapling from upstream and verify response if
> provided.
> - "full": same as "on", but fail also when no response is received.

The "on" seems to be no different from "off" and hardly make
sense, as an attacker can easily avoid returning stapled OCSP
response.

The "full" in turn doesn't seem to be correct feature, as stapled
OCSP response may be legitimately absent for multiple reasons.

[...]

--
Maxim Dounin
http://nginx.org/

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Alessandro Ghedini 566 January 22, 2016 12:40PM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Maxim Dounin 237 January 22, 2016 12:50PM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Alessandro Ghedini 213 January 22, 2016 01:04PM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Maxim Dounin 272 January 22, 2016 01:48PM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Alessandro Ghedini 250 January 22, 2016 04:48PM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Maxim Dounin 250 January 25, 2016 10:00AM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Alessandro Ghedini 312 January 25, 2016 10:42AM

Re: [PATCH 2 of 2] Proxy: add support for OCSP stapling verification from upstream

Alessandro Ghedini 309 February 02, 2016 12:46PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 175
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready