I want to configure a server with:
ssl_stapling on;
ssl_stapling_verify on;
What should happen if the ssl_trusted_certificate is
(not|mis)configured?
How to check nginx is properly configured and server-side OCSP response
verification works?
If there’s no stapling, you’ll get:
“OCSP response: no response sent”.
Please note: when you restart nginx, you won’t get an OCSP answer
immediatly. You’ll have to visit the URL and wait a few seconds before
having the stapling working for the next request. IIRC, this behavior is
because OCSP servers may be slow to answer.
I want to have details about the status nginx’ validation of the initial
OCSP query it did to the OCSP responder of the CA, especially when it goes
wrong.
we do not let nginx fetch the ocsp data itself but use
ssl_stapling_file.
a cronjob call openssl and VERIFY the ocsp resonse.
I do not want to validate OCSP responses client-side, which are OK.
I want to have details about the status nginx’ validation of the initial
OCSP query it did to the OCSP responder of the CA, especially when it
goes
wrong.
I noted that even though ssl_trusted_certificate is not set or set with
a
wrong (set of) certificate(s), a cached OCSP response will served by
nginx
to the client after an initial request has been made to a domain hosted
by
it and served through TLS.
I want to know the consequences of having such a directive badly
configured
:
error.log message? Found nothing
modified OCSP response? Nope
…
What am I supposed to notice and where/when?
B. R.
This forum is not affiliated to the Ruby language, Ruby on Rails framework, nor any Ruby applications discussed here.