luasec
luasec copied to clipboard
OCSP Stapling
Please implement OCSP Stapling. This is especially useful to 1. reduce load of OCSP servers and 2. prevent privacy leaks of who is connecting to your host towards the OCSP server.
+1.
Any chance?
I don't know how hard is to implement this. I'm focused on university stuffs, I need to find free time for it.
Hello, Are there any news on this?
Sorry, I confess I did not look anything about it. I will try to find time to see it.
I started some exploratory coding in https://github.com/Zash/luasec/tree/ocsp that I believe manages a partial client-side OCSP check. No idea how to do the server-side parts yet, or how to check the cert for the must-staple flag.