sozu
sozu copied to clipboard
Support ocsp stapling protocol
To handle x509 certificate revocation, sōzu could support the ocsp stapling protocol. The main idea is to make a request to the ocsp authority to know, if the certificate is valid and put the response in a cache. According to cloudflare's blogpost, sōzu could safely retain response 7 days.