4 ms·
It works just fine if you require an OCSP response and hardfail. Soft-failing is for usability and it's the cause of the problem. Yes, must-staple is the optim
by problems 9y ago
It works just fine if you require an OCSP response and hardfail. Soft-failing is for usability and it's the cause of the problem.
Yes, must-staple is the optimal solution, but OCSP required is the best available today.
Look at some of the numbers here: https://www.grc.com/revocation/crlsets.htm https://www.grc.com/revocation/crlsets.htm
- tptacek 9y agoSoft failing isn't for "usability". OCSP simply doesn't work in situations where you would otherwise soft-fail, not because of any problem with the certificate, but because the protocol itself does not work.
- problems 9y agoHow so? Replay might be a bit of a concern, but it's fairly time limited. The other stuff cited by Langley is just down to usability alone.
- tptacek 9y agoYou are using the word "usability" to describe a situation in which extremely popular sites that are themselves doing everything right from a security perspective simply stop working --- because OCSP does not work. This is a silly conversation, and I'm opting out of it now.
- problems 9y ago> simply stop working How would this happen? Are you suggesting that network failures are something that shouldn't impact even advanced users who've opted themselves in to the potential pitfalls in order to gain security? I'm not suggesting hard-fail be the default, I'm suggesting CRLs be the default with hard-fail as an option for advanced users who know how to resolve problems when they do occur.