3 ms·
The thing that always bugged me about OCSP stapling is how poorly nginx handled it. I don't remember the specifics at the moment, but when the server would star
by smitelli 2y ago
The thing that always bugged me about OCSP stapling is how poorly nginx handled it. I don't remember the specifics at the moment, but when the server would start up cold it would not have some necessary information cached, which resulted in the first couple of HTTPS connections to each vhost missing some OCSP data.
When combined with a certificate configuration that used Must-Staple, this resulted in the first couple of requests showing a "required feature missing" error (at least in Firefox) until the nginx cache warmed up.
When Let's Encrypt started talking about dropping some support for it, it prompted me to reexamine my configurations and conclude that I actually did not care about it. Like, at all. I removed OSCP from the sites I run back in July 2024.