Important information about Certificates/CAs/OCSP Must-Staple #1285
Zoey2936
announced in
Announcements
Replies: 1 comment 2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Note: This is not a new release but an important information
Let's Encrypt has made an announcement today which has a huge impact on NPMplus, you can read it here: https://letsencrypt.org/2024/12/05/ending-ocsp
If you have any question/ideas etc. on this topic, please write a comment
What is OCSP/CRLs?
OCSP:
=> useful, but with a privacy problem, maybe takes some time to be detected because of cache
OCSP Stapling without Must-Staple:
=> useless without must staple, see below
OCSP Stapling with Must-Staple:
=> useful, if supported by the client, maybe takes some time to be detected because of validity of “second certificate”
CRLs
=> depends: if the revocation information of your cert is not included, then it is useless, otherwise it is ok
My opinion on this (I mostly talk about Must-Staple)
What now?
When will the change happen?
This discussion was created from the release Important information about Certificates/CAs/OCSP Must-Staple.
Beta Was this translation helpful? Give feedback.
All reactions