apache / apache/trafficserver

Discussion on ATS checking origin certificate revocation status

Open
#11,629 1 comment 0 reactions 0 assignees View on GitHub
New Feature Stale TLS
Dominant language
C++
Stars
2k
Forks
874
Avg merge
6d 15h
Merged PRs (30d)
46

Description

This came up as a result of https://www.digicert.com/support/certificate-revocation-incident

Does ATS check revocation status of origin certificates? If not, should it be a configuration setting to do so?

Regarding which method to use, this recent post from Let's Encrypt indicates OCSP (not stapling) on the way out and CRLs are in fashion again: https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.