cloudflare / cloudflare/cfssl

Responder should return unauthorized for a response with NextUpdate in the past

Open
#530 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.5k
Forks
1.2k
PR merge metrics
No merged PRs in 30d

Description

RFC 2560 (and 6960) specifies `[OCSP r]esponses whose nextUpdate value is earlier than the local system time value SHOULD be considered unreliable`. RFC 5019 also states `in order to ensure the database of revocation information does not grow unbounded over time, the responder MAY remove the status records of expired certificates`.

Since the window between a `nextUpdate` in the past and when a response can be removed is somewhat ambiguous it would be a good idea to add a config var to the responder specifying if it should happly serve stale responses, how long it should be allowed to serve stale responses for, or not to serve stale responses at all.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.