Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OCSP stapling support is missing for lighttpd #8084

Open
2 tasks done
meyergru opened this issue Nov 24, 2024 · 4 comments
Open
2 tasks done

OCSP stapling support is missing for lighttpd #8084

meyergru opened this issue Nov 24, 2024 · 4 comments

Comments

@meyergru
Copy link
Contributor

Is your feature request related to a problem? Please describe.

When I want to make use of ACME certificates for dual-use, like for HAproxy sites and OpnSense itself, I want to be able to use OCSP stapling. Currently, OpnSense does not support it.

Describe the solution you like

Lighttpd supports OCSP stapling since 1.4.56:

https://redmine.lighttpd.net/projects/lighttpd/wiki/Docs_SSL#OCSP-Stapling

Once could use "ssl.stapling-file" in the configuration and have a cron job that fetches its content regularly, like described in the docs.

Describe alternatives you considered

Having another non-OCSP-stapling certificate, just for OpnSense.

@Monviech
Copy link
Member

#5567

Just for reference.

@fichtner
Copy link
Member

IMO the whole discussion was derailed so nothing came of it. A prime example of what discouragement does to open source contributions. 🤷‍♂️

@meyergru
Copy link
Contributor Author

meyergru commented Nov 24, 2024

Sorry, did not find it in open issues... should I close this? I would actually test it...

@Monviech
Copy link
Member

I guess the TLDR of the whole discussion in that PR was that upstream has a script for it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

3 participants