Re: Is there any plan to support OCSP to verify cert

2013-03-05 Thread Godbach
Hi, JohnF Thanks for your reply. OCSP which has been supported by openssl library and stunnel is another way to validate client certificates besides CRL. And CRL has a shortcoming that it should be updated in time. So I am wondering that whether haproxy will support OCSP to validate client certi

Re: Is there any plan to support OCSP to verify cert

2013-03-05 Thread Godbach
Hi, JohnF Thanks for your reply. OCSP which has been supported by openssl library and stunnel is another way to validate client certificates besides CRL. And CRL has a shortcoming that it should be updated in time. So I am wondering that whether haproxy will suport OCSP to verify cleint c

Re: Is there any plan to support OCSP to verify cert

2013-03-05 Thread John Marrett
Godbach, I'm interested to better understand what you want to do with OSCP. Ordinarily if you present a certificate using haproxy clients will validate it using methods specified in the certificate itself. If these include OSCP than it could potentially be used. In this context your question does

Is there any plan to support OCSP to verify cert

2013-03-05 Thread Godbach
Hi, all OCSP(Online Certificate Status Protocol) is also used to verify certificates. I am wondering that if there is any plan to support OCSP in haproxy in the future. Best Regards, Godbach