Re: [users@httpd] mod_md usage for OCSP stapling

2020-03-30 Thread Stefan Eissing
Steffen described the way to do it where you get the most benefits (thanks!). However, you not need to declare "MDomain"s for all your certificates. You can also just configure MDStapling on and *all* the certificates in your Apache will be stapled by mod_md. more details: see

Re: [users@httpd] mod_md usage for OCSP stapling

2020-03-28 Thread Steffen
Yep very nice. In mod_status you can see : Managed StaplingsDomainCertificate IDOCSP StatusStapling ValidResponderActivitydomain.com3ff13e35fbe9d1ce4bcafbc3fd2ccd6ff5079eca gooduntil 2020-04-03ocsp.int-x3.letsencrypt.orgRefresh in ~3 days Try in global conf: MDCertificateFile conf/do

[users@httpd] mod_md usage for OCSP stapling

2020-03-27 Thread Marek Svent
Hi, >From 2.4 changelog I read that from next 2.4 release it's possible to use mod_md OCSP stapling even for certificates not managed by mod_md. It's very welcome as there is too many problems with mod_ssl stapling code. However it's not clear for me how this could be configured. I have many virt