Learn about Centmin Mod LEMP Stack today
Register Now

Beta Branch acmetool.sh 1.0.28 add OCSP Must Staple Support

Discussion in 'Centmin Mod Github Commits' started by eva2000, May 20, 2017.

  1. eva2000

    eva2000 Administrator Staff Member

    55,374
    12,255
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,835
    Local Time:
    2:06 PM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    acmetool.sh 1.0.28 add OCSP Must Staple Support

    - optionally add OCSP Must Staple support OCSP Must-Staple when you set in persistent config file /etc/centminmod/custom_config.inc the variable, ACME_MUSTSTAPLE='y' prior to issuing Letsencrypt SSL certificates
    - disabled by default, ACME_MUSTSTAPLE='n'


    Continue reading...

    123.09beta01 branch
     
  2. eva2000

    eva2000 Administrator Staff Member

    55,374
    12,255
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,835
    Local Time:
    2:06 PM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    ssllabs test

    upload_2017-5-20_14-47-49.png
     
  3. rdan

    rdan Well-Known Member

    5,451
    1,412
    113
    May 25, 2014
    Ratings:
    +2,206
    Local Time:
    12:06 PM
    Mainline
    10.2
    Scary for critical sites :).
     
  4. eva2000

    eva2000 Administrator Staff Member

    55,374
    12,255
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,835
    Local Time:
    2:06 PM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    and also problematic if you choose to use Nginx + BoringSSL for HTTPS as BoringSSL doesn't support OCSP at all heh