Description
When get OCSP response, we check it before cache/staple it. If it's negative, I think we'd better discard it instead of sending back to user agent. This would not increase security risk: User agent would query CA for OCSP response if ATS does not staple it with certificate.
Attachments
Attachments
Issue Links
- relates to
-
TS-2367 Add OCSP (Online Certificate Status Protocol) Stapling Support
- Closed