Hacker News new | ask | show | jobs
by johnp_ 2222 days ago
That's why there's OCSP stapling and OCSP must staple. Ever seen an nginx server fail HTTPS connection exactly once after rotating the certificate? That's nginx lazily fetching the OCSP response from upstream for stapling purposes.
1 comments

Notarization has a similar "stapling" workflow as well.