diff options
author | Maxim Dounin <mdounin@mdounin.ru> | 2012-10-01 12:53:11 +0000 |
---|---|---|
committer | Maxim Dounin <mdounin@mdounin.ru> | 2012-10-01 12:53:11 +0000 |
commit | bec2cc5286e5888eb1de9462f7c64b922967b47b (patch) | |
tree | f51608be0c1ae2306ec75a99190398b47b360807 /src/http/modules/perl/nginx.pm | |
parent | 3ebbb7d521e9faeebdfdbba0a98a7a029e56c0a2 (diff) | |
download | nginx-bec2cc5286e5888eb1de9462f7c64b922967b47b.tar.gz nginx-bec2cc5286e5888eb1de9462f7c64b922967b47b.zip |
OCSP stapling: ssl_stapling_verify directive.
OCSP response verification is now switched off by default to simplify
configuration, and the ssl_stapling_verify allows to switch it on.
Note that for stapling OCSP response verification isn't something required
as it will be done by a client anyway. But doing verification on a server
allows to mitigate some attack vectors, most notably stop an attacker from
presenting some specially crafted data to all site clients.
Diffstat (limited to 'src/http/modules/perl/nginx.pm')
0 files changed, 0 insertions, 0 deletions