Forum OpenACS Q&A: Re: Letsencrypt OCSP change could impact your instance

Collapse
Posted by Gustaf Neumann on
This shows, reading the forums helps.

Deactivating OCSP in the configuration file is just a short run solution, I try to come up with something better. OCSP was introduced to improve the security ratings from sites like ssllabs, and was part of the sample configuration files of OpenACS included in the NaviServer versions 4.99.20 - 4.99.31/head (see e.g. [1,2].

In general, you should keep OCSP active when using non-letsencrypt certificates.

[1] https://sourceforge.net/p/naviserver/mailman/naviserver-devel/thread/AM0PR05MB6003DCDACCEE5A378E2F5A15FE110%40AM0PR05MB6003.eurprd05.prod.outlook.com/#msg36926639
[2] https://openacs.org/forums/message-view?message_id=5509678