Hello,

We were using HAProxy 1.7 for a while in combination with a cron job
that fetches OCSP Staple data, stores it with the certificates as
.ocsp files per the [documentation][] and then uses 'set ssl
ocsp-response' on the administration [socket][] to update the running
server instance. We recently decided to finally upgrade to 1.8 and
everything seemed to be working well until we noticed that the OCSP
response is no longer being sent from the server.

Running a quick Git Bisect reveals
f6b37c67be277b5f0ae60438d796ff29ef19be40 introduced this regression in
the haproxy-1.8 tree. My uneducated initial guess is that it seems as
the default context has information about the certificate but not
about the OCSP Staple, however I am not familiar with how the contexts
are handled there. Is there someone who minds looking into this or at
least giving pointers so that I can try and propose a PATCH?

Cheers,
Valter J.

[documentation]:
https://cbonte.github.io/haproxy-dconv/1.8/configuration.html#5.1-crt
[socket]: https://cbonte.github.io/haproxy-dconv/1.8/management.html#9.3

Reply via email to