[
https://issues.apache.org/jira/browse/TS-3186?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14251836#comment-14251836
]
Alan M. Carroll commented on TS-3186:
-------------------------------------
Leif;
That is what I meant by "Normally when this is used it is immediately
{{strdup}}'d". But there's still a small window of vulnerability while the
duplication is happening.
Anyway, if this isn't to go in to {{records.config}}, then where? There are no
callbacks for the plugin to handle this. If you have multiple proxies, how are
requests split among them? I'm not sure I want to do the SplitDNS stuff again.
Would it just be failover? Round robin? I suppose it could be handled like DNS
nameservers.
As for typical use cases, we only have one and it's adequate for that, so 100%
match :-). Perhaps, contrary to our nature, we should start simply and expand
when it's needed.
> support ocsp queries through a proxy
> -------------------------------------
>
> Key: TS-3186
> URL: https://issues.apache.org/jira/browse/TS-3186
> Project: Traffic Server
> Issue Type: Improvement
> Components: SSL
> Reporter: Atsutomo Kotani
> Assignee: Alan M. Carroll
> Fix For: 5.3.0
>
> Attachments: ocsp_proxy.diff
>
>
> When ATS behind http proxy, it need ocsp queries through http proxy for ocsp
> stapling.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)