In setting up OCSP stapling on 1.5.10 I've found it behaving in a way which is opposite to what I perceive is documented. There it states that the contents of ssl_trusted_certificate are not sent to the client. However when I enable ssl_stapling_verify, which requires the inclusion of in this case the GeoTrust root certificate for the OCSP response to work, this root certificate is included in the response back to the client. Am I just interpreting the documentation incorrectly? It's not a dire issue, simply unexpected, and when including the root cert the SSL handshake increases from 4434 bytes to 5293.
*__________________Scott LarsonSystems AdministratorWiredrive/LA310 823 8238 ext. 1106310 943 2078 faxwww.wiredrive.com <http://www.wiredrive.com/>www.twitter.com/wiredrive <http://www.twitter.com/wiredrive>www.facebook.com/wiredrive <http://www.wiredrive.com/facebook>*
_______________________________________________ nginx mailing list nginx@nginx.org http://mailman.nginx.org/mailman/listinfo/nginx