RE: OCSP stapling broken with 1.15.4

2018-10-01 Thread Reinis Rozitis
> Indeed, with further tests I think that the stapling is working... > sometimes. > > > I'm not using the staple file, though. Is this behavior expected without such > configuration? Also, I've enabled ssl_early_data. Each nginx worker has it's own cache. Depending on your worker_processes you

Re: OCSP stapling broken with 1.15.4

2018-10-01 Thread Bernardo Donadio
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 10/1/18 10:04 AM, A. Schulze wrote: > Did you try to measure twice? Indeed, with further tests I think that the stapling is working... sometimes. I've restored the 1.15.4 package and have been making some requests. Some of them are correctly

Re: OCSP stapling broken with 1.15.4

2018-10-01 Thread A. Schulze
Bernardo Donadio: Hi. I've noticed that OCSP stapling was broken by 1.15.4, as you may see below: -- nginx 1.15.4 with OpenSSL 1.1.1 final $ openssl s_client -connect bcdonadio.com:443 -tlsextdebug -status CONNECTED(0003) TLS server extension "renegotiation info"