Re: JEP Review Request: OCSP Stapling for TLS

2014-09-04 Thread Xuelei Fan
On 9/3/2014 8:47 AM, Bernd Eckenfels wrote: > Also I can understand the restriction to not require API changes I > wonder if this is a good idea. I will come back to that later, but just > a prelimiary question: will a TrustManager (or HostnameVerifier) be > able to actually see and work on the O

Re: JEP Review Request: OCSP Stapling for TLS

2014-09-03 Thread Jamil Nimeh
Hello Bernd, thanks for the quick feedback! I don't have concrete answers to all your questions at this point, but I'll address what I can in-line. On 09/02/2014 05:47 PM, Bernd Eckenfels wrote: hello, this is good news! jut a quick question before I prepare a full response. There is a "tu

Re: JEP Review Request: OCSP Stapling for TLS

2014-09-02 Thread Bernd Eckenfels
hello, this is good news! jut a quick question before I prepare a full response. There is a "tunables" section mentioned in the JIRA which is not very concrete, is there a draft somewhere for it? Because, I would add as a sample/recommended tunable the option to deny for ServerSockets to respon

JEP Review Request: OCSP Stapling for TLS

2014-09-02 Thread Jamil Nimeh
Hello all, The draft JEP "OCSP Stapling for TLS" has been opened up for community review. This is an update to the original call for comments back in mid-March this year[*]. Like some of the other early JEPs this year, this has been brought under the JEP 2.0 process. https://bugs.openjdk.j