Re: JEP Review Request: OCSP Stapling for TLS

2014-09-04 Thread Xuelei Fan
On 9/3/2014 8:47 AM, Bernd Eckenfels wrote: > Also I can understand the restriction to not require API changes I > wonder if this is a good idea. I will come back to that later, but just > a prelimiary question: will a TrustManager (or HostnameVerifier) be > able to actually see and work on the O

Re: JEP Review Request: OCSP Stapling for TLS

2014-09-03 Thread Jamil Nimeh
Hello Bernd, thanks for the quick feedback! I don't have concrete answers to all your questions at this point, but I'll address what I can in-line. On 09/02/2014 05:47 PM, Bernd Eckenfels wrote: hello, this is good news! jut a quick question before I prepare a full response. There is a "tu

Re: JEP Review Request: OCSP Stapling for TLS

2014-09-02 Thread Bernd Eckenfels
hello, this is good news! jut a quick question before I prepare a full response. There is a "tunables" section mentioned in the JIRA which is not very concrete, is there a draft somewhere for it? Because, I would add as a sample/recommended tunable the option to deny for ServerSockets to respon