Envoy: OCSP Stapling

Created on 24 Apr 2018  路  9Comments  路  Source: envoyproxy/envoy

Title: OCSP Stapling

Description:

We are trying to use Envoy as secure ingress layer. Just wondering if envoy v1.6.0 support this feature or is there any plan to have it in coming feature?

aretls enhancement help wanted

Most helpful comment

Any update on that front? This seems a rather important security feature.

All 9 comments

Not supported currently. cc @PiotrSikora @ggreenway

It's on my list of things I'd like to support eventually, but I have no firm plans yet.

@ggreenway Is this something that is planned for near future?

@ggreenway @PiotrSikora Refreshing this thread.
What are one's options today if s/he wanted OCSP stapling with Envoy?

+1

+1

Any update on that front? This seems a rather important security feature.

As I mentioned in the last Envoy community meeting, I wrote up a design doc describing how this could be implemented in Envoy. I'm soliciting comments and will also post this in the Envoy Slack.

https://docs.google.com/document/d/14Ji0Vq7Xbe9LXM6IsWQo8mgEnOB8Bo6TH75sSmFbCEE/edit

Fixed in #12685

Was this page helpful?
0 / 5 - 0 ratings