Applications Google
Menu principal

Post a Comment On: Jinn Koriech's Blog

"OCSP Stapling with HAProxy"

2 Comments -

1 – 2 of 2
Blogger Stephen said...

Thanks a lot for this, it was very helpful in understand the OCSP stapling process behind the scenes.

I did have a lot of trouble with this however (with a Let's Encrypt cert) until I realised that the older OpenSSL version 1.0.1 might be an issue (everything appeared to work OK except HAProxy wasn't issuing the OCSP stapling response when testing).

After compiling HAProxy with OpenSSL 1.0.2, it worked fine. I don't believe this is mentioned in docs anywhere so might be useful if someone else runs into the same problem.

Some other points were for the .issuer files, I just copied and renamed the .chain files from /etc/letsencrypt/live to my HAProxy cert directory. Also, I think it was necessary to add "-verify_other ${pem}.issuer \" to the openssl ocsp lines as per https://community.letsencrypt.org/t/unable-to-verify-ocsp-response/7264/4

After doing the above it works great!

October 20, 2016 at 7:33 PM

Blogger Thomas said...

Hi Stephan,

I'm trying to get OCSP to work with haproxy and letsencrypt as well. In the folder /etc/letsencrypt/live/domain.com are the 4 .pem files. Which one(s) do I have to rename and to what? How do i get/make this .issuer file?

Thanks in advance!

December 12, 2016 at 4:01 PM

You can use some HTML tags, such as <b>, <i>, <a>

This blog does not allow anonymous comments.

Comment moderation has been enabled. All comments must be approved by the blog author.

You will be asked to sign in after submitting your comment.
Please prove you're not a robot