Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create allow-list for OCSP Must-Staple #7914

Open
aarongable opened this issue Jan 6, 2025 · 0 comments
Open

Create allow-list for OCSP Must-Staple #7914

aarongable opened this issue Jan 6, 2025 · 0 comments

Comments

@aarongable
Copy link
Contributor

As we move towards dropping OCSP support, we have to drop support for Must-Staple as well. We want to do so in a graceful way, by first blocking that extension for folks who have never used Must-Staple in the past, and only dropping support at the last minute for those who have been actively using it.

We announced this plan here: https://letsencrypt.org/2024/12/05/ending-ocsp/#must-staple

To that end, the RA (probably; maybe the CA) needs to grow a new config field which can load an allow-list of accounts which can request the Must-Staple extension, and logic to reject finalize requests from accounts not on that allow-list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant