OCSP Stapling Behavior in Qt 6
Qt 6 does not provide a unified, cross-platform mechanism to enforce OCSP stapling requirements. Because the Qt Network module delegates the TLS handshake to platform-specific backends (OpenSSL, Schannel, or Secure Transport), the handling of missing or malformed OCSP staples is determined by the backend's native implementation rather than a centralized Qt policy.
Backend-Specific Handling
When a backend does not natively support status validation or is configured for "soft-fail," a missing or malformed OCSP staple is typically ignored. The connection proceeds as long as the certificate chain is otherwise valid. However, the behavior varies by platform:
- OpenSSL (Linux/Android): Generally treats missing staples as a non-fatal event unless specific flags are passed to the underlying SSL context, which are not exposed via
QSslConfiguration.
- Schannel (Windows): Follows Windows system-level revocation policies. If the system is configured to require revocation checks and the staple is missing, it may attempt a synchronous DNS lookup to an OCSP responder.
- Secure Transport (macOS/iOS): Similarly relies on Apple's system trust evaluation, which may vary between "fail-open" and "fail-closed" based on the OS version and certificate profile.
Enforcing Validation Requirements
Since there is no QSslConfiguration::setOcspRequired(bool) method, you cannot enforce a "hard-fail" for missing staples through the Qt API alone. To implement a strict security policy across platforms, you must move validation to the application layer:
- Monitor SSL Errors: Connect to the
QSslSocket::sslErrors signal. While standard certificate errors are reported, OCSP-specific failures may not always trigger a QSslError depending on the backend.
- Manual Verification: For high-security requirements, manually extract the certificate chain using
QSslSocket::peerCertificateChain() and perform an out-of-band OCSP request using a dedicated library or system call.
- Backend Alignment: Ensure all deployment environments use a consistent OpenSSL version if possible, as this reduces variance compared to mixing native OS backends.
Verification Steps
To diagnose whether the issue is the server's response or the Qt backend's interpretation, use the following command to verify the staple independently of Qt:
openssl s_client -connect yourserver.com:443 -status
Check the OCSP response: section of the output. If the staple is present and valid here but the Qt application behaves inconsistently, the issue lies in the backend's validation logic.
Diagnostic Detail Required: To provide a more specific workaround, please provide the output of QSslSocket::sslLibraryVersionString() for the platforms where validation is failing.