Enabling OCSP Stapling in OpenSSL TLS Servers
Learn how to enable OCSP stapling in an OpenSSL TLS server, see a minimal C callback example, and verify the stapled response with openssl s_client.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Learn how to enable OCSP stapling in an OpenSSL TLS server, see a minimal C callback example, and verify the stapled response with openssl s_client.
When connecting to a PostgreSQL instance over TLS using DBeaver, the client sometimes rejects the server's certificate despite the certificate being valid and trusted by the system Java keystore. The issue appears to be related to DNS resolution of the host name used in the connection string, which may cause a mismatch between the certificate's subject alter
When building TypeScript applications that validate TLS certificates by performing DNS lookups, developers rely on the dns and dnsPromises APIs to obtain A, AAAA, MX, or TXT records. The goal is to guarantee that the type definitions accurately reflect the shape of the resolved data so that certificate hostname validation logic can safely process the results
Administrators want Redis to reject TLS connections when the client certificate does not match the hostname used to reach the server, ensuring that a certificate issued for one service cannot be reused for another. Currently, with tls-auth-clients set to yes, Redis validates the certificate chain and expiration but relies on the underlying OpenSSL library to