Afaik, NGINX and Apache only have OCSP stapling support.
Afaik, NGINX and Apache only have OCSP stapling support.
So no API-based configuration, like OCSP stapling, that just works. I can probably try to configure this with a cronjob/systemd timer but this is significantly less ergonomic.
The client does that for you, by checking back at the CA. No need for any configuration server side.
https://letsencrypt.org/2023/03/23/improving-resliiency-and-...
Some good implementations of ocsp stapling can already automatically get a new certificate if they receive a “revoked” ocsp response.
Requiring humans to read their email and be looped in is work I want to avoid needing at all.
If you use certs for client auth it’s unlikely it’s used on the web and only in a company setting where you control the PCs, where you could just use something more suited for that case.
[0] https://httpd.apache.org/docs/current/mod/mod_ssl.html#sslpr...