Optimizing Nginx TLS Time To First Byte
igvita.com
igvita.com
http {
ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /etc/nginx/ssl/stapling.trusted.crt;
resolver 8.8.4.4 8.8.8.8 valid=300s;
resolver_timeout 15s;
}
We https://commando.io use GoDaddy SSL (sigh, face-palm), so the contents of stapling.trusted.crt is: http://pastebin.com/0H0i09PnJust install pdns-recursor and you're good to go.
"DNS" does not let the client set the record TTL, and "DNS" in this case would be a round-trip request to the Google DNS servers listed in the config snippet - precisely what it was suggested be avoided.
Turns out whenever you restart nginx it fetches the ocsp information for each certificate one after the other. The system now had about 100-200 sites on it. I turned ocsp off and the problem was solved.
I still use it on Nginx systems that only have a couple of certs on though.
[1] https://www.ssllabs.com/ssltest/analyze.html?d=commando.io&h...
https://www.ssllabs.com/ssltest/analyze.html?d=commando.io&h...