https://bugs.exim.org/show_bug.cgi?id=2350
--- Comment #6 from Torsten Tributh <torsten@???> ---
Hi,
happy new year. After investigating I bit deeper, we can close this issue for
now.
There is no support in the client handshake to staple the OCSP status_response
for TLS< 1.3 and actually no codepoints registered for usage in TLS 1.3.
Maybe only a hint in the manual could be useful, possibly like this:
"Take care not to use a single certificate with OCSP-must-stable feature
enabled if you want to use it for incoming and outgoing connections.
The definitions have lake of support to staple OCSP in client mode."
Torsten
--
You are receiving this mail because:
You are on the CC list for the bug.