Closed CarterLi closed 6 years ago
added
why you remove that feature from your repo?
@pleaz Because I don't use BoringSSL now.
You could get it on: https://raw.githubusercontent.com/kn007/patch/35f2b0decbc510f2c8adab9261e3d46ba1398e33/Enable_BoringSSL_OCSP.patch
Restore this patch and increase the allowed stapling file size(for some CA like GlobalSign https://github.com/kn007/patch/commit/0b83bc2789bc919e2174f9480d7f387c33b1d1cf).
I wrote a article for auto-rebuild OCSP stapling file with shell and atd(at cron).
For people who like 折腾 Note only \"ssl_stapling_file\" with single cert is supported. Use it as your own risk.
Tested on Nginx/1.14.0, BoringSSL/master with nginx.patch
Be sure to apply this patch to enable TLS13 support