vrk-kpa / xroad-joint-development

Unmaintained repository. Development moved to: https://github.com/nordic-institute/X-Road-development
19 stars 8 forks source link

As a Security Server Administrator I want the the security server to recover faster from an OCSP responder downtime #216

Closed JyrgenSuvalov closed 6 years ago

JyrgenSuvalov commented 6 years ago

Affected components: - xroad-signer Affected documentation: - ug-sysparams Estimated delivery: - N/A External reference: - https://jira.ria.ee/browse/XTE-402

Problem

When an OCSP responder is down for an extended period, the OCSP refresh cycle'is retry time grows pretty long, because of the current Fibonacci logic. So when the OCSP responder starts working again, it takes too much time for security servers to refresh their certificates' OCSP status.

We propose implementing a sort of max_ocsp_retry_delay parameter that's configurable and can be set to a more acceptable timeframe.

Acceptance criteria

petkivim commented 6 years ago

Added as an enhancement request to X-Road Service Desk.