diff options
| author | Daniel Micay <daniel.micay@grapheneos.org> | 2025-05-04 21:57:41 -0400 |
|---|---|---|
| committer | Daniel Micay <daniel.micay@grapheneos.org> | 2025-05-04 23:46:56 -0400 |
| commit | 298c357bc9a6023d1ce470ad1711851775313c0a (patch) | |
| tree | 1cd61c8c4e8a5c692b11e645c8ed28a4f2501f36 | |
| parent | c57490de09fcdc3eadadc8422b4b17da313841b2 (diff) | |
handle Let's Encrypt removing OCSP support
We can no longer use OCSP stapling and Must-Staple. These will soon be
obsolete once the `shortlived` profile is available for public use since
it will provide certificates with a similar lifetime as OCSP responses.
In the meantime, we've moved to the `tlsserver` profile stripping legacy
features to prepare for the `shortlived` profile which will be identical
to `tlsserver` but with a validity period of 6 days.
| -rwxr-xr-x | certbot-replicate | 1 | ||||
| -rw-r--r-- | nginx/nginx.conf | 5 | ||||
| -rw-r--r-- | static/features.html | 1 |
3 files changed, 0 insertions, 7 deletions
diff --git a/certbot-replicate b/certbot-replicate index aab07d55..ef7d9cf4 100755 --- a/certbot-replicate +++ b/certbot-replicate @@ -11,7 +11,6 @@ for replica in ${replicas[@]}; do echo rsync -rpcvl --delete --fsync --preallocate /etc/letsencrypt/ $replica:/etc/letsencrypt && - rsync -rpcvl --delete --fsync --preallocate /var/cache/certbot-ocsp-fetcher/ $replica:/var/cache/certbot-ocsp-fetcher && ssh root@$replica nginx -s reload || status=1 done diff --git a/nginx/nginx.conf b/nginx/nginx.conf index d4716ed9..28fb9d92 100644 --- a/nginx/nginx.conf +++ b/nginx/nginx.conf @@ -66,11 +66,6 @@ http { ssl_session_timeout 1d; ssl_buffer_size 4k; - ssl_trusted_certificate /etc/letsencrypt/live/grapheneos.org/chain.pem; - ssl_stapling on; - ssl_stapling_verify on; - ssl_stapling_file /var/cache/certbot-ocsp-fetcher/grapheneos.org.der; - log_format main '$connection-$connection_requests $remote_addr $remote_user $ssl_session_reused $ssl_protocol $server_protocol ' '$host $request_method "$request_uri" $status $request_length $body_bytes_sent/$bytes_sent ' '$request_time $upstream_connect_time/$upstream_header_time/$upstream_response_time ' diff --git a/static/features.html b/static/features.html index 1dc71e9a..1a650d21 100644 --- a/static/features.html +++ b/static/features.html @@ -1489,7 +1489,6 @@ when sending mail including alert messages from the attestation service</li> <li>SSHFP across all domains for pinning SSH keys</li> <li>Static key pinning for our services in apps like Auditor</li> - <li>Our web services use robust OCSP stapling with Must-Staple</li> <li>No persistent cookies or similar client-side state for anything other than login sessions, which are set up securely using <code>SameSite=Strict</code>, <code>Secure</code>, <code>HttpOnly</code>, and <code>Path=/</code> flags, prefixed with |
