ๅ่งไบ,OCSP
2024/10/29,Microsoft Root Program ไฟฎๆนไบ[ไธไธชไธ่ตท็ผ็ๆๆกฃ](https://learn.microsoft.com/en-us/security/trusted-root/program-requirements) ไธญไธ่ตท็ผ็ไธๆฎต,ไธบๆ็ปญไธๅนดๅค็ OCSP ๅๅซไปชๅผ็ปไธไบไธไธชๅฅๅท,็ปๆไบ OCSP ๅคงๅ้ๆงๅฐๅ CRL ไธพ่ตทๅคงๅ้ๆง็ๆถไปฃ。 ่ฎฉๆไปฌๅจ่ฟ้็บชๅฟตๅฎ,ๆๅ็ OCSP ๅผบๅถ่ฆๆฑ([ๆถๅ
ๆบ](https://web.archive.org/web/20241002221253/https://learn.microsoft.com/en-us/security/trusted-root/program-requirements)),ๅฎไปฃ่กจไบๅ
ฌๅผๅ ๅฏๅบ็ก่ฎพๆฝไธๆฌก้ฟ่พพ 20 ๅนด็ๆข็ดข,ไน่ฎฐๅฝไบไบบ็ฑป็ฝ็ปๅบๅปบ็ช้ฃ็่ฟ็ 20 ๅนดๅฏนๆๆฏ็ๅๅๆนๅ: ``` All end-entity certificates must contain an AIA extension with a valid OCSP URL. These certificates may also contain a CDP extension that contains a valid CRL URL. All other certificate types must contain either an AIA extension with an OCSP URL or a CDP extension with a valid CRL URL. ``` ## ไปไนๆฏ ๆ่ฎธๆไธ้่ฆ่งฃ้ไปไนๆฏ OCSP(Online Certificate Status Protocol,ๅจ็บฟ่ฏไนฆ็ถๆๅ่ฎฎ),ๅ ไธบๅฝๅ
ๅผๅ่
ๆฉๅทฒๆทฑๅๅ
ถๅฎณ:ๅ ไนๆฏไธช Nginx ไผๅๆ็จ้ฝๅจๆไฝ ๆๅผ OCSP Stapling。 ๆญฃๅฆๆไปฌๆ็ฅ,OCSP ๆฌ่ดจๆฏไธไธช HTTP ๆๅก,็จๆทๅจๆฏๆฌก้ๅฐ่ฏไนฆๆถๅฐ่ฏไนฆๅบๅๅทๆๆๅ็ป CA ็ๆๅกๅจ,CA ๅๆๆ่ฟๅไธไธชๆฏๅฆๅฏ็จ็็ถๆ。 ่ฟๆฏไผ ็ป็ CRL(Certificate Revocation List,่ฏไนฆๅ้ๅ่กจ) ๅฏ้
ทๅคไบ:็จๆทไธๅ้่ฆๆฏๆฌกไธ็ฝๅฐฑ่ฆๅๅๅฐ็จ 56K modem ไป **ๆฏไธช** CA ้ฃ้ไธไธชๆฐ M ็ๆไปถ(ๅ
ถไธญๅ
ๅซ่ฟไธช...