Re: TLS Feature Extension ocsp must staple demonstration

Mark Goodwin <[email protected]> Fri, 29 Jan 2016 10:08:05 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <CAGXeGt+nfvi4=XQhfZUQq+T=giCEUwno7N2RNA7d-P0r3AzypA@mail.gmail.com>
Hi Dan,

You should be able to find all of the information you need in rfc 7633.

The OID you're looking for is: 1.3.6.1.5.5.7.1.24
(See
https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.1
)

The extension value will be a sequence of the features you want to require
(see http://tools.ietf.org/html/rfc6066 for information on these). At
present, only the status_request feature is supported.

This means you want: 0x30, 0x03, 0x02, 0x01, 0x05

I hope this helps.

-mgoodwin


On Tue, Jan 12, 2016 at 4:46 PM, Dan Bryan <[email protected]> wrote:

> Hello, I was reading the following article:
>
> https://blog.mozilla.org/security/2015/11/23/improving-revocation-ocsp-must-staple-and-short-lived-certificates/
>
> Which states that:
>
> "OCSP Must-Staple makes use of the recently specified TLS Feature
> Extension. When a CA adds this extension to a certificate, it requires your
> browser to ensure a stapled OCSP response is present in the TLS handshake.
> If an OCSP response is not present, the connection will fail and Firefox
> will display a non-overridable error page. This feature will be included in
> Firefox 45, currently scheduled to be released in March 2016."
>
> I have downloaded firefox 45.0a2 (2016-01-12) and would like to see this
> in action. I own a certificate authority product that allows me to issue
> custom extensions, but I am unsure of what extension is called. Is their an
> OID or ASN1 value that indicates the CA should add the TLS Feature
> extension supporting ocsp must staple?
>
> --Dan
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>