Re: TLS Feature Extension ocsp must staple demonstration
Rob Stradling <[email protected]> Fri, 29 Jan 2016 10:20:38 +0000
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On 29/01/16 10:08, Mark Goodwin wrote: > Hi Dan, > > You should be able to find all of the information you need in rfc 7633. > > The OID you're looking for is: 1.3.6.1.5.5.7.1.24 > (See > https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.1 > ) > > The extension value will be a sequence of the features you want to require > (see http://tools.ietf.org/html/rfc6066 for information on these). At > present, only the status_request feature is supported. > > This means you want: 0x30, 0x03, 0x02, 0x01, 0x05 > > I hope this helps. > > -mgoodwin Hi Dan. Here are some existing examples of certs/sites that might help you: Correctly configured (status_request required and supported): Site: https://must-staple.serverhello.com Cert: https://crt.sh/?id=11323316 Deliberately misconfigured (status_request required but _not_ supported): Site: https://must-staple-no-ocsp.serverhello.com Cert: https://crt.sh/?id=11333146 Also, you might find our SSL Analyzer tool useful for verifying that you're doing TLS Feature correctly. e.g. https://sslanalyzer.comodoca.com/?url=must-staple.serverhello.com https://sslanalyzer.comodoca.com/?url=must-staple-no-ocsp.serverhello.com Hope this helps. > On Tue, Jan 12, 2016 at 4:46 PM, Dan Bryan <[email protected]> wrote: > >> Hello, I was reading the following article: >> >> https://blog.mozilla.org/security/2015/11/23/improving-revocation-ocsp-must-staple-and-short-lived-certificates/ >> >> Which states that: >> >> "OCSP Must-Staple makes use of the recently specified TLS Feature >> Extension. When a CA adds this extension to a certificate, it requires your >> browser to ensure a stapled OCSP response is present in the TLS handshake. >> If an OCSP response is not present, the connection will fail and Firefox >> will display a non-overridable error page. This feature will be included in >> Firefox 45, currently scheduled to be released in March 2016." >> >> I have downloaded firefox 45.0a2 (2016-01-12) and would like to see this >> in action. I own a certificate authority product that allows me to issue >> custom extensions, but I am unsure of what extension is called. Is their an >> OID or ASN1 value that indicates the CA should add the TLS Feature >> extension supporting ocsp must staple? >> >> --Dan >> _______________________________________________ >> dev-security mailing list >> [email protected] >> https://lists.mozilla.org/listinfo/dev-security >> > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security > -- Rob Stradling Senior Research & Development Scientist COMODO - Creating Trust Online Office Tel: +44.(0)1274.730505 Office Fax: +44.(0)1274.730909 www.comodo.com COMODO CA Limited, Registered in England No. 04058690 Registered Office: 3rd Floor, 26 Office Village, Exchange Quay, Trafford Road, Salford, Manchester M5 3EQ This e-mail and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the sender by replying to the e-mail containing this attachment. Replies to this email may be monitored by COMODO for operational or business reasons. Whilst every endeavour is taken to ensure that e-mails are free from viruses, no liability can be accepted and the recipient is requested to use their own virus checking software.