Re: TLS Feature Extension ocsp must staple demonstration

Rob Stradling <[email protected]> Fri, 29 Jan 2016 10:20:38 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 29/01/16 10:08, Mark Goodwin wrote:
> Hi Dan,
>
> You should be able to find all of the information you need in rfc 7633.
>
> The OID you're looking for is: 1.3.6.1.5.5.7.1.24
> (See
> https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.1
> )
>
> The extension value will be a sequence of the features you want to require
> (see http://tools.ietf.org/html/rfc6066 for information on these). At
> present, only the status_request feature is supported.
>
> This means you want: 0x30, 0x03, 0x02, 0x01, 0x05
>
> I hope this helps.
>
> -mgoodwin

Hi Dan.  Here are some existing examples of certs/sites that might help you:

Correctly configured (status_request required and supported):
   Site: https://must-staple.serverhello.com
   Cert: https://crt.sh/?id=11323316

Deliberately misconfigured (status_request required but _not_ supported):
   Site: https://must-staple-no-ocsp.serverhello.com
   Cert: https://crt.sh/?id=11333146


Also, you might find our SSL Analyzer tool useful for verifying that 
you're doing TLS Feature correctly.  e.g.
   https://sslanalyzer.comodoca.com/?url=must-staple.serverhello.com
   https://sslanalyzer.comodoca.com/?url=must-staple-no-ocsp.serverhello.com

Hope this helps.

> On Tue, Jan 12, 2016 at 4:46 PM, Dan Bryan <[email protected]> wrote:
>
>> Hello, I was reading the following article:
>>
>> https://blog.mozilla.org/security/2015/11/23/improving-revocation-ocsp-must-staple-and-short-lived-certificates/
>>
>> Which states that:
>>
>> "OCSP Must-Staple makes use of the recently specified TLS Feature
>> Extension. When a CA adds this extension to a certificate, it requires your
>> browser to ensure a stapled OCSP response is present in the TLS handshake.
>> If an OCSP response is not present, the connection will fail and Firefox
>> will display a non-overridable error page. This feature will be included in
>> Firefox 45, currently scheduled to be released in March 2016."
>>
>> I have downloaded firefox 45.0a2 (2016-01-12) and would like to see this
>> in action. I own a certificate authority product that allows me to issue
>> custom extensions, but I am unsure of what extension is called. Is their an
>> OID or ASN1 value that indicates the CA should add the TLS Feature
>> extension supporting ocsp must staple?
>>
>> --Dan
>> _______________________________________________
>> dev-security mailing list
>> [email protected]
>> https://lists.mozilla.org/listinfo/dev-security
>>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>

-- 
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online
Office Tel: +44.(0)1274.730505
Office Fax: +44.(0)1274.730909
www.comodo.com

COMODO CA Limited, Registered in England No. 04058690
Registered Office:
   3rd Floor, 26 Office Village, Exchange Quay,
   Trafford Road, Salford, Manchester M5 3EQ

This e-mail and any files transmitted with it are confidential and 
intended solely for the use of the individual or entity to whom they are 
addressed.  If you have received this email in error please notify the 
sender by replying to the e-mail containing this attachment. Replies to 
this email may be monitored by COMODO for operational or business 
reasons. Whilst every endeavour is taken to ensure that e-mails are free 
from viruses, no liability can be accepted and the recipient is 
requested to use their own virus checking software.