]> git.ipfire.org Git - thirdparty/apache/httpd.git/commit
Treat a SSLFakeTryLater generated response as a responder error.
authorWIND Internet <info@windinternet.nl>
Tue, 10 Mar 2020 23:50:06 +0000 (00:50 +0100)
committerWIND Internet <info@windinternet.nl>
Tue, 10 Mar 2020 23:50:06 +0000 (00:50 +0100)
commita43f7c1f5af0280d46a3b068a7f2bae75374b80f
tree75bc631bd7988ac5b4ed5e1fea7f305486b8026f
parent124e3ea5e0f3cbfd7e7383a5976d3d9fd1bd4281
Treat a SSLFakeTryLater generated response as a responder error.

Any failure to obtain a response from the original OCSP responder
with SSLStaplingFakeTryLater set to ON should generate a cacheable response.
BUT the cached response has to be marked as an error at time of caching.
Otherwise it will be cached too long, AND the generated error response
will go out to the client even if SSLStaplingReturnResponderErrors
is set to OFF.

This change is in line with trunk and 2.5.
modules/ssl/ssl_util_stapling.c