Re: OCSP Stapling

Glen <glen@amsl.com> Mon, 22 August 2016 16:46 UTC

Return-Path: <glen@amsl.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 418F312D630 for <ietf@ietfa.amsl.com>; Mon, 22 Aug 2016 09:46:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.169
X-Spam-Level:
X-Spam-Status: No, score=-103.169 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001, USER_IN_WHITELIST=-100] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HUbGUFZv2zkv for <ietf@ietfa.amsl.com>; Mon, 22 Aug 2016 09:46:39 -0700 (PDT)
Received: from mail.amsl.com (c8a.amsl.com [4.31.198.40]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8ED412D0A0 for <ietf@ietf.org>; Mon, 22 Aug 2016 09:46:39 -0700 (PDT)
Received: from mail.amsl.com (localhost [127.0.0.1]) by c8a.amsl.com (Postfix) with ESMTPS id AEF281E5D63 for <ietf@ietf.org>; Mon, 22 Aug 2016 09:42:29 -0700 (PDT)
Received: from mail-qt0-f175.google.com (mail-qt0-f175.google.com [209.85.216.175]) by c8a.amsl.com (Postfix) with ESMTPSA id 7FFD21E5D5D for <ietf@ietf.org>; Mon, 22 Aug 2016 09:42:29 -0700 (PDT)
Received: by mail-qt0-f175.google.com with SMTP id 93so245599qtg.2 for <ietf@ietf.org>; Mon, 22 Aug 2016 09:46:39 -0700 (PDT)
X-Gm-Message-State: AEkoouv6T00EZUJrjRkUlTWRV0DUwbzgnYPrhYamauhwJ59jDZoDjfFaVGGRBl3YLuywxvHU1+fp8aKZIb1mow==
X-Received: by 10.237.50.230 with SMTP id z93mr24987874qtd.35.1471884398643; Mon, 22 Aug 2016 09:46:38 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.88.105 with HTTP; Mon, 22 Aug 2016 09:46:18 -0700 (PDT)
In-Reply-To: <CAHbk4RLjW6as8jN7CPnhqqGj=Fnw4waGeUnPLDExvsg=ZjXNBQ@mail.gmail.com>
References: <CABL0ig54RAvDGoqJN+YuQWk1unkYuiQLExF4Guo8LXYQKpsg2Q@mail.gmail.com> <CAHbk4RLjW6as8jN7CPnhqqGj=Fnw4waGeUnPLDExvsg=ZjXNBQ@mail.gmail.com>
From: Glen <glen@amsl.com>
Date: Mon, 22 Aug 2016 09:46:18 -0700
X-Gmail-Original-Message-ID: <CABL0ig5pnV+SJG=+=s5YD1sw6pmfu2CKFr0XVUhYEeJst5a_xQ@mail.gmail.com>
Message-ID: <CABL0ig5pnV+SJG=+=s5YD1sw6pmfu2CKFr0XVUhYEeJst5a_xQ@mail.gmail.com>
Subject: Re: OCSP Stapling
To: Sam Whited <sam@samwhited.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/IjHUp6os34ZJmRbY5KGPThAZTuc>
Cc: ietf <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: glen@amsl.com
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Aug 2016 16:46:41 -0000

Sam -

This was done as announced and scheduled, and appears to be configured
and working properly, both on our server directly, and through
CloudFlare.  Various tests I've run seem to confirm that OCSP Stapling
is completed.

If anyone continues to have trouble, please contact us at
ietf-action@ietf.org, or reach out to me directly, and we'll do
whatever we can to assist.

Glen
Glen Barney
IT Director
AMS (IETF Secretariat)




On Mon, Aug 22, 2016 at 9:09 AM, Sam Whited <sam@samwhited.com> wrote:
> On Mon, Aug 1, 2016 at 1:58 PM, Glen <glen@amsl.com> wrote:
>> Absent any objections to this, we will enable OCSP Stapling as
>> requested later this week.
>
> Hi Glen et al,
>
> Original requester here:
>
> Since there were no objections, is there any chance we can go ahead
> and deploy this? I've had a few more times where the OCSP server goes
> down temporarily or just has trouble handling the request.
>
> Thanks,
> Sam
>
>
> --
> Sam Whited
> pub 4096R/54083AE104EA7AD3
>