Giter VIP home page Giter VIP logo

Comments (6)

ivanr avatar ivanr commented on September 6, 2024

Why is it relevant that a CA has IPv6 OCSP and CRL infrastructure?

from ssllabs-scan.

andrepereiradasilva avatar andrepereiradasilva commented on September 6, 2024

For what i understand, when OCSP stapling is implemented the web server queries the OCSP server and the response is "stapled" in the tls handshake.

When OCSP stapling is configured in the server, if the server is pure IPv6 doesn't it try to communicate via IPv6 with the OCSP server? If so, if the server is IPv6 and the CA OCSP is only IPv4, it will not work, right? I don't see many cases for this now, but with IPv4 exaustion, i guess it will happen more in the future.

Also if a client only has IPv6? How will he connect to the OCSP server if it doesn't support IPv4?
The GlobalSign SSL Check Test (that i think is based on Qualys test), tests IPv6 OCSP support. They have an explanation why they do the test:
«We have detected that your site is available over IPv6 but your site's certificate contains references to servers that do not support IPv6. This means that despite your organization having done the work to support IPv6, users who can only communicate over IPv6 would experience errors when visiting your site.»
Source: https://sslcheck.globalsign.com/en/help/c15b8d74

I don't think it's a priority but it would be good to test OCSP IPv6 support in the future.
I see this like a feature for the future, not a bug.

from ssllabs-scan.

ivanr avatar ivanr commented on September 6, 2024

I understand. We don't test IPv6 at all now, but that should change soon. I'll consider this ticket then.

from ssllabs-scan.

andrepereiradasilva avatar andrepereiradasilva commented on September 6, 2024

ivanr, another thing i remembered is that you can have the same server with SNI for IPv4 and without SNI for IPv6, since a provider can give one IPv4 and a lots of IPv6 for the same server, like DO for instance.
So i'm guessing if the IPv6 test shouldn't be considered an individual different endpoint.

from ssllabs-scan.

selecadm avatar selecadm commented on September 6, 2024

GlobalSign warns about CRL and OCSP inaccessibility over IPv6 primarily because their own servers support IPv6.

Comodo made the servers available over IPv6 on 15 February 2015.

Who else?

from ssllabs-scan.

andrepereiradasilva avatar andrepereiradasilva commented on September 6, 2024

Yes, Globalsign and Comodo seem to be the only ones:
http://ip6.nl/#!ocsp.globalsign.com | http://ip6.nl/#!crl.globalsign.com
http://ip6.nl/#!ocsp.comodoca.com | http://ip6.nl/#!crl.comodoca.com

Entrust as some IPv6 capability, but doesn't seem to have full support
http://ip6.nl/#!ocsp.entrust.net | http://ip6.nl/#!crl.entrust.net

Don't know other that provides OCSP/CRL in IPv6.

from ssllabs-scan.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.