Comments (6)
Why is it relevant that a CA has IPv6 OCSP and CRL infrastructure?
from ssllabs-scan.
For what i understand, when OCSP stapling is implemented the web server queries the OCSP server and the response is "stapled" in the tls handshake.
When OCSP stapling is configured in the server, if the server is pure IPv6 doesn't it try to communicate via IPv6 with the OCSP server? If so, if the server is IPv6 and the CA OCSP is only IPv4, it will not work, right? I don't see many cases for this now, but with IPv4 exaustion, i guess it will happen more in the future.
Also if a client only has IPv6? How will he connect to the OCSP server if it doesn't support IPv4?
The GlobalSign SSL Check Test (that i think is based on Qualys test), tests IPv6 OCSP support. They have an explanation why they do the test:
«We have detected that your site is available over IPv6 but your site's certificate contains references to servers that do not support IPv6. This means that despite your organization having done the work to support IPv6, users who can only communicate over IPv6 would experience errors when visiting your site.»
Source: https://sslcheck.globalsign.com/en/help/c15b8d74
I don't think it's a priority but it would be good to test OCSP IPv6 support in the future.
I see this like a feature for the future, not a bug.
from ssllabs-scan.
I understand. We don't test IPv6 at all now, but that should change soon. I'll consider this ticket then.
from ssllabs-scan.
ivanr, another thing i remembered is that you can have the same server with SNI for IPv4 and without SNI for IPv6, since a provider can give one IPv4 and a lots of IPv6 for the same server, like DO for instance.
So i'm guessing if the IPv6 test shouldn't be considered an individual different endpoint.
from ssllabs-scan.
GlobalSign warns about CRL and OCSP inaccessibility over IPv6 primarily because their own servers support IPv6.
Comodo made the servers available over IPv6 on 15 February 2015.
Who else?
from ssllabs-scan.
Yes, Globalsign and Comodo seem to be the only ones:
http://ip6.nl/#!ocsp.globalsign.com | http://ip6.nl/#!crl.globalsign.com
http://ip6.nl/#!ocsp.comodoca.com | http://ip6.nl/#!crl.comodoca.com
Entrust as some IPv6 capability, but doesn't seem to have full support
http://ip6.nl/#!ocsp.entrust.net | http://ip6.nl/#!crl.entrust.net
Don't know other that provides OCSP/CRL in IPv6.
from ssllabs-scan.
Related Issues (20)
- Error Unable to connect to server. HOT 1
- Outdated Server Rating Guide Visuals
- (whoops, filed this in the wrong place)
- Regarding JDK Update Issues HOT 7
- Release v1.5
- INTERNAL ERROR: test.drownattack.com HOT 1
- API v2 "getEndpointData" returns server certificate information but v3 and v4 do not HOT 2
- First
- Qualys SSL Labs scan is incorrectly capping TLS 1.3 servers to an "A" rating due to testing an obsolete functionality. HOT 2
- incorrect cipher suite order for TLS 1.3 HOT 2
- -email flag should not be required with -version flag
- (api.)dev.ssllabs.com ist not available HOT 2
- Unable to resolve domain name HOT 3
- Add HTTP/3 support HOT 2
- when will v3 API be deprecated? HOT 2
- 405 error on register HOT 1
- Detection for Server incompatibility with "post-quantum key agreement"
- Incomplete cipher detection on github.com
- Cipher Suits update value - TLS_DHE_RSA, - at 2024 are Weak
- Getting 529 response with ssllabs-scan, but WebUI works HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from ssllabs-scan.