# # OCSP Response Stapling # # nginx/1.7.0 # OpenSSL 1.0.1f 6 Jan 2014 # # Enables or disables stapling of OCSP responses by the server. # Default: ssl_stapling off; ssl_stapling on; # # Enables or disables verification of OCSP responses by the server. # Default: ssl_stapling_verify off; ssl_stapling_verify on; # # DNS servers used to resolve names for OCSP servers (and upstream servers) # Only needed if there is no system configured resolver or you need to ovverride # somehow. # Default: #resolver 172.20.10.43 172.20.10.1; # # When set, the stapled OCSP response will be taken from the specified file # instead of querying the OCSP responder specified in the server certificate. # The file should be in the DER format as produced by the “openssl ocsp” # command. # Default: #ssl_stapling_file /etc/dehydrated/certs/;