-
Notifications
You must be signed in to change notification settings - Fork 18.4k
Description
I'd like to do OCSP verification using the VerifyPeerCertificate
field of tls.Config
. My understanding is that it is not possible to access the stapled OCSP response from the peer in this callback. This is because the stapled response is available on the connection itself through the OCSPResposne
method on tls.Conn
or through the ConnectionState
type. Unless there is a way to access it in the callback, the OCSP verification will have to be done after the handshake has been completed, which isn't ideal because the peer logs will show that the connection was successfully established.
Is there a way to currently access the stapled responses in the verification callback that I've missed? If not, is this possible given how the TLS handshake code is currently written?