OCSP stapling is an alternative to the Online Certificate Status Protocol (OCSP) that you can use to validate digital certificates. OCSP stapling allows Alibaba Cloud CDN servers to retrieve OCSP details. This reduces the latency when clients send requests to validate digital certificates and minimizes the time that is consumed by clients to receive the validation responses. This topic describes the use scenarios of OCSP stapling, and how to enable OCSP stapling in the Alibaba Cloud CDN console.
OCSP extension fields are supported by clients. Otherwise, the OCSP stapling feature cannot take effect.
OCSP details are provided by the certificate authority (CA) that issues the digital certificates. Based on the OCSP details, the digital certificates can be validated online based on actual requirements.
- Log on to the Alibaba Cloud CDN console.
- In the left-side navigation pane, click Domain Names.
- On the Domain Names page, find the domain name that you want to manage and click Manage in the Actions column of the domain name.
- In the management pane of the domain name, click HTTPS.
- In the OCSP Stapling section, turn on OCSP stapling.