OCSP stapling is an alternative approach to the Online Certificate Status Protocol (OCSP) that you can use to validate digital certificates. OCSP stapling allows Alibaba Cloud CDN servers to retrieve OCSP details. This reduces the latency that occurs when clients send requests to validate digital certificates. OCSP stapling also reduces the time that is required by clients to receive the validation responses. This topic describes the application scenarios of OCSP stapling. It also provides details about how to enable this feature in the Alibaba Cloud CDN console.
OCSP extension fields are supported by clients. Otherwise, the OCSP stapling feature fails to take effect.
OCSP details are provided by the certification authority (CA) that issues the digital certificates. Based on the OCSP details, you can check the digital certificates online in real time to determine whether they are valid.
- Log on to the Alibaba Cloud CDN console.
- In the left-side navigation pane, click Domain Names.
- On the Domain Names page, find the target domain name and click Manage.
- In the OCSP Stapling section, turn on the switch.