quickjs-tart

quickjs-based runtime for wallet-core logic
Log | Files | Refs | README | LICENSE

doh-cert-status.md (813B)


      1 ---
      2 c: Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
      3 SPDX-License-Identifier: curl
      4 Long: doh-cert-status
      5 Help: Verify DoH server cert status OCSP-staple
      6 Added: 7.76.0
      7 Category: dns tls
      8 Multi: boolean
      9 See-also:
     10   - doh-insecure
     11 Example:
     12   - --doh-cert-status --doh-url https://doh.example $URL
     13 ---
     14 
     15 # `--doh-cert-status`
     16 
     17 Same as --cert-status but used for DoH (DNS-over-HTTPS).
     18 
     19 Verify the status of the DoH servers' certificate by using the Certificate
     20 Status Request (aka. OCSP stapling) TLS extension.
     21 
     22 If this option is enabled and the DoH server sends an invalid (e.g. expired)
     23 response, if the response suggests that the server certificate has been
     24 revoked, or no response at all is received, the verification fails.
     25 
     26 This support is currently only implemented in the OpenSSL and GnuTLS backends.