Does headscale support OCSP stapling? #432

Closed
opened 2025-12-29 01:29:06 +01:00 by adam · 1 comment
Owner

Originally created by @wly-13 on GitHub (Feb 17, 2023).

Problem: revoked certificates are still valid

When I use a revoked SSL certificate issued by Let's Encrypt to run headscale, the client tailscale can still log in normally. This may have some security risk.
So I'm wondering if headscale support OCSP stapling?

Originally created by @wly-13 on GitHub (Feb 17, 2023). <!-- Headscale is a multinational community across the globe. Our common language is English. Please consider raising the feature request in this language. --> **Problem: revoked certificates are still valid** When I use a revoked SSL certificate issued by Let's Encrypt to run headscale, the client tailscale can still log in normally. This may have some security risk. So I'm wondering if headscale support OCSP stapling? <!-- A clear and precise description of what new or changed feature you want. --> <!-- Please include the reason, why you would need the feature. E.g. what problem does it solve? Or which workflow is currently frustrating and will be improved by this? -->
adam added the enhancement label 2025-12-29 01:29:06 +01:00
adam closed this issue 2025-12-29 01:29:06 +01:00
Author
Owner

@kradalby commented on GitHub (May 10, 2023):

No we sadly does not support this, and it is out of scope for this project.

@kradalby commented on GitHub (May 10, 2023): No we sadly does not support this, and it is out of scope for this project.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/headscale#432