Remove the ability for the issuance package to include the AIA OCSP URI and the Must Staple (more properly known as the tlsRequest) extension in certificates. Deprecate the "OmitOCSP" and "AllowMustStaple" profile config keys, as they no longer have any effect. Similarly deprecate the "OCSPURL" issuer config key, as it is no longer included in certificates. Update the tests to always include to CRLDP extension instead, and remove some OCSP- or Stapling-specific test cases. Fixes https://github.com/letsencrypt/boulder/issues/8179 |
||
---|---|---|
.. | ||
proto | ||
testdata | ||
ca.go | ||
ca_test.go | ||
crl.go | ||
crl_test.go | ||
ocsp.go | ||
ocsp_test.go |