发个福利!第一个大陆 OCSP 的自动续期证书机构
如何使用: 常见 ACME 客户端指定 `server` 参数为 `https://acme.pki.plus/acme/directory` 就可以
– https://www.v2ex.com/t/822401 – https://www.pki.plus – https://acme.pki.plus/acme/directory
OCSP 性能评测: 对比之下海外机构,包过付费 Sectigo 证书的 OCSP 都是要 500 毫秒以上
- wget https://crt.sh/?d=5711085653 -O quantumca-user.crt
- wget https://crt.sh/?d=4089178243 -O quantumca-ca.crt
-
- for i in $(seq 0 10);
- do
- openssl ocsp -issuer quantumca-ca.crt -cert quantumca-user.crt -nonce –reqout – | curl http://ocsp.sslcom.cn -s -H ‘Content-type: application/ocsp-request’ -X POST –data-binary @- -w "Total time: %{time_total}n"
- done
-
- > Total time: 0.028411
- > Total time: 0.013579
- > Total time: 0.014744
- > Total time: 0.013982
- > Total time: 0.015370
- > Total time: 0.012121
- > Total time: 0.012970
- > Total time: 0.014744
- > Total time: 0.015144
- > Total time: 0.015726
- > Total time: 0.013049
-
- wget https://crt.sh/?d=1205293401 -O sectigo-user.crt
- wget https://crt.sh/?d=1282303295 -O sectigo-ca.crt
-
- for i in $(seq 0 10);
- do
- openssl ocsp -issuer sectigo-ca.crt -cert sectigo-user.crt -nonce –reqout – | curl http://ocsp.sectigo.com -s -H ‘Content-type: application/ocsp-request’ -X POST –data-binary @- -w "Total time: %{time_total}n"
- done
- Total time: 0.475027
- Total time: 0.883063
- Total time: 0.463176
- Total time: 1.403743
- Total time: 1.464955
- Total time: 0.463922
- Total time: 0.462206
- Total time: 0.445534
- Total time: 0.472526
- Total time: 0.468809
- Total time: 0.461183
复制代码
|