openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/apache-selfsigned.key -out /etc/ssl/certs/apache-selfsigned.crt
SSLEngine on SSLCertificateFile /etc/ssl/certs/apache-selfsigned.crt SSLCertificateKeyFile /etc/ssl/private/apache-selfsigned.key
SSLStaplingCache shmcb:/tmp/stapling_cache(128000) SSLUseStapling On SSLStaplingResponderTimeout 5 SSLStaplingReturnResponderErrors Off
systemctl restart apache2
openssl s_client -connect example.com:443 -status
此命令应返回如下行:
OCSP Response Data: .......
如果返回状态代码为“good”的响应,则OCSP Stapling正常工作。