“security.OCSP.require” in Google Chrome

2

0

https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion

"Users of Mozilla Firefox that are concerned about this issue should enable security.OCSP.require in the about:config dialog."

How can i enable this feature in Google Chrome?

LanceBaynes

Posted 2011-03-23T22:34:14.523

Reputation: 3 510

possible duplicate of “security.OCSP.require” in Google Chrome

– Kez – 2011-03-24T11:44:35.330

Answers

2

There is no about:config in Chrome so there is no way (that I am aware of) to force OCSP usage. However, it should use OCSP by default and fallback to CRLs if that doesn't work. Plus, the web browsers have blacklisted the serial numbers of the stolen certificates directly in the web browser so if you upgrade your web browser you will be completely protected.

Robert

Posted 2011-03-23T22:34:14.523

Reputation: 136

1

You'll be completely protected... THIS time. OCSP and CRL checking are a joke if the browser doesn't refuse the connection should the OCSP or CRL services prove (or appear) to be offline. As far as I'm concerned all browsers should refuse connections when the certificate can't be verified, but browser makers are loath to do so because users would blame the browser for any problems they experience, and likely switch over to another with looser restrictions.

The setting can be found in: Google Chrome > Settings > Advanced settings > Security > Check server for revocation (or something along those lines.. I'm using a Dutch version)

MHonig

Posted 2011-03-23T22:34:14.523

Reputation: 11