Skip to content

Latest commit

 

History

History
26 lines (21 loc) · 815 Bytes

doh-cert-status.md

File metadata and controls

26 lines (21 loc) · 815 Bytes
c SPDX-License-Identifier Long Help Added Category Multi See-also Example
Copyright (C) Daniel Stenberg, <[email protected]>, et al.
curl
doh-cert-status
Verify DoH server cert status OCSP-staple
7.76.0
dns tls
boolean
doh-insecure
--doh-cert-status --doh-url https://doh.example $URL

--doh-cert-status

Same as --cert-status but used for DoH (DNS-over-HTTPS).

Verifies the status of the DoH servers' certificate by using the Certificate Status Request (aka. OCSP stapling) TLS extension.

If this option is enabled and the DoH server sends an invalid (e.g. expired) response, if the response suggests that the server certificate has been revoked, or no response at all is received, the verification fails.

This support is currently only implemented in the OpenSSL and GnuTLS backends.