OCSP stapling
Please switch on OCSP stapling. This feature makes access to HTTPS sites faster in case of OSCP present, so avoid clients requests to CA to verify certs.

OCSP stapling is now enabled across all Cloudways servers.
Regards,
Cloudways Team.
-
Loren Diaz commented
This post provided structured knowledge that was easy to absorb. The logical progression of ideas ensured a smooth reading experience.
https://africansmag.co.za/ -
Raza Rizvi commented
I also had to enable OCSP stapling but I was not able to do it myself as advance/root server access is not available on Cloudways, fortunately I got it activated by requesting CSR on chat and it was done in few minutes. Hope I will not be charge any additional amount because I was neither told nor found charges related to it anywhere.
Cloudways teem seem to be more effective when it comes to standing by so somehow not providing root access can be tolerated as they do many operations on our behalf. -
frihet commented
I was just told that turning on ocsp stapling will cost $100 / month / server.
"Mujtaba
This is to let you know that as it requires customization on servers therefore you have to go for advanced support option. Advanced support charges are $100/month/server." -
Paul Braren commented
Good news, I asked Cloudways to enable this for me today, and they immediately did. So apparently OCSP stapling has become possible, just not announced, or available via the Web UI.
Thank you, Cloudways!
-
Paul Braren commented
Any progress?
-
Paul Braren commented
Any progress?
-
Paul commented
C'mon Cloudways - this is the obvious final step to close the loop on SSL implementation.
-
Milo Jennings commented
This is the article that led me to vote for this feature: https://blog.cloudflare.com/ocsp-stapling-how-cloudflare-just-made-ssl-30/
-
frihet commented
Presently there is not a way to modify NGINX's SSL configuration.
I am looking to be able to configure Nginx server to use OCSP Stapling.
Edit site’s SSL configuration file to Add the following directives INSIDE the “server { }” block:
ssl_stapling on;
ssl_stapling_verify on;This will reduce the SSL overhead abnd speed up performance.
-
frihet commented
OCSP calls are costing nearly a 1/2 second on every page lookup...
As google continues to push for SSL only, this overhead is hurting page speed..It could very simply be enabled in the stack:
https://www.digicert.com/ssl-support/nginx-enable-ocsp-stapling-on-server.htm
-
Paul Braren commented
If folks are interested in a bit more detail about why OCSP stapling would be good, see also my brief write-up at:
https://TinkerTry.com/about#certificate
https://TinkerTry.com/testing-of-http2-underway-at-tinkertry#jul-08-2016-update -
Paul Braren commented
+1