启用ocsp stapling可减少150–300ms tls握手延迟,原理是nginx代替客户端向ca的ocsp服务器查询并缓存吊销状态,在tls握手时一并发送给客户端;需满足nginx≥1.3.7、openssl≥1.0.1、证书含authorityinfoaccess扩展、时间准确、证书链完整、resolver显式配置等前提。

直接启用 ssl_stapling 并不能“绕过 CA 机构解析”,而是让服务器代替客户端去查 CA 的 OCSP 服务器,并把结果缓存后在 TLS 握手时一并发送给客户端。这个过程不跳过验证,也不削弱安全性,但确实能显著降低移动端 HTTPS 延时——尤其在弱网、高延迟或 DNS 不稳定环境下。
关键效果是:省掉客户端一次独立的 OCSP 查询(含 DNS 解析 + TCP 连接 + TLS + HTTP 请求),实测可减少 150–300ms 握手延迟,95 分位延迟压到 100ms 内。
✅ 满足前提条件才能生效
- Nginx ≥ 1.3.7(推荐 ≥ 1.19.0)
- OpenSSL ≥ 1.0.1(建议升级至 3.x,兼顾性能与安全)
- 证书必须包含
authorityInfoAccess扩展(主流 CA 如 Let’s Encrypt、Sectigo、DigiCert 默认支持) - 系统时间准确(误差需
- 服务端能访问 CA 的 OCSP 地址(如
http://ocsp.int-x3.letsencrypt.org/),且防火墙未拦截 - 配置中提供完整可信证书链(
ssl_trusted_certificate必须指向含根+中间证书的 PEM)
? Nginx 核心配置项
server {
listen 443 ssl http2;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
# 启用 OCSP Stapling
ssl_stapling on;
ssl_stapling_verify on;
# 指向完整可信链(不含私钥,含根+中间证书)
ssl_trusted_certificate /etc/letsencrypt/live/example.com/chain.pem;
# 可选:指定本地缓存文件路径(提升首次加载稳定性)
ssl_stapling_file /var/lib/nginx/ocsp/example.com.ocsp;
# DNS 解析器(必须显式配置,否则 stapling 无法发起 OCSP 查询)
resolver 8.8.8.8 1.1.1.1 valid=300s;
resolver_timeout 5s;
# 其他推荐加固项
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:CHACHA20-POLY1305;
ssl_prefer_server_ciphers off;
}
⚠️ 注意:
resolver不可用127.0.0.1或localhost(除非你本地运行了可靠 DNS 服务),建议用公共 DNS(如8.8.8.8或1.1.1.1)。
? 手动触发与自动维护
-
首次启用后,手动获取一次 OCSP 响应(避免重启后首请求失败):
openssl ocsp -issuer /etc/letsencrypt/live/example.com/chain.pem \ -cert /etc/letsencrypt/live/example.com/fullchain.pem \ -url http://ocsp.int-x3.letsencrypt.org/ \ -text -out /var/lib/nginx/ocsp/example.com.ocsp -
加到定时任务(每日更新):
0 2 * * * /usr/bin/openssl ocsp -issuer /etc/letsencrypt/live/example.com/chain.pem \ -cert /etc/letsencrypt/live/example.com/fullchain.pem \ -url http://ocsp.int-x3.letsencrypt.org/ \ -text -out /var/lib/nginx/ocsp/example.com.ocsp 2>/dev/null -
确保目录可写:
mkdir -p /var/lib/nginx/ocsp chown -R www-data:www-data /var/lib/nginx/ocsp
✅ 验证是否成功
用终端执行(替换为你的域名):
openssl s_client -connect example.com:443 -servername example.com -status -tlsextdebug &1 | grep -i "OCSP response"
看到类似输出即成功:
OCSP Response Status: successful (0x0) ... Response Type: Basic OCSP Response
浏览器开发者工具的「Security」标签页中,也可查看连接详情里是否显示 “OCSP stapling: yes”。
不复杂但容易忽略。











