Add server-side OCSP stapling to the BCJSSE provider and the low-level TLS API, answering status_request and status_request_v2 with a certificate_status message for TLSv1.2 and, from the same TlsServer.getCertificateStatus callback, a per-CertificateEntry extension for TLSv1.3, behind jdk.tls.server.enableStatusRequestExtension and a per-SSLContext response cache, dropping the echoes a resumed handshake would otherwise replay, reading the TLSv1.3 form on the client, dropping a response too large for its CertificateEntry to carry rather than failing the handshake over it, and clearing the status_request_v2 and trusted_ca_keys a reused TlsServer would otherwise carry into a following handshake, relates to github #1157.
D
David Hook committed
ec2f3f06ba33787ed600e32ae6eba35040549201
Parent: 2feaf10