Expect-Staple


What is Expect-Staple?

The Expect-Staple header allows you to determine if your site is delivering proper OCSP Staples with certificates. If you're thinking about using Must-Staple certificates then deploying Expect-Staple is an essential step prior to deploying them.


Getting Started

Deploying Expect-Staple is safe, easy and can give you vital information about your site. Right now the only way to deploy Expect-Staple is with a custom entry into the Chromium HSTS preload list. Please contact us if you'd like information on how to request inclusion.


https://github.com/ScottHelme/draft-helme-expect-staple

https://scotthelme.co.uk/designing-a-new-security-header-expect-staple/

https://scotthelme.co.uk/ocsp-expect-staple/

https://scotthelme.co.uk/ocsp-must-staple/