Implement OCSP Stapling

For nginx/Let’s Encrypt. Speeds up SSL, improves privacy.
......@@ -23,6 +23,12 @@ server {
ssl_prefer_server_ciphers on;
add_header Strict-Transport-Security "max-age=31536000; includeSubdomains";
# Implement OCSP Stapling
# (Speed up SSL and improve privacy by not requiring calls to certificate authority)
ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /etc/letsencrypt/certs/;
# --- End of SSL-specific setup ---
# Serve the site from the git repository.
