# Letsencrypt OCSP response times measured?

**URL:** https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813
**Category:** Issuance Tech
**Created:** [November 14, 2015, 3:41pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813 "2015-11-14T15:41:20Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [November 14, 2015, 3:41pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/1 "2015-11-14T15:41:20Z")

</div>

@josh @jsha @jcjones @kelunik @schoen @pde

From article at [https://blog.digicert.com/ocsp-times-and-what-they-mean-for-you/](https://blog.digicert.com/ocsp-times-and-what-they-mean-for-you/) and [https://blog.cloudflare.com/ocsp-stapling-how-cloudflare-just-made-ssl-30/](https://blog.cloudflare.com/ocsp-stapling-how-cloudflare-just-made-ssl-30/) OCSP response times matter, so curious if Letsencrypt folks have or are actively measuring, benchmarking and monitoring their response times in response to increasing loads and demands ?

How does Letsencrypt’s OCSP response times fair against other CAs ? Just curious 🙂

![](https://global.discourse-cdn.com/letsencrypt/original/2X/c/c6688ea7f31272e9fc37cdb68fef240e21dd294f.png)

And some other stats at [http://uptime.netcraft.com/perf/reports/performance/OCSP](http://uptime.netcraft.com/perf/reports/performance/OCSP) different numbers if ordered by total time [http://uptime.netcraft.com/perf/reports/performance/OCSP?orderby=avg\_total](http://uptime.netcraft.com/perf/reports/performance/OCSP?orderby=avg_total)

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/e/e1c37dd393f6024574753fc07e2120e72af53dfa.png)

I believe LE said their are using Akamai for this ? And I believe Globalsign use Akamai too, so close ?

---

<div class="post-metadata">

### Author: ![kelunik](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kelunik/32/359_2.png) [@kelunik](https://community.letsencrypt.org/u/kelunik)
#### Post date: [November 14, 2015, 3:48pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/2 "2015-11-14T15:48:39Z")

</div>

OCSP response times don’t matter that much once OCSP stapling is supported everywhere. Unfortunately, we didn’t have time to implement it for PHP’s streams in time for PHP 7. 😟

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [November 14, 2015, 3:50pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/3 "2015-11-14T15:50:30Z")

</div>

> [@kelunik](#):
>
> OCSP response times don't matter that much once OCSP stapling is supported everywhere

indeed true.. just curious how LE OCSP performance stacks up with other CAs for non-stapled responses. i.e. pretty sure there's quite alot of Apache 2.2.x based https serving servers out there too.

---

<div class="post-metadata">

### Author: ![kelunik](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kelunik/32/359_2.png) [@kelunik](https://community.letsencrypt.org/u/kelunik)
#### Post date: [November 14, 2015, 3:52pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/4 "2015-11-14T15:52:26Z")

</div>

Every server supporting it makes it not only faster for its users but also for all other LE sites, because the LE servers have less load then. Can’t give you any stats. 😉

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [November 14, 2015, 3:55pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/5 "2015-11-14T15:55:19Z")

</div>

indeed it does… guess it’s important in LE client deployment where you alter server configs, that OCSP stapling is configured where available 😃

hmmm if it’s that important, not sure if additional automated checks for working OCSP on LE deployed and auto reconfigured web servers would be a good idea ?

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [November 14, 2015, 4:02pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/6 "2015-11-14T16:02:58Z")

</div>

interesting finding from [http://uptime.netcraft.com/perf/reports/performance/OCSP?orderby=avg\_total](http://uptime.netcraft.com/perf/reports/performance/OCSP?orderby=avg_total) and looking an individual CA’s ocsp stats pages the top 5 commercial CA’s some use Akamai as well but the faster Akamai ones are reporting server signatures as Nginx while slower Akamai ones are reporting Apache 2.2/Debian 🙂

nginx \> apache 😃

---

<div class="post-metadata">

### Author: ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)
#### Post date: [November 20, 2015, 7:16pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/7 "2015-11-20T19:16:31Z")

</div>

> [@eva2000](#):
>
> How does Letsencrypt's OCSP response times fair against other CAs ?

As of today our OCSP responder answers in 41ms average, 47ms median.

We definitely care a lot about performance characteristics of our OCSP responder, and we plan to continue monitoring it in the long run as load increases.

Of course, we also strongly encourage everyone who can enable OCSP Stapling to do so. It's a win on multiple levels!

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [November 21, 2015, 3:00am UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/8 "2015-11-21T03:00:32Z")

</div>

sweet thanks @jsha for sharing that info 41-47ms is good 🙂

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [December 8, 2015, 12:41am UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/9 "2015-12-08T00:41:35Z")

</div>

@jsha @jcjones how’s response times now with public beta operational ? 🙂

---

<div class="post-metadata">

### Author: ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)
#### Post date: [December 8, 2015, 2:24am UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/10 "2015-12-08T02:24:19Z")

</div>

30ms median, 38ms mean.

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [December 8, 2015, 3:05am UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/11 "2015-12-08T03:05:31Z")

</div>

looking good… @jsha 🙂

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [June 14, 2016, 11:57pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/12 "2016-06-14T23:57:32Z")

</div>

@jsha @schoen would deploying cloudflare’s dynamic tls record size patch on letsencrypt’s ocsp servers which are nginx based be of any benefit in terms of ocsp response times [https://blog.cloudflare.com/optimizing-tls-over-tcp-to-reduce-latency/](https://blog.cloudflare.com/optimizing-tls-over-tcp-to-reduce-latency/) ? Was beneficial for my nginx patched servers - benchmarks [https://community.centminmod.com/posts/32120/](https://community.centminmod.com/posts/32120/) 🙂

actual patch [https://github.com/cloudflare/sslconfig/blob/master/patches/nginx\_\_dynamic\_tls\_records.patch](https://github.com/cloudflare/sslconfig/blob/master/patches/nginx__dynamic_tls_records.patch)

---

<div class="post-metadata">

### Author: ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)
#### Post date: [June 15, 2016, 12:48am UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/13 "2016-06-15T00:48:17Z")

</div>

We use Nginx in our DC, but that is in turn fronted by Akamai, which we are not at liberty to patch. 🙂

---

<div class="post-metadata">

### Author: ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)
#### Post date: [June 14, 2016, 11:43pm UTC](https://community.letsencrypt.org/t/letsencrypt-ocsp-response-times-measured/3813/14 "2016-06-14T23:43:20Z")

</div>

@jsha update with letsencrypt included [http://uptime.netcraft.com/perf/graph?site=ocsp.int-x3.letsencrypt.org&tn=&range=86400&sd=0&collector=all&sample=2#performanceReport](http://uptime.netcraft.com/perf/graph?site=ocsp.int-x3.letsencrypt.org&tn=&range=86400&sd=0&collector=all&sample=2#performanceReport)

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/6/6e2858b734a65daeb8d0b561e6fbf5dd5e55c3ed.png) 

by avg response time

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/9/90c7d752e7631e5d852a40a0e8e1c616ceb0fc4a.png)
