OCSP Errors

Status
Not open for further replies.

itw

Dabbler
Joined
Aug 31, 2011
Messages
48
I've noticed GoDaddy seems to have trouble keeping their OCSP data current. Not just on this site but sporadically around the internet.
 

Attachments

  • Screen Shot 2015-11-23 at 8.27.42 AM.png
    Screen Shot 2015-11-23 at 8.27.42 AM.png
    56.3 KB · Views: 272
Joined
Dec 2, 2015
Messages
21
I have had that problem with my own web servers when the certificate is new.

When renewing a cert, I always but new cert with new private key several days before it goes live so it isn't an issue, but with brand new sites or if there is reason to believe a private key may have been compromised, with the new cert that sometimes happens during the first 24 to 48 hours of use.

I don't think it is godaddy, I think it is the certificate authority. If the server can't get fresh OCSP to send to the client because the CA isn't responding, then the server may send outdated OCSP info to the client (if using OCSP stapling) which may result in that error.

I don't know that's the case here, but it may be.
 
Status
Not open for further replies.
Top