Cerca nel supporto

Attenzione alle mail truffa. Mozilla non chiederà mai di chiamare o mandare messaggi a un numero di telefono o di inviare dati personali. Segnalare qualsiasi attività sospetta utilizzando l'opzione “Segnala abuso”.

Learn More

Questa discussione è archiviata. Inserire una nuova richiesta se occorre aiuto.

Having intermittent trouble with Error code: sec_error_ocsp_try_server_later

more options

Seems to be at 1PM EST almost every day where we experience Error code: sec_error_ocsp_try_server_later while trying to connect to https://www.sdtrucksprings.com (our website).

Obviously Chrome doesn't use OCSP so we don't experience it there and we also do not experience it with any other site (that i have tested).

We have contacted Digicert to see if they could help with this and they as well as the host point to asking Firefox which i dont necessarily agree with but figured it couldn't hurt at this point.

Since it only lasts about 10 mins at 1PM i was assuming maybe some sort of caching issue with the default responder but im not sure.

Seems to be at 1PM EST almost every day where we experience Error code: sec_error_ocsp_try_server_later while trying to connect to https://www.sdtrucksprings.com (our website). Obviously Chrome doesn't use OCSP so we don't experience it there and we also do not experience it with any other site (that i have tested). We have contacted Digicert to see if they could help with this and they as well as the host point to asking Firefox which i dont necessarily agree with but figured it couldn't hurt at this point. Since it only lasts about 10 mins at 1PM i was assuming maybe some sort of caching issue with the default responder but im not sure.

Tutte le risposte (1)

more options

If I'm reading it correctly, the cert specifies:

OCSP: URI: http://ocsp.digicert.com

And they don't see any problem on their end around that time?

Can you replicate the problem using other networks, e.g., mobile networks, home networks, Starbucks, or does it only affect your main ISP? Just wondering whether a particular network provider might be dropping those connection requests for some reason, maybe anti-DDOS or some other filter.

Since you use OCSP stapling, might there be a problem on the server with updating the stapled certificate? (I'm over my head here, so apologies if that is a stupid question.)