nginx auth_error ai_generated true

nginx: [emerg] SSL: OCSP stapling verify failed (SSL: error:2707307E:OCSP routines:OCSP_basic_verify:certificate verify error) while verifying certificate

ID: nginx/ssl-ocsp-stapling-verify-failed

Also available as: JSON · Markdown · 中文
90%Fix Rate
85%Confidence
1Evidence
2024-05-10First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
nginx/1.18.0 active
nginx/1.20.0 active
nginx/1.24.0 active
nginx/1.26.0 active

Root Cause

OCSP stapling fails because the certificate chain is incomplete or the OCSP responder certificate is not trusted by nginx's CA bundle.

generic

中文

OCSP 装订失败,因为证书链不完整或 OCSP 响应程序证书不受 nginx 的 CA 包信任。

Official Documentation

https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling_verify

Workarounds

  1. 90% success Ensure the full certificate chain (including intermediate CA) is specified in ssl_certificate: `cat server.crt intermediate.crt > fullchain.crt` and set `ssl_certificate /path/to/fullchain.crt;`
    Ensure the full certificate chain (including intermediate CA) is specified in ssl_certificate: `cat server.crt intermediate.crt > fullchain.crt` and set `ssl_certificate /path/to/fullchain.crt;`
  2. 85% success Set ssl_trusted_certificate to the CA bundle that includes the OCSP responder's issuer: `ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
    Set ssl_trusted_certificate to the CA bundle that includes the OCSP responder's issuer: `ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
  3. 95% success If using Let's Encrypt, use the fullchain.pem file: `ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`
    If using Let's Encrypt, use the fullchain.pem file: `ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`

中文步骤

  1. 确保 ssl_certificate 指定完整的证书链(包括中间 CA):`cat server.crt intermediate.crt > fullchain.crt` 并设置 `ssl_certificate /path/to/fullchain.crt;`
  2. 将 ssl_trusted_certificate 设置为包含 OCSP 响应程序颁发者的 CA 包:`ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
  3. 如果使用 Let's Encrypt,请使用 fullchain.pem 文件:`ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`

Dead Ends

Common approaches that don't work:

  1. 50% fail

    Without verification, nginx will staple any OCSP response, including potentially forged ones, weakening TLS security.

  2. 70% fail

    The responder's certificate must be in the trusted store; changing the URL does not fix trust issues.

  3. 60% fail

    OCSP responses are signed by the CA, not the server certificate; the CA's certificate must be in the trust chain.