nginx
auth_error
ai_generated
true
nginx: [emerg] SSL: OCSP stapling verify failed (SSL: error:2707307E:OCSP routines:OCSP_basic_verify:certificate verify error) while verifying certificate
ID: nginx/ssl-ocsp-stapling-verify-failed
90%Fix Rate
85%Confidence
1Evidence
2024-05-10First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| nginx/1.18.0 | active | — | — | — |
| nginx/1.20.0 | active | — | — | — |
| nginx/1.24.0 | active | — | — | — |
| nginx/1.26.0 | active | — | — | — |
Root Cause
OCSP stapling fails because the certificate chain is incomplete or the OCSP responder certificate is not trusted by nginx's CA bundle.
generic中文
OCSP 装订失败,因为证书链不完整或 OCSP 响应程序证书不受 nginx 的 CA 包信任。
Official Documentation
https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling_verifyWorkarounds
-
90% success Ensure the full certificate chain (including intermediate CA) is specified in ssl_certificate: `cat server.crt intermediate.crt > fullchain.crt` and set `ssl_certificate /path/to/fullchain.crt;`
Ensure the full certificate chain (including intermediate CA) is specified in ssl_certificate: `cat server.crt intermediate.crt > fullchain.crt` and set `ssl_certificate /path/to/fullchain.crt;`
-
85% success Set ssl_trusted_certificate to the CA bundle that includes the OCSP responder's issuer: `ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
Set ssl_trusted_certificate to the CA bundle that includes the OCSP responder's issuer: `ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
-
95% success If using Let's Encrypt, use the fullchain.pem file: `ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`
If using Let's Encrypt, use the fullchain.pem file: `ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`
中文步骤
确保 ssl_certificate 指定完整的证书链(包括中间 CA):`cat server.crt intermediate.crt > fullchain.crt` 并设置 `ssl_certificate /path/to/fullchain.crt;`
将 ssl_trusted_certificate 设置为包含 OCSP 响应程序颁发者的 CA 包:`ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
如果使用 Let's Encrypt,请使用 fullchain.pem 文件:`ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`
Dead Ends
Common approaches that don't work:
-
50% fail
Without verification, nginx will staple any OCSP response, including potentially forged ones, weakening TLS security.
-
70% fail
The responder's certificate must be in the trusted store; changing the URL does not fix trust issues.
-
60% fail
OCSP responses are signed by the CA, not the server certificate; the CA's certificate must be in the trust chain.