nginx auth_error ai_generated true

OCSP 装订验证失败(SSL:错误:2707307E:OCSP 例程:OCSP_basic_verify:证书验证错误)

nginx: [emerg] SSL: OCSP stapling verify failed (SSL: error:2707307E:OCSP routines:OCSP_basic_verify:certificate verify error) while verifying certificate

ID: nginx/ssl-ocsp-stapling-verify-failed

其他格式: JSON · Markdown 中文 · English
90%修复率
85%置信度
1证据数
2024-05-10首次发现

版本兼容性

版本状态引入弃用备注
nginx/1.18.0 active
nginx/1.20.0 active
nginx/1.24.0 active
nginx/1.26.0 active

根因分析

OCSP 装订失败,因为证书链不完整或 OCSP 响应程序证书不受 nginx 的 CA 包信任。

English

OCSP stapling fails because the certificate chain is incomplete or the OCSP responder certificate is not trusted by nginx's CA bundle.

generic

官方文档

https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling_verify

解决方案

  1. 确保 ssl_certificate 指定完整的证书链(包括中间 CA):`cat server.crt intermediate.crt > fullchain.crt` 并设置 `ssl_certificate /path/to/fullchain.crt;`
  2. 将 ssl_trusted_certificate 设置为包含 OCSP 响应程序颁发者的 CA 包:`ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;`
  3. 如果使用 Let's Encrypt,请使用 fullchain.pem 文件:`ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;`

无效尝试

常见但无效的做法:

  1. 50% 失败

    Without verification, nginx will staple any OCSP response, including potentially forged ones, weakening TLS security.

  2. 70% 失败

    The responder's certificate must be in the trusted store; changing the URL does not fix trust issues.

  3. 60% 失败

    OCSP responses are signed by the CA, not the server certificate; the CA's certificate must be in the trust chain.