Skip to main content

Comodo OCSP Outage

Comments

5 comments

  • cPanelMichael
    Hello, Did you notice anything unusual in /var/log/messages or /var/log/dmesg during the downtime? It seems like a network issue based on the information you provided. You may want to follow-up with your provider and let them know you reviewed the logs and don't see anything that suggests a server-level issue. Thank you.
    0
  • Ruiz
    Thanks cPanelMichael! The same problem happened yesterday for a few minutes, and i think i found the source. It wasn't the network, but our SSL certificate issued by Comodo (probably). Some websites without ssl were working correctly, so I used this service to analise out SSL certificate: SSL Server Test (Powered by Qualys SSL Labs) Here is the result: ibb.co/j8T8Pv My main concern was the line that says: OCSP ERROR: Exception: connect timed out [
    0
  • rpvw
    Couple of things to take into account: The OCSP requirement is more likely to be a setting in the configuration of the browser you are using (eg in Firefox you can see it in Preferences > advanced > certificates, or use the string ocsp in about:config There is a possibility that the OCSP server was down, overloaded or unreachable at the time you experienced the issues. It has also been suggested in various forums that an UN-synchronized time/date on the calling device (the computer you are calling the site FROM) may sometimes provoke this response. Hope this helps
    0
  • cPanelMichael
    My main concern was the line that says: OCSP ERROR: Exception: connect timed out [Comodo Certificate Authority Status These types of outages can result in websites failing to open when the browser (e.g. Firefox) is unable to directly connect to the OCSP server. Note that we did implement the following case back in June: EA-6302: Add SSLStaplingResponderTimeout to help when OCSP is down This helps to ensure the connection fails sooner when the OCSP server is down, whereas before the connection would hang. I recommend using the "Subscribe" button in the Comodo status URL referenced above so you are alerted when there's a Comodo outage in order to better identify when this issue might appear. Thank you.
    0
  • Ruiz
    Thank you Michael! That was spot on
    0

Please sign in to leave a comment.