我的 Apache 错误日志显示了很多“stapling_renew_response: responder”错误。本来想添加浏览器截图,但我是新手,因此没有权限。以下是从浏览器显示的:
"Secure Connection Failed
An error occurred during a connection to www.mysite.co.uk. The OCSP server suggests trying again later. (Error code: sec_error_ocsp_try_server_later)
这是一个间歇性故障,但当我重新启动 Apache 时,问题暂时消失。看起来问题发生在 Apache 尝试解析 OCSP 响应器的地址时。
[Mon Jun 30 16:00:52.666880 2014] [ssl:error] [pid 20449] (EAI 3)Temporary failure in name resolution: [client 12.34.56.78.9:54254] AH01972: could not resolve address of OCSP responder EVSSL-ocsp.geotrust.com
[Mon Jun 30 16:00:52.666954 2014] [ssl:error] [pid 20449] AH01941: stapling_renew_response: responder error
[Wed Jul 02 21:16:00.660224 2014] [ssl:error] [pid 13700] (EAI 3)Temporary failure in name resolution: [client 12.34.56.78.9:7467] AH01972: could not resolve address of OCSP responder rapidssl-ocsp.geotrust.com
[Wed Jul 02 21:16:00.660284 2014] [ssl:error] [pid 13700] AH01941: stapling_renew_response: responder error
[Mon Jul 07 13:00:48.082422 2014] [ssl:error] [pid 23502] (EAI 3)Temporary failure in name resolution: [client 12.34.56.78.9:62983] AH01972: could not resolve address of OCSP responder rapidssl-ocsp.geotrust.com
[Mon Jul 07 13:00:48.082505 2014] [ssl:error] [pid 23502] AH01941: stapling_renew_response: responder error
从我的 http.conf 文件:
SSLUseStapling on
SSLStaplingCache shmcb:/usr/local/apache/logs/stapling_cache_shmcb(256000)
SSLSessionCache shmcb:/usr/local/apache/logs/ssl_gcache_data_shmcb(1024000)
SSLSessionCacheTimeout 300
Mutex file:/usr/local/apache/logs ssl-cache
SSLRandomSeed startup builtin
SSLRandomSeed connect builtin
我使用以下命令检查了 OCSP Stapling:echo QUIT | openssl s_client -connect www.mysite.com:443 -status 2> /dev/null | grep -A 17 'OCSP response:' | grep -B 17 'Next Update'
并收到此回复,表明它正在运行:
OCSP Response Data:
OCSP Response Status: successful (0x0)
Response Type: Basic OCSP Response
Version: 1 (0x0)
Responder Id: CN = RapidSSL TGV OCSP Responder
Produced At: Aug 8 22:59:14 2014 GMT
Responses:
Certificate ID:
Hash Algorithm: sha1
Issuer Name Hash: 123456789XXXXXXXXXXXXXXXXXXXX
Issuer Key Hash: 123456789XXXXXXXXXXXXXXXXXXXX
Serial Number: ABCD123
Cert Status: good
This Update: Aug 8 22:59:14 2014 GMT
Next Update: Aug 15 22:59:14 2014 GMT
我检查了 httpd.conf 中提到的缓存文件(stapling_cache_shmcb 和 ssl_gcache_data_shmcb),但都不存在。它们应该存在吗?
任何帮助都将非常有帮助。