You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A server running hitch 1.7.0 is logging the following every 5 minutes:
Jan 16 10:39:43 hostname hitch[24465]: 20210116T103943.120223 [24494] {core} Error: OCSP response for cert /etc/letsencrypt/live/nnnn.no/hitch-bundle.pem has status unauthorized
What does it mean, and how do I fix this?
It appears for test domains that are possibly not being renewed. These are Let's Encrypt certificates. Is this hitch is trying to fetch an OCSP token/assurance for a certificate that has expired?
I have 300-400 of these in the log per day.
Can I somehow turn off OCSP stapling for some domains? I don't want to remove the test domains, even if they are expired currently. It is fine that they are, I just need to test varnish config changes by modifying my own /etc/hosts to point there temporarily. Going outside the TLS channel would void the test setup.
Any insight appreciated.
The text was updated successfully, but these errors were encountered:
A server running hitch 1.7.0 is logging the following every 5 minutes:
What does it mean, and how do I fix this?
It appears for test domains that are possibly not being renewed. These are Let's Encrypt certificates. Is this hitch is trying to fetch an OCSP token/assurance for a certificate that has expired?
I have 300-400 of these in the log per day.
Can I somehow turn off OCSP stapling for some domains? I don't want to remove the test domains, even if they are expired currently. It is fine that they are, I just need to test varnish config changes by modifying my own /etc/hosts to point there temporarily. Going outside the TLS channel would void the test setup.
Any insight appreciated.
The text was updated successfully, but these errors were encountered: