Skip to content

OCSP Stapling Problem #7377

@Knight1

Description

@Knight1

Issue Details

Hi!

I use Google PKI with 2 Day Certificates. But Caddy refuses to use them for OCSP stapling because caddy argues that the Certificates are invalid because the OCSP response is longer valid then the Certificate itself.

2025/12/02 21:36:52.787 WARN    tls     stapling OCSP   {"error": "invalid: OCSP response for [] valid after certificate expiration (-119h3m9s)", "identifiers": [""]}

Is this intentional because CAB / Chrome / Firefox does not allow this or is Caddy too restrict here?

Assistance Disclosure

AI not used

If AI was used, describe the extent to which it was used.

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions