Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. How to disable OCSP stapling?

How to disable OCSP stapling?

Scheduled Pinned Locked Moved Solved Support
reverseproxyletsencryptcertificates
5 Posts 2 Posters 243 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    B Offline
    BetaBreak
    wrote last edited by girish
    #1

    My Cloudron instance keeps crashing and my openid also crashes when trying to login into my apps.

    nginx: [warn] "ssl_stapling" ignored, no OCSP responder URL in the certificate

    Any way to fix that?

    This could be the culprit:

    This issue is particularly prevalent with certificates issued by Let's Encrypt. As of May 7, 2025, Let's Encrypt stopped including OCSP URLs in new certificates. Consequently, any certificate issued after this date will lack the necessary OCSP URL, causing the warning to appear in the server logs. The OCSP responders for Let's Encrypt were scheduled to be turned off entirely on August 6, 2025. Therefore, for certificates issued after May 7, 2025, OCSP stapling is no longer a viable option.

    1 Reply Last reply
    1
    • B BetaBreak referenced this topic
    • B Offline
      B Offline
      BetaBreak
      wrote last edited by
      #2

      Fixed by grep -r "ssl_stapling" /etc/nginx/ and manually commenting out # ssl_stapling on; and # ssl_stapling on; > Reinstalling domain (location) in dashboard also works...

      1 Reply Last reply
      1
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote last edited by
        #3

        @BetaBreak Thanks for the reminder. I read that announcement and summarized it here - https://forum.cloudron.io/topic/4917/ocsp-stapling-for-tls-ssl/7 . We will remove the stapling config in our code entirely , that way the warnings will go away.

        B 1 Reply Last reply
        1
        • girishG girish

          @BetaBreak Thanks for the reminder. I read that announcement and summarized it here - https://forum.cloudron.io/topic/4917/ocsp-stapling-for-tls-ssl/7 . We will remove the stapling config in our code entirely , that way the warnings will go away.

          B Offline
          B Offline
          BetaBreak
          wrote last edited by
          #4

          @girish it seems to be that the ssl certs are not the cause of my openid / dashboard crashes. I can't find anything else in the logs..

          1 Reply Last reply
          0
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote last edited by
            #5

            Fixed here - https://git.cloudron.io/platform/box/-/commit/ac7001b96e176e540ede9bb81e3fcb17ae7f6416

            1 Reply Last reply
            0
            • girishG girish has marked this topic as solved
            • girishG girish referenced this topic
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • Bookmarks
            • Search