Home

How to fix invalid OCSP Signing Certificate in OCSP response. Error Code: sec_error_ocsp_invalid_signing_cert.

Alton Alexander
By Alton AlexanderUpdated on June 4th, 2022

An invalid ocsp signing certificate error code occurs when the ocsp response is signed with an invalid certificate. This can happen for a variety of reasons, including if the certificate has expired, been revoked, or is otherwise not valid. This error code can also occur if the ocsp response is not signed at all.

1. Update the signing certificate

  1. Navigate to the "Signing Certificates" tab in the OCS Portal.
  2. Select the certificate that needs to be updated and click on "Update Signing Certificate".
  3. On the "Update Signing Certificate" window, select "Update from Certificate Authorities" and select the certificate authority (CA) that issued the certificate that needs to be updated.
  4. On the "Update from Certificate Authorities" window, select "Properties" and then "Serial Number" to view the certificate's serial number.
  5. In the "Serial Number" field, input the new serial number that corresponds to the certificate that needs to be updated.
  6. Click on "Update Signing Certificate" to update the certificate.

2. Revoke the signing certificate

  1. Access the Certificate Authorities page in the PKI Management Console.
  2. Select the certificate authority (CA) that issued the invalid ocsp signing certificate.
  3. Click the Revoke Signing Certificate button.
  4. On the Revoke Signing Certificate page, click the Revoke button.
  5. On the Revoke Signing Certificate page, provide the following information:
  • CA name
  • Signing certificate name
  • URL of the revocation certificate
  • Description of the revocation
  1. Click the Revoke button.

3. Get a new signing certificate

  1. Request a new signing certificate from your certificate authority.
  2. Upload the new signing certificate to your server.
  3. Update the ocsp response on your website to use the new signing certificate.