You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SSL证书Chrome正常但Firefox报SEC_ERROR_REVOKED_CERTIFICATE问题求助

Hey there, let’s break down this SSL certificate issue you’re facing with Firefox— I’ve tackled similar problems before, so let’s dive in.

问题原因分析

The SEC_ERROR_REVOKED_CERTIFICATE error in Firefox means the browser has determined your SSL certificate has been revoked. Here are the most likely causes:

  • Your certificate was actually revoked by the issuing CA: This could happen if your private key was compromised, you changed your domain details without updating the certificate, or you requested a revocation manually.
  • Firefox’s certificate revocation check (via OCSP/CRL) conflicts with Chrome’s: The two browsers use different validation engines and caching strategies, so one might pick up revocation status the other doesn’t.
  • Misconfigured OCSP Stapling on your server: If your server isn’t properly serving OCSP responses (or serves invalid ones), Firefox will reject the certificate, while Chrome might fall back to its own checks.
修复步骤

Let’s go through actionable fixes from most critical to least:

1. Verify if your certificate is truly revoked

First, confirm the revocation status outside of browsers to rule out browser-specific issues. Use this OpenSSL command (replace placeholders with your certificate details):

openssl ocsp -issuer /path/to/ca-cert.pem -cert /path/to/your-cert.pem -url https://your-ca-ocsp-server.com

You can also look up your certificate’s serial number on your CA’s official revocation check page.

If the certificate IS revoked:

  • Contact your SSL certificate provider immediately to request a new, unrevoked certificate.
  • If revocation was due to a private key leak, generate a new private key for your server before installing the new certificate (never reuse a compromised key).
  • Replace the old certificate and key on your web server, then restart the server to apply changes.

If the certificate is NOT revoked:

  • Clear Firefox’s certificate cache:
    1. Open Firefox → Go to Settings (three dots menu → Settings)
    2. Scroll to Privacy & Security → Find the Certificates section
    3. Click View Certificates → Locate your site’s certificate under Your Certificates or Servers
    4. Select it and click Delete → Restart Firefox and test again.
  • Fix OCSP Stapling on your server:
    • For Nginx: Ensure these directives are in your SSL server block:
      ssl_stapling on;
      ssl_stapling_verify on;
      ssl_trusted_certificate /path/to/ca-chain.pem;
      
      Restart Nginx after making changes.
    • For Apache: Enable mod_ssl and add these lines to your virtual host:
      SSLUseStapling on
      SSLStaplingCache "shmcb:/var/run/ocsp(128000)"
      
    OCSP Stapling lets your server send revocation status directly to browsers, avoiding inconsistent checks.
  • Check Firefox’s OCSP settings:
    1. Type about:config in Firefox’s address bar → Accept the warning
    2. Search for security.OCSP.enabled
    3. Ensure the value is set to 1 (default, enables OCSP checks) — if it’s 0, change it to 1 and restart Firefox.
Why do Chrome and Firefox show different results?

The two browsers use distinct systems for certificate validation, which leads to these discrepancies:

  • Different validation engines: Firefox uses its own NSS (Network Security Services) library, while Chrome relies on the system’s certificate store plus Google’s proprietary security services. Firefox tends to be stricter with revocation checks, especially if OCSP Stapling is misconfigured.
  • Caching differences: Chrome caches revocation status longer or uses Google’s global cache for certificate data, so it might not pick up a recent revocation (or false positive) as quickly as Firefox.
  • Fallback behavior: If Chrome can’t get a valid OCSP response, it might temporarily allow the connection (depending on settings), while Firefox will block it immediately if it detects any revocation issue.

内容的提问来源于stack exchange,提问作者user9853119

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:05:32