SSL证书Chrome正常但Firefox报SEC_ERROR_REVOKED_CERTIFICATE问题求助
Hey there, let’s break down this SSL certificate issue you’re facing with Firefox— I’ve tackled similar problems before, so let’s dive in.
The SEC_ERROR_REVOKED_CERTIFICATE error in Firefox means the browser has determined your SSL certificate has been revoked. Here are the most likely causes:
- Your certificate was actually revoked by the issuing CA: This could happen if your private key was compromised, you changed your domain details without updating the certificate, or you requested a revocation manually.
- Firefox’s certificate revocation check (via OCSP/CRL) conflicts with Chrome’s: The two browsers use different validation engines and caching strategies, so one might pick up revocation status the other doesn’t.
- Misconfigured OCSP Stapling on your server: If your server isn’t properly serving OCSP responses (or serves invalid ones), Firefox will reject the certificate, while Chrome might fall back to its own checks.
Let’s go through actionable fixes from most critical to least:
1. Verify if your certificate is truly revoked
First, confirm the revocation status outside of browsers to rule out browser-specific issues. Use this OpenSSL command (replace placeholders with your certificate details):
openssl ocsp -issuer /path/to/ca-cert.pem -cert /path/to/your-cert.pem -url https://your-ca-ocsp-server.com
You can also look up your certificate’s serial number on your CA’s official revocation check page.
If the certificate IS revoked:
- Contact your SSL certificate provider immediately to request a new, unrevoked certificate.
- If revocation was due to a private key leak, generate a new private key for your server before installing the new certificate (never reuse a compromised key).
- Replace the old certificate and key on your web server, then restart the server to apply changes.
If the certificate is NOT revoked:
- Clear Firefox’s certificate cache:
- Open Firefox → Go to
Settings(three dots menu → Settings) - Scroll to
Privacy & Security→ Find theCertificatessection - Click
View Certificates→ Locate your site’s certificate underYour CertificatesorServers - Select it and click
Delete→ Restart Firefox and test again.
- Open Firefox → Go to
- Fix OCSP Stapling on your server:
- For Nginx: Ensure these directives are in your SSL server block:
Restart Nginx after making changes.ssl_stapling on; ssl_stapling_verify on; ssl_trusted_certificate /path/to/ca-chain.pem; - For Apache: Enable
mod_ssland add these lines to your virtual host:SSLUseStapling on SSLStaplingCache "shmcb:/var/run/ocsp(128000)"
- For Nginx: Ensure these directives are in your SSL server block:
- Check Firefox’s OCSP settings:
- Type
about:configin Firefox’s address bar → Accept the warning - Search for
security.OCSP.enabled - Ensure the value is set to
1(default, enables OCSP checks) — if it’s0, change it to1and restart Firefox.
- Type
The two browsers use distinct systems for certificate validation, which leads to these discrepancies:
- Different validation engines: Firefox uses its own NSS (Network Security Services) library, while Chrome relies on the system’s certificate store plus Google’s proprietary security services. Firefox tends to be stricter with revocation checks, especially if OCSP Stapling is misconfigured.
- Caching differences: Chrome caches revocation status longer or uses Google’s global cache for certificate data, so it might not pick up a recent revocation (or false positive) as quickly as Firefox.
- Fallback behavior: If Chrome can’t get a valid OCSP response, it might temporarily allow the connection (depending on settings), while Firefox will block it immediately if it detects any revocation issue.
内容的提问来源于stack exchange,提问作者user9853119

