# Identrust OCSP producing errors

**URL:** <https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677>\
**Category:** Issuance Tech\
**Created:** [April 25, 2020, 7:53am UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677 "2020-04-25T07:53:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hannob](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/hannob/32/22157_2.png) [@hannob](https://community.letsencrypt.org/u/hannob)\
**Post date:** [April 25, 2020, 7:53am UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/1 "2020-04-25T07:53:43Z")

</div>

It looks to me the OCSP server of Identrust is down.

Usually few clients do OCSP checks of the intermediate cert, thus this probably doesn’t show up very often. I noticed because I have some monitoring set up using gnutls-cli with ocsp checks to verify if certificates are okay.

You can check e.g. with:  
gnutls-cli --ocsp [letsencrypt.org:443](http://letsencrypt.org:443)

This is what I get:  
Connecting to OCSP server: [isrg.trustid.ocsp.identrust.com](http://isrg.trustid.ocsp.identrust.com)…  
Resolving ‘[isrg.trustid.ocsp.identrust.com:80](http://isrg.trustid.ocsp.identrust.com:80)’…  
Connecting to ‘2a02:26f0:3100::1735:2a09:80’…  
importing response: ASN1 parser: Error in TAG.

(There’s a curious behavior of gnutls that it does not check the ocsp of the intermediate if the server runs ocsp stapling, so this only reproduces on servers without stapling.)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 25, 2020, 8:07am UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/2 "2020-04-25T08:07:47Z")

</div>

It sure seems that way:

```
$ openssl ocsp -no_nonce -url "http://isrg.trustid.ocsp.identrust.com" \
-issuer dst.pem -cert chain.pem -text
OCSP Request Data:
    Version: 1 (0x0)
    Requestor List:
        Certificate ID:
          Hash Algorithm: sha1
          Issuer Name Hash: 6FF4684D4312D24862819CC02B3D472C1D8A2FA6
          Issuer Key Hash: C4A7B1A47B2C71FADBE14B9075FFC41560858910
          Serial Number: 0A0141420000015385736A0B85ECA708
Error querying OCSP responder
140671078831424:error:27076072:OCSP routines:parse_http_line1:server response error:../crypto/ocsp/ocsp_ht.c:260:Code=503,Reason=Service Unavailable

```

> Code=503,Reason=Service Unavailable

At least, in 4-7 months from now, we'll all be on the ISRG root and there will only be one OCSP server to worry about 🙂 .

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [April 25, 2020, 8:29am UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/3 "2020-04-25T08:29:53Z")

</div>

> [@\_az](#):
>
> (…) in 4-7 months from now (…)

That soon?&nbsp;&nbsp;

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 25, 2020, 8:31am UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/4 "2020-04-25T08:31:36Z")

</div>

It was gonna [happen last year](https://letsencrypt.org/2019/04/15/transitioning-to-isrg-root.html) but got delayed because of (I think) Android.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [April 25, 2020, 8:37am UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/5 "2020-04-25T08:37:56Z")

</div>

@_az Thanks.

* * *

Perhaps [@lestaff](https://community.letsencrypt.org/groups/lestaff) needs to know about this, so they can contact IdenTrust.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [April 25, 2020, 4:41pm UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/6 "2020-04-25T16:41:55Z")

</div>

Thanks for the report @hannob, and thanks for the ping @Osiris. Our team is aware of the issue and has been working with IdenTrust to help resolve it.

---

<div class="post-metadata">

**Author:** ![hannob](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/hannob/32/22157_2.png) [@hannob](https://community.letsencrypt.org/u/hannob)\
**Post date:** [April 30, 2020, 12:22pm UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/7 "2020-04-30T12:22:06Z")

</div>

It seems this works again now, but may I propose that Let’s Encrypt adds some monitoring of the Identrust OCSP?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 30, 2020, 12:22pm UTC](https://community.letsencrypt.org/t/identrust-ocsp-producing-errors/120677/8 "2020-05-30T12:22:09Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
