# Stapling error message from Apache

**URL:** <https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807>\
**Category:** Help\
**Created:** [September 2, 2022, 2:51am UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807 "2022-09-02T02:51:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![epopen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/epopen/32/15496_2.png) [@epopen](https://community.letsencrypt.org/u/epopen)\
**Post date:** [September 2, 2022, 2:51am UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/1 "2022-09-02T02:51:20Z")

</div>

My domain is:  
[epopen.com](http://epopen.com)  
My web server is (include version):  
Apache 2.4.54  
The operating system my web server runs on is (include version):  
FreeBSD 13.1-RELEASE  
I can login to a root shell on my machine (yes or no, or I don't know):  
yes  
The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):  
certbot-1.29.0

Hi All

I got error message short periodic since using Let's Encrypt as follows..

```nohighlight
[Fri Sep 02 09:08:59.563529 2022] [ssl:error] [pid 37:tid 34401891072] AH01936: stapling_check_response: response times invalid
[Fri Sep 02 09:08:59.563686 2022] [ssl:error] [pid 37:tid 34401891072] AH01943: stapling_renew_response: error in retrieved response!
[Fri Sep 02 09:19:41.964499 2022] [ssl:error] [pid 37:tid 34401790720] AH01936: stapling_check_response: response times invalid
[Fri Sep 02 09:19:41.964666 2022] [ssl:error] [pid 37:tid 34401790720] AH01943: stapling_renew_response: error in retrieved response!
[Fri Sep 02 09:35:46.852414 2022] [ssl:error] [pid 37247:tid 34401785344] AH01936: stapling_check_response: response times invalid
[Fri Sep 02 09:35:46.852575 2022] [ssl:error] [pid 37247:tid 34401785344] AH01943: stapling_renew_response: error in retrieved response!
[Fri Sep 02 10:02:15.346355 2022] [ssl:error] [pid 37247:tid 34401767424] AH01936: stapling_check_response: response times invalid
[Fri Sep 02 10:02:15.347322 2022] [ssl:error] [pid 37247:tid 34401767424] AH01943: stapling_renew_response: error in retrieved response!
[Fri Sep 02 10:22:21.561221 2022] [ssl:error] [pid 37247:tid 34401892864] AH01936: stapling_check_response: response times invalid
[Fri Sep 02 10:22:21.561386 2022] [ssl:error] [pid 37247:tid 34401892864] AH01943: stapling_renew_response: error in retrieved response!

```

I googled the issue, found [https://community.letsencrypt.org/t/ocsp-server-sending-expired-responses-stapling-breaks-chrome/23964/3](https://community.letsencrypt.org/t/ocsp-server-sending-expired-responses-stapling-breaks-chrome/23964/3)  
Talk about the issue in the topic, but my result is fine as follow.

```nohighlight
OCSP response: 
OCSP Response Data:
    OCSP Response Status: successful (0x0)
    Response Type: Basic OCSP Response

```

Therefore it is not my issue, root cause unknown and have not solution.

- About firewall, apache can be access outside internet as port 80 & 443
- About apache, configure as follow.  
SSLUseStapling On  
SSLStaplingCache "shmcb:/var/run/ssl\_stapling(128000)"  
SSLStaplingStandardCacheTimeout 3600  
SSLStaplingErrorCacheTimeout 600  
SSLStaplingResponderTimeout 5  
SSLStaplingResponseMaxAge 900  
SSLStaplingReturnResponderErrors on

Please help debug. 🙂  
Thanks a lot.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 2, 2022, 3:52am UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/2 "2022-09-02T03:52:34Z")

</div>

Other volunteers may be willing to help educate you and configure Apache for stapling. It's more than I wish to take on. I will refer you to these topics. These are good background for understanding stapling and Apache.

> [@Apache - robust OCSP stapling config](https://community.letsencrypt.org/t/apache-robust-ocsp-stapling-config/68628/3):
>
> M…

The blog referred to in above thread:  
[https://blog.hboeck.de/archives/886-The-Problem-with-OCSP-Stapling-and-Must-Staple-and-why-Certificate-Revocation-is-still-broken.html](https://blog.hboeck.de/archives/886-The-Problem-with-OCSP-Stapling-and-Must-Staple-and-why-Certificate-Revocation-is-still-broken.html)

> [@SOLVED: Apache's "built-in" OCSP stapling problem](https://community.letsencrypt.org/t/solved-apaches-built-in-ocsp-stapling-problem/149340):
>
> P…

---

<div class="post-metadata">

**Author:** ![epopen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/epopen/32/15496_2.png) [@epopen](https://community.letsencrypt.org/u/epopen)\
**Post date:** [September 6, 2022, 7:17am UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/3 "2022-09-06T07:17:51Z")

</div>

Thanks your a lot.  
I will try your suggestion due try too many times to reach the limit before, therefore other try after 7 days. 😅 😅 😅

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 6, 2022, 5:57pm UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/4 "2022-09-06T17:57:49Z")

</div>

There is a `staging` environment specifically created for `testing`.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [September 6, 2022, 11:11pm UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/5 "2022-09-06T23:11:19Z")

</div>

And here is Let's Encrypt docs on [Staging Environment - Let's Encrypt](https://letsencrypt.org/docs/staging-environment/)

---

<div class="post-metadata">

**Author:** ![epopen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/epopen/32/15496_2.png) [@epopen](https://community.letsencrypt.org/u/epopen)\
**Post date:** [September 19, 2022, 2:24pm UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/6 "2022-09-19T14:24:34Z")

</div>

Thanks all very much.  
I reading and testing.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 19, 2022, 2:25pm UTC](https://community.letsencrypt.org/t/stapling-error-message-from-apache/183807/7 "2022-10-19T14:25:23Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
