Bug 1717711 Comment 5 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

Thanks John and Dana. Would you please also help me with the following?

When I tried verifying EV-enablement in Firefox Nightly for these 4 root certificates, I found that the test URLs for the 2015 root certs are getting EV treatment now, but the test URLs for the 2021 root certs are not getting EV treatment.

So I ran https://tls-observatory.services.mozilla.com/static/ev-checker.html for the test URLs for the 2021 root certs, and get the following result:
ev-checker exited successfully: exit status 1, Stderr: Error making OCSP request to '

I understand that for EV, when Firefox is unable to complete the OCSP check it falls back to non-EV. But I'm trying to figure out why the OCSP check is failing. The message returned by the ev-checker isn't complete, so not quite sure what's going wrong.

To try to figure out more about the OCSP problem, I looked at 
https://certificate.revocationcheck.com/https://tls-ecc-valid-ev.root2021.harica.gr
https://certificate.revocationcheck.com/https://tls-ecc-valid-ev.root2021.harica.gr
This OCSP response was cached at Oct 11, 2021 2:15:13 PM
OCSP appears to work fine.

Are you able to see where the OCSP check is failing?
Thanks John and Dana. Would you please also help me with the following?

When I tried verifying EV-enablement in Firefox Nightly for these 4 root certificates, I found that the test URLs for the 2015 root certs are getting EV treatment now, but the test URLs for the 2021 root certs are not getting EV treatment.

So I ran https://tls-observatory.services.mozilla.com/static/ev-checker.html for the test URLs for the 2021 root certs, and get the following result:
ev-checker exited successfully: exit status 1, Stderr: Error making OCSP request to '

I understand that for EV, when Firefox is unable to complete the OCSP check it falls back to non-EV. But I'm trying to figure out why the OCSP check is failing. The message returned by the ev-checker isn't complete, so not quite sure what's going wrong.

To try to figure out more about the OCSP problem, I looked at 
https://certificate.revocationcheck.com/https://tls-ecc-valid-ev.root2021.harica.gr
https://certificate.revocationcheck.com/tls-rsa-valid-ev.root2021.harica.gr
This OCSP response was cached at Oct 11, 2021 2:15:13 PM
OCSP appears to work fine.

Are you able to see where the OCSP check is failing?
Thanks John and Dana. Would you please also help me with the following?

When I tried verifying EV-enablement in Firefox Nightly for these 4 root certificates, I found that the test URLs for the 2015 root certs are getting EV treatment now, but the test URLs for the 2021 root certs are not getting EV treatment.

So I ran https://tls-observatory.services.mozilla.com/static/ev-checker.html for the test URLs for the 2021 root certs, and get the following result:
ev-checker exited successfully: exit status 1, Stderr: Error making OCSP request to '

I understand that for EV, when Firefox is unable to complete the OCSP check it falls back to non-EV. But I'm trying to figure out why the OCSP check is failing. The message returned by the ev-checker isn't complete, so not quite sure what's going wrong.

To try to figure out more about the OCSP problem, I looked at 
https://certificate.revocationcheck.com/tls-ecc-valid-ev.root2021.harica.gr
https://certificate.revocationcheck.com/tls-rsa-valid-ev.root2021.harica.gr
This OCSP response was cached at Oct 11, 2021 2:15:13 PM
OCSP appears to work fine.

Are you able to see where the OCSP check is failing?

Back to Bug 1717711 Comment 5