[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: UCC or Wildcard question




On Aug 10, 2009, at 1:50 PM, Patrick Landry wrote:

We use a wildcard cert from ipsCA (http://certs.ipsca.com/). Their offer
for 2 year .edu certs for free is good even for wildcard certs.

We do too (though not on the zimbra box at the moment). One caveat about this registrar that was recently brought to my attention. As it says on https://spaces.umbc.edu/display/CIG/IPSCA+Certificates, "The reason we don't use IPSCA for everything is because their OCSP provider is not compliant with every OCSP client. This causes problems with certain broken OCSP implementations, such as whatever Firefox is using. The real fix is to turn off OCSP in firefox, but getting all of our users to do that would be onerous."

The way this manifests for most people is a short delay before Firefox SSL connects on machines that don't use a separate OCSP daemon.

      -- dNb