[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: UCC or Wildcard question
On Aug 10, 2009, at 1:50 PM, Patrick Landry wrote:
We use a wildcard cert from ipsCA (http://certs.ipsca.com/). Their
offer
for 2 year .edu certs for free is good even for wildcard certs.
We do too (though not on the zimbra box at the moment). One caveat
about this registrar that was recently brought to my attention. As it
says on https://spaces.umbc.edu/display/CIG/IPSCA+Certificates, "The
reason we don't use IPSCA for everything is because their OCSP
provider is not compliant with every OCSP client. This causes problems
with certain broken OCSP implementations, such as whatever Firefox is
using. The real fix is to turn off OCSP in firefox, but getting all of
our users to do that would be onerous."
The way this manifests for most people is a short delay before Firefox
SSL connects on machines that don't use a separate OCSP daemon.
-- dNb