[openssl-users] OCSP: ocsp.omniroot.com/baltimore/... - what is it exactly?
tch at virtall.com
Thu Apr 30 17:44:30 UTC 2015
This might not be very relevant to OpenSSL, but I'm not sure if there is
any better list for this question...
My webserver is getting flooded with queries like:
ocsp.omniroot.com 184.108.40.206 - - [30/Apr/2015:19:24:30 +0200] "GET
HTTP/1.1" 301 184 "-" "ocspd/1.0.3"
ocsp.omniroot.com 220.127.116.11 - - [30/Apr/2015:19:24:33 +0200] "GET
HTTP/1.1" 301 184 "-" "Microsoft-CryptoAPI/6.1"
If I understand it right, because the query was sent to my server
(China's Great Firewall DNS poisoning at works), and not to "original"
ocsp.omniroot.com, somebody's browser or device was not able to verify
if the certificate is still valid or not - am I correct here?
Is it possible to say what "Common name / fqdn / certificate" is queried
in such requests?
More information about the openssl-users