Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Fix "The OCSP Server Has No Status for the Certificate"

This guide explains this SSL error and shows what to check and do when you see it.

SSL and Security2 min read7 steps

What does the error mean?

An SSL certificate is a digital ID that proves your website is real. Browsers and tools sometimes ask the company that issued the certificate if it is still valid. This check uses OCSP, which stands for Online Certificate Status Protocol. The company's OCSP server is like a front desk that answers "is this ID still good?"

The error means the server did not know your certificate yet, or could not give an answer. This often happens soon after a certificate is issued or reissued. The record has not reached the OCSP server yet.

Common causes

  • The certificate is brand new, and the issuer's records are not updated.
  • The certificate was reissued and the old one is still installed.
  • The certificate chain is missing. The chain is the set of linked certificates from yours up to a trusted root.
  • The server clock is wrong.
  • The OCSP stapling setting is wrong. Stapling means your server attaches a fresh answer to the certificate for faster loading.

Steps to fix it

  1. Wait one to two hours if the certificate is new. Try again. Often the error goes away on its own.
  2. Check which certificate is installed. Open your site, click the padlock and view the certificate details. Compare the dates with the one you received.
  3. Run a free online SSL checker on your domain. It will show chain problems and OCSP status.
  4. Make sure you installed the full chain. Install the CA bundle together with your certificate. The CA bundle is the file with the issuer's linked certificates.
  5. Restart the web server after changes. On shared hosting, ask support to do it for you.
  6. If you use OCSP stapling and it fails, turn it off for now. Then turn it back on when the issuer's status is live. On shared hosting, you cannot change this, so ask support.
  7. If the error stays for more than a day, contact the company that sold you the certificate. Ask them to check their OCSP responder.

Warning: Before you replace or reinstall a certificate, save a copy of the current files.

Tip: To see this error from the command line, run openssl s_client -connect yourdomain.com:443 -status and read the OCSP part of the output.

If you need help, open a support ticket with your domain name and the full error.

Quick recap

  • OCSP checks if a certificate is still valid.
  • New or reissued certificates often show this error for a short time.
  • Wait, check the chain and restart the web server.
  • Contact your certificate issuer if it lasts.