Intermittent site problems

It looks like only firefox is affected and maybe it is the problem with the firefox implementation.

well it worked yesterday and I don't think my firefox version changed


You can blame it on either side. My understanding is that if the OCSP servers gives a "try again later response", Apache stupidly staples that to its replies so that the browser gets it.

OCSP stapling is intended as a form of privacy enhancement. The idea is that if a browser sees a key on an SSL connection, it needs to check if it was revoked. If the browser just connects to the OCSP provider, that could clue anyone passively intercepting the traffic into knowing what CA signed the key, which could compromise privacy.

Firefox assumes the response was only stapled if it was important that the browser not make its own connection to the CA's OCSP server. So when it sees a stapled "try again later" response, it reports the error. This behavior can be disabled from about:config by disabling stapling entirely in the browser which you can do by changing security.ssl.enable_ocsp_stapling to false.

