Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

How can you set Firefox to, or tell if FF is always checking for certificate revocation?

  • 2 cavab
  • 4 have this problem
  • 1 view
  • Last reply by cor-el

more options

I am anticipating a number of certificate revocations related to the heartbleed voulnerability, and would like to be able to check whether Firefox is checking for revocation, and tell it to if not.

I am anticipating a number of certificate revocations related to the heartbleed voulnerability, and would like to be able to check whether Firefox is checking for revocation, and tell it to if not.

Chosen solution

By default, Firefox will check but, if the OCSP server is not available, will accept the certificate for the time being.

Edit menu > Preferences > Advanced > Certificates mini-tab > "Validation" button

Read this answer in context 👍 6

All Replies (2)

more options

Seçilmiş Həll

By default, Firefox will check but, if the OCSP server is not available, will accept the certificate for the time being.

Edit menu > Preferences > Advanced > Certificates mini-tab > "Validation" button

more options

For this heartbleed issue you can also temporarily disable OCSP Stapling by setting the security.ssl.enable_ocsp_stapling pref to false on the about:config page.

Make sure to check in a few days if you still need this workaround and if necessary reset the pref to true.