国内 Let’s Encrypt 的 OSCP 域名 ocsp.int-x3.letsencrypt.org 的解析被污染了?
今天早上续签 Let’s Encrypt 的证书,发现报
[WARNING] Stapling OCSP: no OCSP stapling for [*.com]: making OCSP request: Post http://ocsp.int-x3.letsencrypt.org: dial tcp 88.191.249.182:80: i/o timeout
nslookup 后发现
nslookup ocsp.int-x3.letsencrypt.org Server: 127.0.0.53 Address: 127.0.0.53#53 Non-authoritative answer: ocsp.int-x3.letsencrypt.org canonical name = ocsp.int-x3.letsencrypt.org.edgesuite.net. ocsp.int-x3.letsencrypt.org.edgesuite.net canonical name = a771.dscq.akamai.net. Name: a771.dscq.akamai.net Address: 31.13.65.1 Name: a771.dscq.akamai.net Address: 2001::4b7e:8783
用 ipip 的 DNS 解析得到同样结果