# Using Custom Certificate Without OCSP

**URL:** <https://forums.plex.tv/t/using-custom-certificate-without-ocsp/936972>\
**Category:** Plex Media Server\
**Tags:** server-docker\
**Created:** [March 10, 2026, 7:04am UTC](https://forums.plex.tv/t/using-custom-certificate-without-ocsp/936972 "2026-03-10T07:04:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jstnryan](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@jstnryan](https://forums.plex.tv/u/jstnryan)\
**Post date:** [March 10, 2026, 7:04am UTC](https://forums.plex.tv/t/using-custom-certificate-without-ocsp/936972/1 "2026-03-10T07:04:51Z")

</div>

Server Version#: 1.43.0.10492

**TLDR: Is OCSP certificate revocation checking required to use custom certificates? Can it be bypassed, or alternately CRL used?**

I use Traefik with the Let’s Encrypt ACME certificate resolver to issue a wildcard certificate to my Docker containers, including Plex. Traefik’s JSON certificate storage is decoded to output the certificate’s private key and certificate (including intermediate cert) PEM, and then encoded as PKCS12 via:

```auto
openssl pkcs12 -export -out plex-certificate.p12 \
  -certpbe AES-256-CBC -keypbe AES-256-CBC -macalg SHA256 \
  -inkey privatekey.key -in certificate.crt -passout pass:password

```

Note that I’m using the newer encoding options, and openssl ~1.1.1 and ~3.0 have identical output. I can verify the key file is valid by again using openssl to deconstruct it to PEM and verifying with `openssl x509 …`. I have populated the certificate settings via web UI appropriately (filename, password, and domain).

My certificates always result in:

```auto
DEBUG - [CERT/OCSP] no URL available
WARN - [CERT/OCSP] getCertInfo failed; skipping stapling
ERROR - [CERT] Found a user-provided certificate, but couldn't install it.

```

After many hours of searching and reading, I have discovered that Let’s Encrypt has phased out support for OCSP (also “stapling”), ending in August 2025: [https://letsencrypt.org/2024/12/05/ending-ocsp](https://letsencrypt.org/2024/12/05/ending-ocsp) This would seem to explain the `no URL available` error, as certificates issued by Let’s Encrypt no longer include an OCSP URI. This is verified by examining the applicable section of the output of `openssl-3 x509 -in certificate.crt -text -noout`:

```auto
Authority Information Access: 
    CA Issuers - URI:http://r12.i.lencr.org/

```

**Is the lack of OCSP the real issue causing my custom certificate to fail to load?**

---

<div class="post-metadata">

**Author:** ![jstnryan](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@jstnryan](https://forums.plex.tv/u/jstnryan)\
**Post date:** [March 13, 2026, 7:49am UTC](https://forums.plex.tv/t/using-custom-certificate-without-ocsp/936972/3 "2026-03-13T07:49:04Z")

</div>

Can confirm it works without OCSP. The problem was elsewhere.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [June 11, 2026, 7:49am UTC](https://forums.plex.tv/t/using-custom-certificate-without-ocsp/936972/4 "2026-06-11T07:49:26Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
