After a few days of tearing my hair out, it appears Nginx does not prime its OCSP cache for a site for the very first visitor. This can result in TLS errors (MOZILLA_PKIX_ERROR_REQUIRED_TLS_FEATURE_MISSING on Firefox is quite a common one) for...