← Start Commercial (StartCom) Ltd. cases
Bugzilla #1006479
Self Reported Incident
StartCom: OCSP responder often returns "unknown" for recently-issued certificates
RESOLVED
WONTFIX
Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case involves StartCom's OCSP responder frequently returning 'unknown' for recently issued certificates, causing connection errors for users. This issue was triggered when users attempted to access sites with newly issued certificates, leading to errors indicating that the OCSP server had no status for the certificate. StartCom acknowledged the problem but did not provide a fix, resulting in the bug being marked as resolved with a 'WONTFIX' status. The resolution indicates that the responsibility lies with StartCom to address the OCSP responder's update delays.
Chronology
- User reports OCSP responder issues leading to connection errors.
- Bug marked as resolved with a 'WONTFIX' status.
Thread Activity
- Iserv representative — Reported that StartSSL's OCSP server takes hours to update, causing 'unknown' responses.
- Briansmith representative — Explained that the OCSP requirements were changed to enhance security against mis-issuance.
- Mozilla representative — Assigned the issue to Eddy Nigg for further action.
- Mozilla representative — Resolved the bug, indicating that if StartCom becomes trusted again, they may not face the same issues.
Participants
Iserv representative
Startcom representative
Briansmith representative
Mozilla representative
External References
Similar Local Cases
StartCom: Action Items
Camerfirma: Startcom are issuing by proxy using Camerfirma
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
Disclosure of StartCom CA Certificates
DigiCert / Justica: Invalid DNS names
EV SSL certificate (and OCSP response) for www.camerfirma.com fails to meet EV Guidelines
SHA-1 issuance by Visa root
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits