Firmaprofesional: Non-BR-Compliant OCSP Responders
This case involves Autoridad de Certificacion Firmaprofesional's non-compliance with Baseline Requirements (BR) regarding OCSP responders. The CA was alerted to the issue on August 29, 2017, and confirmed that affected CAs had ceased issuing SSL/EV certificates. Following the identification of the problem, Firmaprofesional provided a timeline of actions taken and confirmed the revocation of all valid SSL certificates by September 27, 2017. The CA's OCSP responders were found to be returning 'good' statuses for unissued certificates, which led to further scrutiny. The CA has since implemented corrective measures and the non-compliant certificates were added to OneCRL, marking the resolution of the issue.
- CA became aware of OCSP responder issues via email.
- All valid SSL certificates issued by CA1 and AA.PP. were revoked.
- Non-compliant CA certificates were added to OneCRL.
- Mozilla representative — Reported problems with OCSP responders for this CA.
- Isigma representative — Confirmed awareness of the issue and provided a timeline of actions taken.
- Isigma representative — Attached a list of still valid SSL certificates and confirmed plans for revocation.
- Isigma representative — Confirmed that all valid SSL certificates have been revoked.
- Fastly representative — Confirmed that non-compliant CA certificates have been added to OneCRL.