← Disig, a.s. cases
Bugzilla #1398242
Certificate Problem Report
Disig: Non-BR-Compliant OCSP Responders
RESOLVED
FIXED
Disig, a.s.
AI Summary
Disig, a certification authority, faced issues with its OCSP responders that were not compliant with the Baseline Requirements (BRs). Specifically, the OCSP responders were incorrectly configured to respond with a 'good' status for unissued certificates, violating section 4.9.10 of the BRs. The issue was reported on September 8, 2017, and was resolved by August 31, 2017. Disig provided a detailed incident report outlining their response timeline and corrective actions taken to ensure compliance moving forward.
Chronology
- Issue reported regarding non-compliance of OCSP responders.
- OCSP problem resolved.
Participants
Kathleen Wilson
Peter Miskovic
Ryan Sleevi
External References
Similar Local Cases
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
Disig CRL broken, mis-listed? / CA list CRL links need auditing.
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders
certSIGN: Non-BR-Compliant OCSP Responders
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
Visa: Non-BR-Compliant Certificate Issuance
D-TRUST: Non-BR-Compliant Certificate Issuance